Wednesday, November 30, 2016

Interesting idea - Using AWS Access Keys for deception

 
Folks continue to get creative about deceptive tricks against attackers.
 

Tuesday, May 12, 2015

Paper on fooling malware that they're not in a sandbox

Very interesting paper

From Patches to Honey-Patches: Lightweight Attacker Misdirection, Deception, and Disinformation


My first take is that if malware is becoming virtual sandbox aware, can we fake visualization on our physical hosts so the malware goes away?

Saturday, April 20, 2013

Thursday, April 18, 2013

Good ideas on booby traps from an old talk by MJR

Recently I was re-reading some of Marcus Ranum's old stuff (hint: it's still relevant and prescient) and came across:

"Tutorial notes for a briefing on the IDS approach of using policy-centric detectors (AKA "production honeypots")"

 It's got awesome great ideas on setting up improvised deceptive traps for attackers.