Skip to main content
QUICK REVIEW

[Paper Review] Cyber Deception for Computer and Network Security: Survey and Challenges

Zhuo Lu, Cliff Wang|arXiv (Cornell University)|Jul 28, 2020
Network Security and Intrusion Detection41 references13 citations
TL;DR

This paper presents a comprehensive survey and analysis of cyber deception as a proactive cyber defense mechanism, categorizing deception strategies into game-theoretic modeling, network-level deception, in-host-system deception, and cryptography-based approaches. It identifies key challenges in observability, controllability, usability, and integration with moving target defense, advocating for interdisciplinary research to establish a scientific foundation for deception-based security.

ABSTRACT

Cyber deception has recently received increasing attentions as a promising mechanism for proactive cyber defense. Cyber deception strategies aim at injecting intentionally falsified information to sabotage the early stage of attack reconnaissance and planning in order to render the final attack action harmless or ineffective. Motivated by recent advances in cyber deception research, we in this paper provide a formal view of cyber deception, and review high-level deception schemes and actions. We also summarize and classify recent research results of cyber defense techniques built upon the concept of cyber deception, including game-theoretic modeling at the strategic level, network-level deception, in-host-system deception and cryptography based deception. Finally, we lay out and discuss in detail the research challenges towards developing full-fledged cyber deception frameworks and mechanisms.

Motivation & Objective

  • To provide a formal framework for understanding cyber deception as a proactive defense mechanism against advanced cyber attacks.
  • To categorize and summarize recent advancements in deception-based cyber defense techniques across multiple domains: strategic, network, host-level, and cryptographic approaches.
  • To identify and analyze major research challenges in observability, controllability, usability, and integration with moving target defense (MTD).
  • To advocate for interdisciplinary research integrating control theory, cognitive science, and security to build a scientific foundation for cyber deception.
  • To guide future research by outlining open issues and directions for developing robust, scalable, and usable deception frameworks.

Proposed method

  • Proposes a one-round deception model with three phases: planning deception (designing deception goals and biased information), implementing deception (deploying fake artifacts like files, devices, and network traffic), and analyzing deception (monitoring adversary behavior and measuring effectiveness).
  • Classifies deception techniques into four categories: game-theoretic modeling for strategic decision-making, network-level deception using fake routing and traffic, in-host-system deception via fake system files and services, and cryptography-based deception using obfuscation and fake keys.
  • Introduces the concept of 'observability' in deception, defined as the defender’s ability to perceive and measure adversary behavior, and 'controllability' as the ability to steer the adversary toward a false mental model.
  • Proposes that deception effectiveness should be evaluated not only by detection and disruption but also by usability impact, ensuring minimal disruption to legitimate users.
  • Recommends combining cyber deception with moving target defense (MTD) to enhance resilience by increasing system complexity and misdirection simultaneously.
  • Calls for formal metrics grounded in control theory and cognitive science to quantify deception observability and controllability, enabling systematic evaluation of deception schemes.

Experimental results

Research questions

  • RQ1How can cyber deception be formally modeled as a strategic, interactive process between attacker and defender across multiple phases?
  • RQ2What are the key technical categories and representative techniques of deception-based cyber defense, and how do they differ in implementation and effectiveness?
  • RQ3How can observability and controllability in cyber deception be formally defined and measured using control theory principles?
  • RQ4What usability trade-offs exist in deception deployment, and how can deception be designed to minimize disruption to legitimate users?
  • RQ5How can cyber deception be effectively combined with moving target defense (MTD) to maximize protection across the cyber kill chain?

Key findings

  • Cyber deception is a promising proactive defense mechanism that can disrupt attackers during the reconnaissance and planning stages, reducing the effectiveness of subsequent attacks.
  • Deception techniques are broadly categorized into game-theoretic modeling, network-level deception, in-host-system deception, and cryptography-based deception, each addressing different attack surfaces.
  • Observability and controllability are critical metrics for deception effectiveness, but formal definitions and quantification methods are still lacking in current research.
  • Usability is a major concern: deception must be carefully designed to avoid confusing or disrupting normal users, yet no standardized metrics exist for usability impact in deception schemes.
  • Combining deception with moving target defense (MTD) enhances security by increasing system complexity and misdirection, with recent works showing success in disrupting network flow inference.
  • Significant interdisciplinary research is needed—spanning computer security, control theory, and cognitive science—to formalize deception models and build scalable, effective deception frameworks.

Better researchstarts right now

From reading papers to final review, dramatically reduce your research time.

No credit card · Free plan available

This review was created by AI and reviewed by human editors.