Labyrinth Development
Implementation of Deception System in IT Company
Pages
2
Time to read
3 mins
Publication
Language
English
Pages
2
Time to read
3 mins
Publication
Language
English
This case study details the implementation of a deception system within an IT company to enhance cybersecurity measures. The document outlines the steps taken to deploy this system, which included identifying the number of traps based on active hosts, investigating services in network segments, and configuring honeypots. The case study emphasizes the establishment of a 24/7 incident detection and response capability, which involved configuring detection events and developing playbooks for the internal Cybersecurity Operation Center (CSOC). It also discusses the reduction of false positive detections through the creation of a behavioral model of services and users. The outcomes of the implementation were validated through external penetration testing, where professional testers could not detect the network traps. Additionally, the deployment of the Labyrinth deception system improved visibility in network segments, identified policy violations, and enhanced the overall security posture of the organization. The findings indicate that the deception system significantly enriched the incident response capabilities of the CSOC team.