Transcript
In this series of short videos, we're taking a look at the baseline configuration for Deception Standard. This is part one, the value of Deception. Before we talk about Deception and its capabilities, let's talk about the security challenges faced by many organizations today. It's important to understand that attacks today are becoming more and more sophisticated and harder to detect and stop. The vast majority of attacks fail to generate any security alerts, as they are designed to mimic user behavior and defeat standard network and security monitoring tools. Additionally, over two-thirds of attacks are advanced, human-operated attacks that are not malware-based. These problems are compounded by the fact that SOC teams must look at thousands of alerts from dozens of products, nearly half of which end up false positives. This leads to alert fatigue and to security analysts wasting time chasing ghosts, both of which contribute to many attackers loitering undetected inside corporate networks for days before an attack is detected. Since attackers have learned to bypass predictable traditional defenses and avoid detection by monitoring tools, a different approach is needed. By configuring and deploying decoys that serve as honeypots, Deception allows you to detect attackers as soon as they enter your network and access a decoy. This drastically speeds up detecting and addressing threats for your security operations teams by generating high-fidelity alerts, cutting through alert fatigue, and ensuring that attackers can be detected and monitored, even when they manage to disguise their activity inside the network from traditional security and network monitoring tools. While ZIA secures your users' connections to external apps and resources, and ZPA secures your private internal apps, Deception allows you to secure your internal network by making attackers significantly easier to detect and stop. Deception is also fully integrated as part of the Zero Trust Exchange. This allows Deception to leverage existing Zscaler components to place decoys and to make these more convincing. Deception can integrate with ZPA to create decoys that look like private applications inside your environment, can isolate user accounts from private apps when they access decoys, and can leverage the Zscaler Client Connector to deploy client-side lures, such as dummy credentials, that boost the apparent legitimacy of decoys. Here is a quick overview of the key components of Deception. The first of these components is the Admin Portal. This is the central management and analysis hub for deploying decoys and reviewing decoy access data and alerts. The second component are the Decoy Connectors. These deploy and manage decoy applications in virtual local area networks and securely relay their data back to the Admin Portal. Finally, Landmines are endpoint agents that deploy decoy credentials, files, and other lures as traps for attackers. When integrated with ZPA, Deception can also be leveraged to create decoy segments and applications directly inside ZPA. This enables redirecting attackers to fake applications hosted inside the Deception Cloud when an endpoint device is compromised, to further secure your private applications. Finally, here is a quick summary of the capabilities available with a Deception Standard license. This includes the ability to deploy up to 20 decoys, chosen from a library of pre-configured decoy types designed to look like file shares, CRM applications, mail servers, engineering repositories, and other types. The ability to configure and deploy session lures, browser cookies, and beacon files with no limits. The ability to configure alerts and email notifications for triggered alerts, and to connect to external data enrichment sources to provide more context to Deception events. And standard administrator roles, single sign-on, and audit logs. That's it for this video. Thank you for watching!