Lure Cyberattackers in With AI-Powered Honeypots
Question: I keep reading articles about how healthcare systems should prepare for a cyberattack with a “when, not if” mentality. Have cybersecurity professionals considered trying to trap attackers with decoy systems? Georgia Subscriber Answer: As a matter of fact, cybersecurity teams are developing ways to trick hackers before a breach occurs. One way that cybersecurity professionals are trying to stay a step ahead of attackers is by deploying honeypots in their organizations. A honeypot is a duplicate network, server, application, or website not connected to the organization’s existing devices and connected software. The duplicate is geared toward luring malicious actors, so the cybersecurity team can learn about the cyberattacker’s patterns and methods to help boost security defense. A honeypot can function as an early alert system, warning the practice against incoming attacks. Setting up a honeypot can also redirect attackers away from systems and services that are critical for healthcare operations, such as the servers that store sensitive patient data. Security teams are starting to add artificial intelligence (AI) components to these honeypots to make the already enticing traps much more realistic. Natural language processing (NLP) and machine learning (ML) add an interactive feel to the replica systems and AI allows the honeypots to evolve and adapt, which makes them harder for the attackers to detect. Mike Shaughnessy, BA, CPC, Production Editor, AAPC
