FortiDeceptor-DECEIVE , EXPOSE & ELIMINATE THREATS
Use Cases and Deployment Scope
FortiDeceptor is the Concept of Honeypot & Threat Analytics & Threat Intelligent. Lure attackers to decoys that appear indistinguishable from real IT & OT assets & highly interactive. Centrally manage & automate deployments of decoy VMs(Windows, Linux, ICS/SCADA) and generations of lures (data, applications, Services) FortiDeceptor is designed to DECEIVE, EXPOSE and ELIMINATE external & internal attack kill chain & proactively block these threats before any significant damage occurs. Protect both IT & OT Devices, FortiDeceptor provides expansive decoy support to lure attacks away from IT & OT environments. Fortideceptor is Unintrusive & EasyIt is a Network based solution that creates a fake environment to stimulate the actual one. It is completely unintrusive -no requirement to take SCADA/ICS offline nor does it create any delay in operational duties.
Pros
- Gain visibility of network-related attacks & laterals movements that could potentially bypass existing security in place.
- Redirect attacks from existing critical platforms as well as sensitive data .
- Early warning system to deal with threats.
Cons
- FortiDeceptor works very well with FortiFabric environments, Where We need FortiSIEM & Other FortiGate NGFW, which could lead to a hike in IT Security Budget.
- Reporting part needs to improve, Where again we have to buy a Forti analyzer for reporting part.
Return on Investment
- FortiDeceptor is one of the best Deception technology available across the globe, With the best licensing policy ( Maximum Decoys based on Deception best practice -Four Decoy per VLAN).
- Add-on-per VLAN(minimum quantity of two).
- Day-1 operation via AI-based network and asset discovery & automated deployment of decoys.
- Security Fabrics enables Fortideceptor integration with Fortinet & third-party security solutions to automate threat response.
Alternatives Considered
Rapid7 InsightIDR, Smokescreen IllusionBlack and from Zscaler
