Framework provenance

References and Supporting Basis

These sources document the research and practitioner work that informed the framework. Each technique page identifies its supporting sources, provenance classification, and the specific scope of support. A citation establishes design lineage; it does not by itself validate operational effectiveness, implementation estimates, environment labels, or ATT&CK relationships.

24

Direct antecedent

A cited source directly describes the mechanism or operational activity.

9

Literature-informed design

Published work supports the design, while ShadowMatrix defines the record or workflow.

9

Author-derived extension

ShadowMatrix extends related literature beyond what the cited sources directly establish.

Technique provenance

SDF-PL01Threat Landscape AssessmentDirect antecedentSDF-PL02Deception Objective DefinitionDirect antecedentSDF-PL03Crown Jewel IdentificationDirect antecedentSDF-PL04Adversary Profile DevelopmentDirect antecedentSDF-PL05Deception Architecture BlueprintDirect antecedentSDF-PL06Legal and Compliance ScopingDirect antecedentSDF-PR01Shadow Network ProvisioningDirect antecedentSDF-PR02Decoy Host FabricationDirect antecedentSDF-PR03Service Emulation EngineeringLiterature-informed designSDF-PR04Synthetic Data GenerationDirect antecedentSDF-PR05Identity Ecosystem CreationLiterature-informed designSDF-PR06Monitoring Pipeline SetupDirect antecedentSDF-DP01Honeypot PlacementDirect antecedentSDF-DP02Canary Token DistributionDirect antecedentSDF-DP03Credential Trap PlantingDirect antecedentSDF-DP04Decoy Service ActivationDirect antecedentSDF-DP05Network Breadcrumb DeploymentLiterature-informed designSDF-DP06Trap Document SeedingDirect antecedentSDF-LR01DNS Record MisdirectionAuthor-derived extensionSDF-LR02Network Path EngineeringDirect antecedentSDF-LR03Credential Breadcrumb TrailsDirect antecedentSDF-LR04Vulnerability Surface CraftingDirect antecedentSDF-LR05Lateral Movement ChannelsLiterature-informed designSDF-LR06Supply Chain DecoysAuthor-derived extensionSDF-DT01Interaction Tripwire MonitoringDirect antecedentSDF-DT02Canary Alert ProcessingLiterature-informed designSDF-DT03Behavioral FingerprintingLiterature-informed designSDF-DT04Access Pattern Anomaly DetectionDirect antecedentSDF-DT05Credential Misuse DetectionDirect antecedentSDF-DT06Network Flow SurveillanceDirect antecedentSDF-AN01TTP Extraction and CatalogingLiterature-informed designSDF-AN02MITRE ATT&CK CorrelationLiterature-informed designSDF-AN03IOC HarvestingDirect antecedentSDF-AN04Attack Path ReconstructionAuthor-derived extensionSDF-AN05Adversary Capability AssessmentAuthor-derived extensionSDF-AN06Intelligence Report SynthesisAuthor-derived extensionSDF-RS01Detection Rule EngineeringLiterature-informed designSDF-RS02SOC Playbook EnhancementAuthor-derived extensionSDF-RS03Threat Feed EnrichmentAuthor-derived extensionSDF-RS04Infrastructure HardeningAuthor-derived extensionSDF-RS05Deception Environment RefreshDirect antecedentSDF-RS06Stakeholder ReportingAuthor-derived extension

Source list

  1. Achleitner, S. et al. Deceiving Network Reconnaissance Using SDN-Based Virtual Topologies. IEEE TNSM 14 (2017), 1098–1112.Peer reviewed
  2. Almeshekah, M.H.; Spafford, E.H. Planning and Integrating Deception into Computer Security Defenses. NSPW 2014.Peer reviewed
  3. Bowen, B.M. et al. Baiting Inside Attackers Using Decoy Documents. SecureComm 2009, 51–70.Peer reviewed
  4. Ferguson-Walter, K.J. et al. Examining the Efficacy of Decoy-Based and Psychological Cyber Deception. USENIX Security 2021, 1127–1144.Peer reviewed
  5. Han, X.; Kheir, N.; Balzarotti, D. Deception Techniques in Computer Security: A Research Perspective. ACM Computing Surveys 51 (2018), Article 80.Peer reviewed
  6. Islam, M.M.; Al-Shaer, E. Active Deception Framework: An Extensible Development Environment for Adaptive Cyber Deception. IEEE SecDev 2020, 41–48.Peer reviewed
  7. Juels, A.; Rivest, R.L. Honeywords: Making Password-Cracking Detectable. ACM CCS 2013, 145–160.Peer reviewed
  8. Ladisa, P. et al. SoK: Taxonomy of Attacks on Open-Source Software Supply Chains. IEEE Symposium on Security and Privacy 2023, 1509–1526.Peer reviewed
  9. Ohm, M. et al. Backstabber's Knife Collection: A Review of Open Source Software Supply Chain Attacks. DIMVA 2020, 23–43.Peer reviewed
  10. Roy, S. et al. Adversarial Reconnaissance Mitigation and Modeling. arXiv:2306.06769, 2023.Preprint
  11. Spitzner, L. Honeypots: Catching the Insider Threat. ACSAC 2003, 170–179.Peer reviewed
  12. Spitzner, L. Honeypots: Tracking Hackers. Addison-Wesley Professional, 2003.Practitioner book
  13. Srinivasa, S.; Pedersen, J.M.; Vasilomanolakis, E. Towards Systematic Honeytoken Fingerprinting. SIN 2020, 1–5.Peer reviewed
  14. Strom, B.E. et al. MITRE ATT&CK: Design and Philosophy. The MITRE Corporation, revised 2020.Technical report
  15. Sun, J.; Sun, K.; Li, Q. Towards a Believable Decoy System: Replaying Network Activities from Real System. IEEE CNS 2020, 1–9.Peer reviewed
  16. The MITRE Corporation. A Practical Guide to Adversary Engagement, version 1.0. 2022.Technical guide
  17. Trassare, S.T.; Beverly, R.; Alderson, D. A Technique for Network Topology Deception. MILCOM 2013, 1795–1800.Peer reviewed
  18. Yuill, J.; Zappe, M.; Denning, D.; Feer, F. Honeyfiles: Deceptive Files for Intrusion Detection. IEEE SMC Information Assurance Workshop 2004, 116–122.Peer reviewed