FortiDeceptor decoys
FortiDeceptor creates a network of decoys to lure attackers and monitor their activities on the network. When attackers attack a decoy, first, an alert is generated; second, their malicious activities are captured and analyzed in real-time to generate a mitigation and remediation response that protects the network.
The current FortiDeceptor decoys are:
Windows |
|
Linux |
|
IoT/OT |
|
VPN |
|
The current FortiDeceptor monitor services are:
Windows |
|
Linux | |
IoT/OT |
|
SSL VPN |
|
The current FortiDeceptor IP address capacity are:
- A single FortiDeceptor appliance (HW/VM) can host up to 16 deception VMs.
- A single deception VM supports up to 16 IP addresses or decoys, Each IP represent a decoy.
- A single FortiDeceptor appliance (HW/VM) can support up to 256 IP addresses.
- With 4 decoys per segment on average, a single FortiDeceptor appliance (HW/VM) can support up to 64 segments (VLANS).
-
FortiDeceptor decoys services details
IoT OS
HP printer decoy |
SNMP service |
|
Jetdirect |
|
|
Printer-WEB |
|
|
IP camera decoy
|
IP Camera-WEB |
|
SNMP service |
|
|
UPnP service |
|
|
RTSP service |
For example, to infinitely loop a video: For attacker, the live camera stream is available at |
|
Cisco router decoy
|
Models |
4 cisco images (model) are supported - 2691, 3660, 3725 and 3745, also if users upload a cisco image that cannot be used, an error msg will appear. |
Router Running-Config (optional) |
User can upload a customized cisco config file to predefine the Cisco router setting |
|
Telnet service |
|
|
HTTP service |
|
|
SNMP service |
|
|
CDP service |
|
Medical
Infusion Pump (Telnet) service |
|
Infusion Pump (FTP) |
|
PACS service |
|
PACS-WEB service |
|
DICOM Server service |
|
POS
POS-WEB service |
|
CRM(ERP)
ERP-WEB service |
|
SCADA (version3) OS
Schneider SCADAPack 333E decoy
|
SNMP service |
|
DNP3 service |
|
|
Telnet service |
|
|
Schneider Power Meter - PM5560 decoy
|
SNMP service |
|
BACNET service |
|
|
HTTP service |
|
|
DNP3 service |
|
|
ENIP service |
|
|
Schneider EcoStruxure BMS server decoy
|
SNMP service |
|
BACNET service |
|
|
HTTP service |
|
|
TRICONEX service |
|
|
Siemens S7-200 PLC decoy
|
HTTP service |
|
TFTP service |
|
|
SNMP service |
|
|
MODBUS service |
|
|
S7COMM service |
|
|
Rockwell PLC decoy
|
HTTP service |
|
TFTP service |
|
|
SNMP service |
|
|
ENIP service |
|
|
Siemens S7-300 PLC decoy
|
TFTP service |
|
SNMP service |
|
|
IEC104 service |
|
|
IPMI Device decoy
|
HTTP service |
|
SNMP service |
|
|
FTP service |
|
|
IPMI service |
|
|
KAMSTRUP 382 decoy |
KAMSTRUP service |
|
VAV-DD BACnet controller decoy
|
SNMP service |
|
BACNET service |
|
|
Guardian-AST decoy |
Guardian-AST service |
|
Ascent Compass MNG decoy
|
HTTP service |
|
FTP service |
|
|
SNMP service |
|
|
BACNET service |
|