2026 review

State of cyber deception

Techniques, offerings, evidence and trends.

Download MarkdownBibTeX bibliography

State of cyber deception

Initial review · 15 September 2026

This review connects academic research, open software, products and operational experience. Its scope is public information verified in the catalog. It separates author findings, vendor claims and third-party observations. Metadata-only paper records are not used to infer scientific results.

Definition and boundaries

Cyber deception deliberately introduces signals or resources for an adversary to see, use or make decisions about. A honeypot simulates a system or service. A honeytoken is decoy data whose use produces an alert. Other assets may imitate credentials, files, applications or movement paths. Goals include detection, observation, diversion and imposing cost on adversary activity. MITRE Engage is a framework for planning deception, denial and adversary engagement.

Terminology varies across disciplines. A 2024 survey proposes a broad taxonomy and reviews research with and without AI. A game-theoretic taxonomy distinguishes perturbation, moving target defense, obfuscation, mixing, honey-x and attacker engagement. The Atlas therefore records technique, environment and goal separately. Moving target defense may be part of a deception strategy, but implementations are not automatically classified as cyber deception.

Available approaches

Open projects cover different levels of interaction. OpenCanary is a multi-protocol network honeypot intended to detect activity inside networks. Cowrie focuses on SSH and Telnet. T-Pot combines honeypots and analysis tools. Galah explores language-model interaction in a web honeypot. Their records describe documentation and maintenance; inclusion is not a comparative performance judgment.

Commercial offerings combine decoys, trap data and security operations integrations. Documented examples include Thinkst Canary, FortiDeceptor, Acalvio ShadowPlex, CounterCraft The Platform, Zscaler Deception and Tracebit. Those capabilities currently come from vendor pages. Public documentation or independent testing is needed before comparing prices, ease of deployment or outcomes.

Services include strategy design, deployment, managed operation, testing and education. Classification needs care: a manufacturer offering support is not automatically a managed service provider. The catalog adds services only when it finds a verifiable offering.

Field evidence

In December 2025 the UK NCSC reported a program involving 121 organizations, 14 commercial providers and 10 product trials across several environments. Its findings identify potential for detection and intelligence, together with terminology confusion, a lack of outcome metrics, demand for impartial guidance and configuration risks. Deception requires operational context and strategy.

Customer stories can illuminate adoption problems, but source attribution matters. The Riot Games story published by Tracebit describes interest in extending deception approaches to cloud. The Atlas labels it as a vendor-published story. Independent evaluation, if available, should be added as a separate source.

Research directions

Research investigates network and host mechanisms, decision models, placement and measurement. The Lu et al. survey organizes strategic, network, host and cryptographic schemes. Attack simulation research proposes a network model for evaluating honeypots and moving target defense. A network-requirements survey examines conditions for effective deployment.

Language-model honeypots are a visible but heterogeneous research direction. LLM Honeypot describes fine-tuning with attacker commands and evaluating responses. HoneyGPT presents a terminal honeypot and field evaluation. These are the authors' findings, not evidence that every language model is safe, economical or superior to traditional decoys.

Measurement and limits

A useful evaluation reports placement, legitimate traffic, observable attacks, alert quality, maintenance and consequences of engagement. Measures can include detection time, useful events per decoy, alerts requiring investigation, interaction depth and operational cost. The NCSC identified missing outcome measures. Alert counts alone do not establish lower risk.

The catalog should also record negative results, detected decoys, discontinued projects, name changes and unpublished data. These details help researchers assess reproducibility and teams compare investments.

Coverage and next revision

This version begins with open sources and pilot records. Coverage by sector, region, language and technique will be shown alongside the catalog. A partial sample will not be treated as a global market distribution. The next revision will add full-text reading, more field experience and reproducible tests, recording how conclusions change.