Document Type

Report

Publisher

Utah State University

Publication Date

2026

First Page

1

Last Page

13

Abstract

Traditional cyber deception mechanisms, such as honeypots and honey-tokens, typically rely on adversary interaction to trigger alerts and provide defensive value. This paper introduces the concept of interactionless deception—a defensive paradigm focused on the strategic manipulation of the environment to disrupt the cyber kill chain without requiring direct engagement. By utilizing a greedy top-k selection method to analyze MITRE ATT&CK® data across 178 Advanced Persistent Threat (APT) groups, this research identifies seven high-frequency sub-techniques that represent common attacker behavior. To counter these, the authors developed a series of proof-of-concept tools, including deceptive web proxies, simulated command-and-control (C2) beacons, and endpoint security simulations. These tools are designed to increase the cognitive load on the adversary, inducing psychological effects such as confusion and caution to increase the operational cost of the attack and enhancing the defender’s ability to detect and neutralize threats.

Share

COinS