×

Canary in Cyber security

Introduction

Cyber security is meant to provide security to the cyber/ internet/ IT world. It aims to secure the organization against cyber-attacks by using various security products. Not just data, applications or software, but network and physical devices need security measures to keep them safe from inner or outer attacks.

For this purpose, security may use industry terms or a slew of buzzwords like firewall, ransomware, encryption, artificial intelligence, cloud, zero-day, botnet and next generation to capture the attention and secure you in terms of solving user problems and providing all-around security. The cyber security products available in the market with the endless list of available options help reduce efficiency and effectiveness and ultimately negatively impact overall security.

All security programs have defending programming, including preventing breaches and intrusion, as their top priority, but when an intrusion occurs, the situation changes. Rather prevention is the key to success, but detection is equally important because prevention is not 100% guaranteed to stop all the cyber-attacks. An organization takes about six months to detect or longer to identify a breach. This higher cost of remediation can result in a loss in business.

To conquer this, cyber security experts find a mediocre way to lie between prevention and curing of cyber-attack and this is termed alarming cyber-attack. This is a new concept taken from the early 90s and designed as a product to increase the detection of malicious actors inside an environment named Canary.

Canary is a bird used in the mining process up to the late 20th century to detect dangerously high levels of toxic gages such as carbon monoxide in the mines and protect them from inhaling dangerous substances. The canary bird suddenly dies after inhaling the poisonous gases. Therefore, it alarms the workers to stop mining; the danger is waiting ahead.

Canary in cyber security

In cyber security, cyber security experts of a company, Thinkst, deploy or create a virtual or physical device that can be intimate with any device in various configurations. It works similarly to a honeypot, based on a cloud, physical or virtual device capable of mimicking any device in any configuration. It results in a token that can track user actions online.

The canaries present in the network send messages to the admin or others when they encounter a threat. Two main functions of canaries in the IT field are:

  • They provide information to the IT team about the attacker's methodology
  • Helps pinpoint a hacker’s attack surface of choice

The best part of canaries is that they can be preconfigured by the user to be deployed and ready to strengthen security within minutes. These canaries are cost-effective as they don't need a lot of time-consuming maintenance and soon gather all the information about the threat. This also empowers the IT staff to respond appropriately and quickly.

Canary honeypots

Canary honeypots create a virtual network mimic system that may attract an attacker. Once the attacker gets into this trap, the administrator studies their behaviour of attacking.      

Canary tokens

Canary tokens are programmed to track the behaviour of cyber criminals by implanting them in regular files. When cybercriminals open these tokens, their token name, IP address and time of file accessed is traced. When files are accessed or executes a process, a certain message is sent to the person who implanted the token so that they can track the functioning.

Canary tokens create a canary trap sold by vendors like ThinkSt Canary or Red Canary. These are physical devices found on http://redcanary.com or http://canary.tools.com. It can also be available in "soft" canary form such as:

URL token

When the user visits a specific URL

Unique email address

When a specific email address is emailed

Word document

When the user opened a word document

DNS token

When the user requests a specific DNS hostname

PDF document

When a particular PDF document is viewed or opened

Window folder

When a certain window folder is viewed or opened

Image token

It is created when a specific image is viewed or opened

Canary free token can be set up at: canarytokens.org/generate

Canary tokens are used for or at certain places:

  • Canary tokens are placed inside DNS or another mechanism
  • For intellectual property
  • For personal identifiable information
  • Placed inside the files (mock filed handles the sensitive data)
  • Tokens can be placed in databases (when someone tries to extract the database content, they can be notified)    

Note: Honeypot and canary tokens have the same goals but are programmed with different approaches. Where one side, the honeypot pretends to be an attractive target for a cyber-criminal or a place for them to play; on the other side, the canary token gives attackers a toy to play with. The common point is that both can trap the attacker, and once they are trapped, IT security teams can gather valuable information about them.

Terms related to canary

Canary objects: When canary folders and canary files are combined, they are known as canary objects. These objects are not on external hard drives like USB or network devices.

Canary folder: Canary objects are installed in the root folders named as a canary folder in (C:\, D:\ etc.)or in the machine's main directory (C:\Users).   

Canary files: Canary folders contain the canary files. These files or folders use a combination of random common English words or random letters and come in a variety of common file types.

Note: Canary objects can be visible or hidden depending on deployment type. Users must maintain balance with these canary objects as some are deployed visible, and some are hidden. Visible canary objects alarm users who don't understand what they are or why they are there.

So, it's necessary to share information about the canary object in a limited way because too much sharing of information should be risky. Less knowledge of canary files or objects to hackers will help the IT ecosystem to protect against an actual ransomware attack.      

How does canary help?

Canary is programmed to protect networks, systems or applications and provide advance alerts to users, informing them about potential dangers. It is an ongoing threat monitoring system that helps IT teams gather information about the attacker's methodology.

When canaries are strategically positioned throughout the network, they can alert admins about how and when attackers try to penetrate the system.

Canaries tokens are fitted in the system and act like LoJack (a stolen vehicle recovery system for network defenders). They prevented attaining sensitive data and proved it like traditional spyware.


Related Topics

Cyber security policies

Introduction Security experts design security policies to protect the enterprise, employees, staff, and business from various threats. The written documents consist of planning to protect the company from undesired issues and...

4 minutes read.

Digital signature

A signature is the authoritative power of a person and is done on paper. Before digitization, a signature done by a human physically by hand was given preference, whereas the...

11 minutes read.

Difference between Network Security and Cyber Security

Introduction While learning about cyber security, usually terms like information security and network security come to have a familiar ring. Still, they are different from each other on numerous factors.  The technology...

3 minutes read.

Types of security policies

Policies act as a protection field for the business, organization, and individual users to allow them and protect their rights. Security policies are meant to provide security for the technology...

9 minutes read.

Types of penetration testing

Penetration testing is the collection of techniques utilized to resolve the various issues of the system and test, analyses and give a solution. So, understanding penetration testing is incomplete without...

6 minutes read.

Botnet in cyber security

Introduction Since people started using computer systems, they have become victims of cyber-attack. The reason and medium of cyber-attack vary from attack to attack like phishing attack uses email, DDOS attack...

14 minutes read.

Eavesdropping attack in cyber security

Introduction Eavesdropping is a technique of finding someone's conversation details for personal benefit. When an ongoing communication between two people is interrupted, or a third person tries to listen to that...

6 minutes read.

Difference between Ethical Hacking & Cyber Security

Cyber security and ethical hacking are usually confusing as they are interrelated but different. These terms have the most booming careers in the tech industry. Ethical hacking is the subset,...

5 minutes read.

Cyberspace

Introduction Cyberspace combines two words, Cyber + Space having a different meaning. Cyber is used as a synonym of the internet related to the computer, computer network, or virtual reality. Space- Rather, the...

4 minutes read.

PCI DSS Standard

Payment cards like credit and debit were designed to ease the payment option for the user whenever, wherever they pay; even when they don't have enough credit, they can pay...

5 minutes read.

ISO - International Standard for Organization

* Abbreviation is ISO of International Standard for Organization derived from the ancient Greek word ísos which means equivalent or equal. ISO develops and publishes a wide of industrial, commercial,...

6 minutes read.

Cyber Forensics Definition

Cyber forensic is an electronic discovery technique used to reveal and determine the evidence of a criminal offence. The primary goal of computer forensics or cyber forensics is to investigate...

6 minutes read.

Overview of Cyber security

The word cyber means computer, virtual reality, or computer network. This word relates to information technology (IT, i.e., computers). This century is the electronic century where everyone's life and work...

4 minutes read.

Functions of Cyber Security

Let’s learn about the Cybersecurity Framework's five Functions that are the key pillars of wholistic and successful cyber security programs. These five functions result from the highest level of abstraction...

3 minutes read.

Information Technology Act

Information technology is everywhere; it is absorbed in the nerves of a human being. Without it, human goes back to their early era, and no work is conducted. It is...

6 minutes read.

Types of cyber security vulnerabilities

The user must know all the vulnerabilities to understand cyber security vulnerabilities and build a vulnerability management program. Here are some of the common types of cyber security vulnerabilities: System misconfigurationsThe...

8 minutes read.

Vulnerability Assessment

Introduction In most cases, vulnerability management is considered a vulnerability assessment. Still, these are different terms as the “vulnerability management” process manages to find and remove vulnerabilities, and “vulnerability assessment” is...

8 minutes read.

Cyber Security Identity and Access Management

Identity and access management is a framework of business processes that provide a facility for digital Identity. It is also abbreviated as IAM. Its main work is to provide restricted...

6 minutes read.

Elements of vulnerability management

Vulnerability management is the process or program that consists of identifying, classifying, remediation, and mitigating security vulnerabilities. The whole process is included in the three core elements of vulnerability management, where...

5 minutes read.

Difference between Information Security and Cyber Security

Cyber security and information security terms are associated with computer security to protect systems from threats, information breaches, and other cyber-attacks. Both the terms are often used interchangeably or as...

3 minutes read.