Sandia supercharges the honeypot

secure network (vs148/ 

Sandia National Laboratory is working with Splunk to sharpen its virtual cybersecurity sandbox environment and evaluate how it might be used in both the federal government and industry to blunt attacks.

HADES -- short for High-Fidelity Adaptive Deception & Emulation System -- is a supercharged "honeypot" system that attracts would-be cyber attackers by creating an entire virtual environment and tricks the intruders into sticking around so their actions can be monitored. The project won a 2018 Government Innovation Award.

Sandia, a National Nuclear Security Administration research and development lab, develops, engineers and tests non-nuclear parts of nuclear weapons. The lab's IT infrastructure is a magnet for cyber bad actors. The lab has been working with Splunk's Enterprise system to widen and deepen the program's ecosystem, said Vincent Urias, distinguished member of the technical staff at Sandia.

HADES is ultimately aimed at "changing the conversation with the adversary," Urias told FCW. That shift is particularly important as threat information is being commoditized by security companies that crunch their own threat intelligence, he said. The system offers the ability to develop unique streams of threat intelligence by observing actual attackers and developing responses at machine speed.

Current cybersecurity practices, such as post-attack forensics and assuming compromise "are not the entire story" for federal and industry IT security managers, he said. HADES can fill in details in the here and now, such as what tools are being used, what time the attack infiltrated the network, where it got in and other details that can be hard to pin down afterwards.

First deployed in 2017, HADES has grown to develop better and better data analytic capabilities, Urias said. "The hopes are to help cross-sectional .gov and commercial networks."

About the Author

Mark Rockwell is a senior staff writer at FCW, whose beat focuses on acquisition, the Department of Homeland Security and the Department of Energy.

Before joining FCW, Rockwell was Washington correspondent for Government Security News, where he covered all aspects of homeland security from IT to detection dogs and border security. Over the last 25 years in Washington as a reporter, editor and correspondent, he has covered an increasingly wide array of high-tech issues for publications like Communications Week, Internet Week, Fiber Optics News, magazine and Wireless Week.

Rockwell received a Jesse H. Neal Award for his work covering telecommunications issues, and is a graduate of James Madison University.

Click here for previous articles by Rockwell. Contact him at [email protected] or follow him on Twitter at @MRockwell4.


    pentagon cloud

    Court orders temporary block on JEDI

    JEDI, the Defense Department’s multi-billion-dollar cloud procurement, is officially on hold, according to a federal court announcement Feb. 13.

  • Defense
    mock-up of the shore-based Aegis Combat Information Center

    Pentagon focuses on research, cyber in 2021 budget request

    The Defense Department wants to significantly increase funds for research, cyber, and cloud.

Stay Connected


Sign up for our newsletter.

I agree to this site's Privacy Policy.