---
title: "Distributed Cyber Deception & Active Defense Traps | Zero-Trust Architecture Canon"
description: "İhlal girişimlerinde anında yüksek doğruluklu alarm üreten sahte AWS anahtarları, aldatıcı Kubernetes servis hesapları ve tuzak ağ portları (honeypot) yerleştiren siber aldatma ve aktif savunma mimarisi."
image: "https://tinycto.tv/assets/zero-trust/zero_trust_architectures_og.jpg"
canonicalUrl: "https://tinycto.tv/tr/zero-trust/architectures/canary-decoy-honeypot-mesh"
locale: "tr"
---

# Distributed Cyber Deception & Active Defense Traps (`zt-arch-15`)

> **Sütun**: DEVICES | **Arketip**: RUNTIME_KERNEL_DEFENSE
> **Engellenen MITRE ATT&CK Teknikleri**: T1083, T1082, T1046, T1552

## Mimari Özeti

İhlal girişimlerinde anında yüksek doğruluklu alarm üreten sahte AWS anahtarları, aldatıcı Kubernetes servis hesapları ve tuzak ağ portları (honeypot) yerleştiren siber aldatma ve aktif savunma mimarisi.

## Saldırgan Modeli

Sisteme sızan saldırganın içeride parola arayarak, sahte kimlik bilgilerini kullanarak veya iç portları tarayarak ilerlemeye çalışması.

## NIST SP 800-207 Temel İlkeleri

- The enterprise collects as much information as possible about the current state of network infrastructure and communications.
- No asset is inherently trusted.

## 3 Kademeli Olgunluk Yapılandırmaları

### INITIAL Seviyesi

- **Uygulama Kapsamı**: Static canary tokens planted in developer documentation and repository READMEs.
- **Kimlik Doğrulama Zorlaması**: Triggered when HTTP decoy URL is visited.
- **Ağ İzolasyonu**: Public canary token service.

### ADVANCED Seviyesi

- **Uygulama Kapsamı**: Synthetic AWS IAM canary keys deployed into GitHub repositories and internal configuration files.
- **Kimlik Doğrulama Zorlaması**: Any API usage triggers automated IAM quarantine and IP blocking.
- **Ağ İzolasyonu**: Decoy container pods running in every cluster namespace.

### OPTIMAL Seviyesi

- **Uygulama Kapsamı**: Dynamic deception fabric with polymorphic honeypots mimicking production databases and services.
- **Kimlik Doğrulama Zorlaması**: Attacker interactions isolated into interactive sandbox with live forensic memory capture.
- **Ağ İzolasyonu**: eBPF-redirected deceptive network routing trapping adversary in endless delay loops.

## Terraform HCL Manifest

```hcl
resource "aws_iam_user" "canary_user" {
  name = "svc-backup-canary-do-not-use"
  path = "/system/"
}

resource "aws_iam_access_key" "canary_key" {
  user = aws_iam_user.canary_user.name
}

resource "aws_cloudwatch_event_rule" "canary_alert" {
  name        = "CanaryKeyUsedAlert"
  description = "Triggered when canary access key is used anywhere"

  event_pattern = jsonencode({
    detail = {
      userIdentity = {
        accessKeyId = [aws_iam_access_key.canary_key.id]
      }
    }
  })
}
```

## Kubernetes / Tetragon Policy Manifest

```yaml
apiVersion: v1
kind: Secret
metadata:
  name: decoy-db-credentials
  namespace: default
stringData:
  DATABASE_URL: "postgres://canary_trap:fake_pass@decoy-db.security.svc:5432/core"
  API_KEY: "canary_token_aws_fake_abcdef123456"
```


```json
{
  "@context": "https://schema.org",
  "@type": "TechArticle",
  "headline": "Distributed Cyber Deception & Active Defense Traps | Zero-Trust Architecture Canon",
  "description": "İhlal girişimlerinde anında yüksek doğruluklu alarm üreten sahte AWS anahtarları, aldatıcı Kubernetes servis hesapları ve tuzak ağ portları (honeypot) yerleştiren siber aldatma ve aktif savunma mimarisi.",
  "url": "https://tinycto.tv/tr/zero-trust/architectures/canary-decoy-honeypot-mesh"
}
```
