An Empirical Assessment of Endpoint Security Systems Against Advanced Persistent Threats Attack Vectors

08/23/2021
by   George Karantzas, et al.
0

Advanced persistent threats pose a significant challenge for blue teams as they apply various attacks over prolonged periods, impeding event correlation and their detection. In this work, we leverage various diverse attack scenarios to assess the efficacy of EDRs and other endpoint security solutions against detecting and preventing APTs. Our results indicate that there is still a lot of room for improvement as state of the art endpoint security systems fail to prevent and log the bulk of the attacks that are reported in this work. Additionally, we discuss methods to tamper with the telemetry providers of EDRs, allowing an adversary to perform a more stealth attack.

READ FULL TEXT

page 7

page 9

page 16

page 36

page 38

page 39

page 40

page 41

research
12/03/2017

Kidemonas: The Silent Guardian

Advanced Persistent Threats or APTs are big challenges to the security o...
research
02/01/2018

Anomaly Detection in Log Data using Graph Databases and Machine Learning to Defend Advanced Persistent Threats

Advanced Persistent Threats (APTs) are a main impendence in cyber securi...
research
03/21/2019

On Preempting Advanced Persistent Threats Using Probabilistic Graphical Models

This paper presents PULSAR, a framework for pre-empting Advanced Persist...
research
05/20/2021

A Rule Mining-Based Advanced Persistent Threats Detection System

Advanced persistent threats (APT) are stealthy cyber-attacks that are ai...
research
01/19/2023

System on Chip Rejuvenation in the Wake of Persistent Attacks

To cope with the ever increasing threats of dynamic and adaptive persist...
research
11/25/2021

Computer Vision User Entity Behavior Analytics

Insider threats are costly, hard to detect, and unfortunately rising in ...
research
12/16/2021

APTSHIELD: A Stable, Efficient and Real-time APT Detection System for Linux Hosts

Advanced Persistent Threat (APT) attack usually refers to the form of lo...

Please sign up or login with your details

Forgot password? Click here to reset