已入深夜,您辛苦了!由于当前在线用户较少,发布求助请尽量完整地填写文献信息,科研通机器人24小时在线,伴您度过漫漫科研夜!祝你早点完成任务,早点休息,好梦!

Offensive Security: Towards Proactive Threat Hunting via Adversary Emulation

作者
Abdul Basit Ajmal,Munam Ali Shah,Carsten Maple,Muhammad Nabeel Asghar,Saif ul Islam
出处
期刊:IEEE Access [Institute of Electrical and Electronics Engineers]
卷期号:9: 126023-126033 被引量:56
标识
DOI:10.1109/access.2021.3104260
摘要

Attackers increasingly seek to compromise organizations and their critical data with advanced stealthy methods, often utilising legitimate tools. In the main, organisations employ reactive approaches for cyber security, focused on rectifying immediate incidents and preventing repeat attacks, through protections such as vulnerability assessment and penetration testing (VAPT) security information and event management (SIEM), firewalls, anti-spam/anti-malware solutions and system patches. Such system have weaknesses in addressing modern modern stealthy attacks. Proactive approaches, have been seen as part of the solution to this problem. However, approaches such as VAPT have limited scope and only works with threats that have already been discovered. Promising methods such as threat hunting are gaining momentum, enabling organisations to identify and rapidly respond to any potential attacks, though they have been criticised for their significant cost. In this paper, we present a novel hybrid model for uncovering tactics, techniques, and procedures (TTPs) through offensive security, specifically threat hunting via adversary emulation. The proposed technique is based on a novel approach of inducing adversary emulation (mapping each respective phase) model inside the threat hunting approach. The experimental results show that the proposed approach uses threat hunting via adversary emulation and has countervailing effects on hunting advance level threats. Moreover, the threat detection ability of the proposed approach utilizes minimum resources. The proposed approach can be used to develop the offensive security-aware environment for organizations to uncover advanced attack mechanisms and test their ability for attack detection.

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
刚刚
刚刚
科研通AI6.2应助漫天星斗采纳,获得10
刚刚
秦何发布了新的文献求助10
2秒前
三峡好人发布了新的文献求助10
3秒前
su应助哭泣的新晴采纳,获得10
4秒前
XQZ发布了新的文献求助80
4秒前
XQZ发布了新的文献求助10
4秒前
悦耳鹰发布了新的文献求助10
5秒前
6秒前
无辜夜云发布了新的文献求助20
6秒前
完美世界应助万事都灵采纳,获得10
7秒前
7秒前
涵涵涵涵完成签到 ,获得积分10
9秒前
10秒前
10秒前
Paranoid发布了新的文献求助10
10秒前
10秒前
10秒前
赘婿应助叫阴天别闹了采纳,获得10
11秒前
12秒前
小面面完成签到 ,获得积分10
13秒前
benben发布了新的文献求助10
13秒前
nkjingyi发布了新的文献求助10
14秒前
14秒前
張歪歪完成签到 ,获得积分10
16秒前
16秒前
科研通AI6.4应助神雕侠采纳,获得50
16秒前
16秒前
所所应助秦何采纳,获得10
16秒前
16秒前
柚子宝宝发布了新的文献求助10
17秒前
汤鱼发布了新的文献求助10
17秒前
华仔应助慈祥的梦蕊采纳,获得10
17秒前
Orange应助LI采纳,获得10
18秒前
专注的芷完成签到 ,获得积分10
18秒前
18秒前
18秒前
19秒前
小文发布了新的文献求助10
20秒前
高分求助中
(应助此贴封号)【重要!!请各用户(尤其是新用户)详细阅读】【科研通的精品贴汇总】 10000
HYDROLYSE ACIDE DE QUELQUES DIOXASPIROCYCLANES 1314
Essentials of Carbohydrate Chemistry and Biochemistry, 4th Edition 800
Navigating Normative Orders. Interdisciplinary Perspectives 800
1 Peter and Christ's Descent to the Dead in Its Early Christian Reception 700
Organizational Behavior 510
Management and the Arts 510
热门求助领域 (近24小时)
化学 材料科学 医学 生物 纳米技术 工程类 有机化学 化学工程 生物化学 计算机科学 内科学 物理 复合材料 催化作用 细胞生物学 无机化学 光电子学 物理化学 电极 基因
热门帖子
关注 科研通微信公众号,转发送积分 7749461
求助须知:如何正确求助?哪些是违规求助? 9297246
关于积分的说明 20239223
捐赠科研通 7330787
什么是DOI,文献DOI怎么找? 3309173
关于科研通互助平台的介绍 2460794
邀请新用户注册赠送积分活动 2321440