An Empirical Assessment of Endpoint Security Systems Against Advanced Persistent Threats Attack Vectors

08/23/2021
by   George Karantzas, et al.
0

Advanced persistent threats pose a significant challenge for blue teams as they apply various attacks over prolonged periods, impeding event correlation and their detection. In this work, we leverage various diverse attack scenarios to assess the efficacy of EDRs and other endpoint security solutions against detecting and preventing APTs. Our results indicate that there is still a lot of room for improvement as state of the art endpoint security systems fail to prevent and log the bulk of the attacks that are reported in this work. Additionally, we discuss methods to tamper with the telemetry providers of EDRs, allowing an adversary to perform a more stealth attack.

READ FULL TEXT

Please sign up or login with your details

Forgot password? Click here to reset