Laccolith: Hypervisor-Based Adversary Emulation with Anti-Detection

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Orbinato, Vittorio, Feliciano, Marco Carlo, Cotroneo, Domenico, Natella, Roberto
Format: Preprint
Published: 2023
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909183426691072
author Orbinato, Vittorio
Feliciano, Marco Carlo
Cotroneo, Domenico
Natella, Roberto
author_facet Orbinato, Vittorio
Feliciano, Marco Carlo
Cotroneo, Domenico
Natella, Roberto
contents Advanced Persistent Threats (APTs) represent the most threatening form of attack nowadays since they can stay undetected for a long time. Adversary emulation is a proactive approach for preparing against these attacks. However, adversary emulation tools lack the anti-detection abilities of APTs. We introduce Laccolith, a hypervisor-based solution for adversary emulation with anti-detection to fill this gap. We also present an experimental study to compare Laccolith with MITRE CALDERA, a state-of-the-art solution for adversary emulation, against five popular anti-virus products. We found that CALDERA cannot evade detection, limiting the realism of emulated attacks, even when combined with a state-of-the-art anti-detection framework. Our experiments show that Laccolith can hide its activities from all the tested anti-virus products, thus making it suitable for realistic emulations.
format Preprint
id arxiv_https___arxiv_org_abs_2311_08274
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle Laccolith: Hypervisor-Based Adversary Emulation with Anti-Detection
Orbinato, Vittorio
Feliciano, Marco Carlo
Cotroneo, Domenico
Natella, Roberto
Cryptography and Security
Operating Systems
Advanced Persistent Threats (APTs) represent the most threatening form of attack nowadays since they can stay undetected for a long time. Adversary emulation is a proactive approach for preparing against these attacks. However, adversary emulation tools lack the anti-detection abilities of APTs. We introduce Laccolith, a hypervisor-based solution for adversary emulation with anti-detection to fill this gap. We also present an experimental study to compare Laccolith with MITRE CALDERA, a state-of-the-art solution for adversary emulation, against five popular anti-virus products. We found that CALDERA cannot evade detection, limiting the realism of emulated attacks, even when combined with a state-of-the-art anti-detection framework. Our experiments show that Laccolith can hide its activities from all the tested anti-virus products, thus making it suitable for realistic emulations.
title Laccolith: Hypervisor-Based Adversary Emulation with Anti-Detection
topic Cryptography and Security
Operating Systems
url https://arxiv.org/abs/2311.08274