Laccolith: Hypervisor-Based Adversary Emulation with Anti-Detection
Fuente:
arXiv
Saved in:
| Main Authors: | , , , |
|---|---|
| Format: | Preprint |
| Published: |
2023
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
| _version_ | 1866909183426691072 |
|---|---|
| author | Orbinato, Vittorio Feliciano, Marco Carlo Cotroneo, Domenico Natella, Roberto |
| author_facet | Orbinato, Vittorio Feliciano, Marco Carlo Cotroneo, Domenico Natella, Roberto |
| contents | Advanced Persistent Threats (APTs) represent the most threatening form of attack nowadays since they can stay undetected for a long time. Adversary emulation is a proactive approach for preparing against these attacks. However, adversary emulation tools lack the anti-detection abilities of APTs. We introduce Laccolith, a hypervisor-based solution for adversary emulation with anti-detection to fill this gap. We also present an experimental study to compare Laccolith with MITRE CALDERA, a state-of-the-art solution for adversary emulation, against five popular anti-virus products. We found that CALDERA cannot evade detection, limiting the realism of emulated attacks, even when combined with a state-of-the-art anti-detection framework. Our experiments show that Laccolith can hide its activities from all the tested anti-virus products, thus making it suitable for realistic emulations. |
| format | Preprint |
| id |
arxiv_https___arxiv_org_abs_2311_08274 |
| institution | arXiv |
| publishDate | 2023 |
| record_format | arxiv |
| spellingShingle | Laccolith: Hypervisor-Based Adversary Emulation with Anti-Detection Orbinato, Vittorio Feliciano, Marco Carlo Cotroneo, Domenico Natella, Roberto Cryptography and Security Operating Systems Advanced Persistent Threats (APTs) represent the most threatening form of attack nowadays since they can stay undetected for a long time. Adversary emulation is a proactive approach for preparing against these attacks. However, adversary emulation tools lack the anti-detection abilities of APTs. We introduce Laccolith, a hypervisor-based solution for adversary emulation with anti-detection to fill this gap. We also present an experimental study to compare Laccolith with MITRE CALDERA, a state-of-the-art solution for adversary emulation, against five popular anti-virus products. We found that CALDERA cannot evade detection, limiting the realism of emulated attacks, even when combined with a state-of-the-art anti-detection framework. Our experiments show that Laccolith can hide its activities from all the tested anti-virus products, thus making it suitable for realistic emulations. |
| title | Laccolith: Hypervisor-Based Adversary Emulation with Anti-Detection |
| topic | Cryptography and Security Operating Systems |
| url | https://arxiv.org/abs/2311.08274 |