Laccolith: Hypervisor-Based Adversary Emulation With Anti-Detection

9Citations
Citations of this article
25Readers
Mendeley users who have this article in their library.

This article is free to access.

Abstract

Advanced Persistent Threats (APTs) represent the most threatening form of attack nowadays since they can stay undetected for a long time. Adversary emulation is a proactive approach for preparing against these attacks. However, adversary emulation tools lack the anti-detection abilities of APTs. We introduce Laccolith, a hypervisor-based solution for adversary emulation with anti-detection to fill this gap. We also present an experimental study to compare Laccolith with MITRE CALDERA, a state-of-the-art solution for adversary emulation, against five popular anti-virus products. We found that CALDERA cannot evade detection, limiting the realism of emulated attacks, even when combined with a state-of-the-art anti-detection framework. Our experiments show that Laccolith can hide its activities from all the tested anti-virus products, thus making it suitable for realistic emulations. prova.

Cite

CITATION STYLE

APA

Orbinato, V., Feliciano, M. C., Cotroneo, D., & Natella, R. (2024). Laccolith: Hypervisor-Based Adversary Emulation With Anti-Detection. IEEE Transactions on Dependable and Secure Computing, 21(6), 5374–5387. https://doi.org/10.1109/TDSC.2024.3376129

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free