Why is Threat Detection Hard?. While creating a recent presentation, I… | by Anton Chuvakin | Anton on Security | Medium
While creating a recent presentation, I needed a slide on “threat detection is hard.” And it got me thinking, why is threat detection so hard for so many organizations today? We can trace the “cyber” threat detection to 1986 (“Cuckoo’s Egg”) and 1987 (first IDS) and perhaps even earlier events (like viruses of the early 1980s). This means we are “celebrating” ~35 years of cyber threat detection. However, many organizations would gladly tell you today, in 2020, that “detection is hard” for them. But why? Naturally, I posted my draft slide on Twitter and lively discussion ensued. As I result, I updated my slide to this: Now, let’s talk about it as this can be useful to those organizations that are in the beginning stages of their detection journey. To start, surely many people think that threat detection is hard because threat actors do not want to be detected (duh!). This is an understandable, but, in my opinion, a naive view. Attackers do need to remain unseen until their goals are acc
While creating a recent presentation, I needed a slide on “threat detection is hard.” And it got me thinking, why is threat detection so hard for so many organizations today? We can trace the “cyber” threat detection to 1986 (“Cuckoo’s Egg”) and 1987 (first IDS) and perhaps even earlier events (like viruses of the early 1980s). This means we are “celebrating” ~35 years of cyber threat detection. However, many organizations would gladly tell you today, in 2020, that “detection is hard” for them. But why? Naturally, I posted my draft slide on Twitter and lively discussion ensued. As I result, I
Explore this link on the map →