flâneur — a map of the web's best reading

You Cannot Escape Me: Detecting Evasions of SIEM Rules in Enterprise Networks | USENIX

usenix.org · 2,684 words · saved by 1 readers

Many organizations rely on Security Information and Event Management (SIEM) systems to discover intruders in their network from security-related events such as host and firewall logs. However, our work shows that adversaries can easily evade a large fraction of popular SIEM detection rules that aim to detect malicious command executions on Windows systems. To mitigate these detection blind spots, we introduce a novel concept called adaptive misuse detection, which utilizes supervised machine learning to discover potential rule evasions while keeping false alerts to a minimum. Finally, we present our open-source proof-of-concept implementation of adaptive misuse detection, AMIDES, and demonstrate its fitness for application in large enterprise networks. Cyberattacks have grown into a major risk for organizations. Attackers often succeed to break into target systems despite elaborate preventive measures, with common consequences being data theft or sabotage. In this case, intruders shoul

February 5, 2024 Research Authors: Louis Hackländer-Jansen , Marco Herzog , Rafael Uetz Article shepherded by: Rik Farrow Many organizations rely on Security Information and Event Management (SIEM) systems to discover intruders in their network from security-related events such as host and firewall logs. However, our work shows that adversaries can easily evade a large fraction of popular SIEM detection rules that aim to detect malicious command executions on Windows systems. To mitigate these detection blind spots, we introduce a novel concept called adaptive misuse detection, which utilizes

Explore this link on the map →

related reading