An Empirical Study of Automated Adversary Emulators
Loading...
Files
Date
Authors
Contributor
Advisor
Editor
Performer
Department
Instructor
Depositor
Speaker
Researcher
Consultant
Interviewer
Interviewee
Narrator
Transcriber
Annotator
Journal Title
Journal ISSN
Volume Title
Publisher
Journal Name
Volume
Number/Issue
Starting Page
7028
Ending Page
Alternative Title
Abstract
Automated adversary emulators are increasingly researched and applied, but their effectiveness remains unclear. This paper empirically evaluates four emulators using data collected from 1700 hours of tests within a cyber range: Caldera, Deep Exploit, Infection Monkey, and Lore. The outcome from each test was scored according to fulfillment of different tactics in MITRE ATT&CK. The results show that Lore consistently discovered all machines and compromised 97% on average. Caldera discovered 27% and compromised 7%, Infection Monkey discovered 23% but compromised none, and Deep Exploit neither discovered nor compromised any machine. All emulators generated similar intrusion alerts except Caldera, which triggered significantly more when starting with elevated privileges.
Description
Citation
Extent
10 pages
Format
Type
Conference Paper
Geographic Location
Time Period
Related To
Proceedings of the 59th Hawaii International Conference on System Sciences
Related To (URI)
Table of Contents
Rights
Attribution-NonCommercial-NoDerivatives 4.0 International
Rights Holder
Catalog Record
Local Contexts
Collections
Email libraryada-l@lists.hawaii.edu if you need this content in ADA-compliant format.
