An Empirical Study of Automated Adversary Emulators

Loading...
Thumbnail Image

Contributor

Advisor

Editor

Performer

Department

Instructor

Depositor

Speaker

Researcher

Consultant

Interviewer

Interviewee

Narrator

Transcriber

Annotator

Journal Title

Journal ISSN

Volume Title

Publisher

Journal Name

Volume

Number/Issue

Starting Page

7028

Ending Page

Alternative Title

Abstract

Automated adversary emulators are increasingly researched and applied, but their effectiveness remains unclear. This paper empirically evaluates four emulators using data collected from 1700 hours of tests within a cyber range: Caldera, Deep Exploit, Infection Monkey, and Lore. The outcome from each test was scored according to fulfillment of different tactics in MITRE ATT&CK. The results show that Lore consistently discovered all machines and compromised 97% on average. Caldera discovered 27% and compromised 7%, Infection Monkey discovered 23% but compromised none, and Deep Exploit neither discovered nor compromised any machine. All emulators generated similar intrusion alerts except Caldera, which triggered significantly more when starting with elevated privileges.

Description

Citation

Extent

10 pages

Format

Type

Conference Paper

Geographic Location

Time Period

Related To

Proceedings of the 59th Hawaii International Conference on System Sciences

Related To (URI)

Table of Contents

Rights

Attribution-NonCommercial-NoDerivatives 4.0 International

Rights Holder

Catalog Record

Local Contexts

Email libraryada-l@lists.hawaii.edu if you need this content in ADA-compliant format.