攻击者的困境

admin 2021年10月5日00:20:50评论56 views字数 1159阅读3分51秒阅读模式

攻击者的困境


1.防御者的困境


攻击者的困境

You've heard of the Defender's Dillema: "Defenders have to get it right every time. Attackers only have to get it right once."

Did you know this is a lie?

I think it was @Soinull who created the idea of the Attacker's Dilemma: defenders have many chances to defend across the entire kill chain. To be successful, attackers have to evade all the defenses in their chosen chain.
 
The Defender's Dilemma really only makes sense if you think of an "attack" as a single atomic thing, which of course it is not. Attacking a complex system will always be easier than defending it. The key to defender success is exploiting the home ground advantage.

Forget the Defender's Dilemma and recognize that we have a lot of chances to succeed. We may not have the resources to take them all, but by choosing wisely, we can make an attacker's job MUCH harder while giving ourselves the best chance of success.

2.攻击者的困境


攻击者的困境

“Attacker’s Dilemma”:
    How do they get to their goal and exfiltrate their target without tripping a single one of our detection ‘landmines’?


攻击者的困境


攻击者的困境


攻击者的困境

3.防御者如何思考?


攻击者的困境

1. Focus on the criminal’s activities rather than the tools and exploits
2. Use the attacker’s needs and techniques against them
3. Balance prevention, detection, and response appropriately
4. Invest in your people over your tools



攻击者的困境

攻击者的困境

攻击者的困境


攻击者的困境


往期精选


围观

威胁猎杀实战(六):横向移动攻击检测


热文

全球“三大”入侵分析模型


热文

实战化ATT&CK:威胁情报


攻击者的困境

本文始发于微信公众号(天御攻防实验室):攻击者的困境

  • 左青龙
  • 微信扫一扫
  • weinxin
  • 右白虎
  • 微信扫一扫
  • weinxin
admin
  • 本文由 发表于 2021年10月5日00:20:50
  • 转载请保留本文链接(CN-SEC中文网:感谢原作者辛苦付出):
                   攻击者的困境http://cn-sec.com/archives/382027.html

发表评论

匿名网友 填写信息