2023
DOI: 10.1007/s10207-023-00725-8
|View full text |Cite
|
Sign up to set email alerts
|

On the detection of lateral movement through supervised machine learning and an open-source tool to create turnkey datasets from Sysmon logs

Abstract: Lateral movement (LM) is a principal, increasingly common, tactic in the arsenal of advanced persistent threat (APT) groups and other less or more powerful threat actors. It concerns techniques that enable a cyberattacker, after establishing a foothold, to maintain ongoing access and penetrate further into a network in quest of prized booty. This is done by moving through the infiltrated network and gaining elevated privileges using an assortment of tools. Concentrating on the MS Windows platform, this work pr… Show more

Help me understand this report
View preprint versions

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1

Citation Types

0
2
0

Year Published

2023
2023
2024
2024

Publication Types

Select...
4
1
1
1

Relationship

1
6

Authors

Journals

citations
Cited by 10 publications
(2 citation statements)
references
References 24 publications
0
2
0
Order By: Relevance
“…Cybersecurity is becoming increasingly critical for various sectors, including government organizations and private enterprises. The rapid escalation of cyberattacks and emerging legislation demand enhanced data-protection measures [138,139]. Blockchain and distributed ledger technology offer novel solutions for safeguarding information in both decentralized and centralized network systems [140].…”
Section: Cybersecuritymentioning
confidence: 99%
“…Cybersecurity is becoming increasingly critical for various sectors, including government organizations and private enterprises. The rapid escalation of cyberattacks and emerging legislation demand enhanced data-protection measures [138,139]. Blockchain and distributed ledger technology offer novel solutions for safeguarding information in both decentralized and centralized network systems [140].…”
Section: Cybersecuritymentioning
confidence: 99%
“…In 150 countries, 300,000 users were targeted, resulting in $8 billion in damages [8]. Attackers steal sensitive data such as classified state secrets and bank accounts [9]. Cybersecurity has, therefore, become a major concern to states, organizations, and individuals [10].…”
Section: Introductionmentioning
confidence: 99%