Go top
Conference paper information

Evaluation of local security event management system vs. standard antivirus software

A. Pérez-Sánchez, R. Palacios

VIII Jornadas Nacionales de Investigación en Ciberseguridad - JNIC 2023, Vigo (Spain). 21-23 June 2023


Summary:

The detection and classification of threats in computer systems has been one of the main problems researched in Cybersecurity. As technology evolves, the tactics employed by adversaries have also become more sophisticated to evade detection systems. In consequence, systems that previously detected and classified those threats are now outdated. This paper proposes a detection system based on the analysis of events and matching the risk level with the MITRE ATT&CK matrix and Cyber Kill Chain. Extensive testing of attacks, using nine malware codes and applying three different obfuscation techniques, was performed. Each malicious code was analyzed using the proposed event management system and also executed in a controlled environment to examine if commercial malware detection systems (antivirus) were successful. The results show that evading techniques such as obfuscation and in-memory extraction of malicious payloads, impose unexpected difficulties to standard antivirus software.


Keywords: SIEM; antivirus; event-based threat detection; MITRE; Cyber Kill Chain


Published in JNIC 2023, pp: 569-570, ISBN: 978-84-8158-970-2

Publication date: 2023-06-23.



Citation:
A. Pérez-Sánchez, R. Palacios, Evaluation of local security event management system vs. standard antivirus software, VIII Jornadas Nacionales de Investigación en Ciberseguridad - JNIC 2023, Vigo (Spain). 21-23 June 2023. In: JNIC 2023: Actas de las VIII Jornadas Nacionales de Investigación en Ciberseguridad. Vigo, 21 a 23 de junio de 2023, ISBN: 978-84-8158-970-2


    Research topics:
  • Cybersecurity: Cybercrime prevention, cybercrime detection