arrow
Return

Detecting lateral movement: A systematic survey

delete2024-02-01
delete7
delete
OA
AI
C
Christos Smiliotopoulos *
G
Georgios Kambourakis
C
Constantinos Kolias
DOI:10.1016/j.heliyon.2024.e26317delete
deleteOriginal
deleteShare
deleteSave
View PDF
Abstract

Abstract

En 中文
Within both the cyber kill chain and MITRE ATT&CK frameworks, Lateral Movement (LM) is defined as any activity that allows adversaries to progressively move deeper into a system in seek of high-value assets. Although this timely subject has been studied in the cybersecurity literature to a significant degree, so far, no work provides a comprehensive survey regarding the identification of LM from mainly an Intrusion Detection System (IDS) viewpoint. To cover this noticeable gap, this work provides a systematic, holistic overview of the topic, not neglecting new communication paradigms, such as the Internet of Things (IoT). The survey part, spanning a time window of eight years and 53 articles, is split into three focus areas, namely, Endpoint Detection and Response (EDR) schemes, machine learning oriented solutions, and graph-based strategies. On top of that, we bring to light interrelations, mapping the progress in this field over time, and offer key observations that may propel LM research forward.
Keywords:
Lateral movement
Advanced persistent threat
Attacks
Network security
IoT
AI Summary

AI Summary

Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.

Journal

Heliyon cover
Heliyon
IF:
3.6
Papers:
3.8W
Citations:
10.5W

Organization

U
university of idaho
Scholars:
5.1K
Papers: 4.6K
Citations: 0
U
University of Aegean
Scholars:
1.8K
Papers: 1.6K
Citations: 5