Are we there yet? An Industrial Viewpoint on Provenance-based Endpoint Detection and Response Tools


연구 분야: Safety



학회: CCS '23: Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security


초록

Provenance-Based Endpoint Detection and Response (P-EDR) systems are deemed crucial for future Advanced Persistent Threats (APT) defenses. Despite the fact that numerous new techniques to improve P-EDR systems have been proposed in academia, it is still unclear whether the industry will adopt P-EDR systems and what improvements the industry desires for P-EDR systems. To this end, we conduct the first set of systematic studies on the effectiveness and the limitations of P-EDR systems. Our study consists of four components: a one-to-one interview, an online questionnaire study, a survey of the relevant literature, and a systematic measurement study. Our research indicates that all industry experts consider P-EDR systems to be more effective than conventional Endpoint Detection and Response (EDR) systems. However, industry experts are concerned about the operating cost of P-EDR systems. In addition, our research reveals three significant gaps between academia and industry (1) overlooking client-side overhead; (2) imbalancedalarm triage cost and interpretation cost; and (3) excessive server side memory consumption. This paper's findings provide objective data on the effectiveness of P-EDR systems and how much improvements are needed to adopt P-EDR systems in industry.


Author Profile
Ding Li

Peking University Beijing China

China
Author Profile
Yao Guo

Peking University Beijing China

China
Author Profile
Xiangqun Chen

Peking University Beijing China

China

📄 논문 정보

발행 연도 2023년
인용수 15
출판 국가 Azerbaijan, Andorra, China, Hong Kong
사이트 ACM
좋아요 수 0

연관 논문 목록 (112건)