
Brian Donahue discusses the misconception of an ever-evolving threat landscape in cybersecurity, arguing that adversaries recycle techniques rather than innovate. He presents data from Red Canary's Threat Detection Reports, highlighting the prevalence of certain attack techniques and the importance of focusing on these 'forever techniques' for effective threat detection.
In the realm of cybersecurity, the phrase "ever-evolving threat landscape" is often thrown around, but Brian Donahue, a principal security researcher at Red Canary, challenges this notion. He argues that rather than evolving, adversaries are recycling techniques that have been used for years. This blog post delves into Donahue's insights presented at ATT&CKcon 6.0, where he outlines his theory of the never-evolving threat landscape and introduces the concept of "forever techniques."
Brian Donahue has over 15 years of experience in information security and has been a consistent presence at ATT&CK Con. His work at Red Canary involves analyzing threats and techniques to compile the annual Threat Detection Report, which serves as a comprehensive resource for understanding the current threat landscape.
Donahue begins by stating his conclusion upfront: the idea of an ever-evolving threat landscape is misleading. Instead, he posits that adversaries tend to use a relatively small set of techniques repeatedly. This observation is based on extensive data analysis from Red Canary's Threat Detection Reports, which have documented over 265,000 confirmed threats and 287,000 technique mappings.
Donahue's analysis reveals that a significant portion of detected threats involves a limited number of techniques. For instance, 75% of total detection volume involved at least one of the top 30 techniques, while 50% included one of the top 10 techniques. This consistency suggests that many breaches rely on familiar methods rather than novel approaches.
Donahue introduces the term "forever techniques" to describe the attack methods that persist over time. He emphasizes that while new threats may emerge, they are often exceptions rather than the rule. The majority of attacks utilize well-known techniques that have been documented for years.
Donahue highlights a common misconception in cybersecurity reporting: the belief that threats are constantly evolving. He argues that many reports exaggerate the novelty of threats, often due to confusion over terminology or changes in visibility and technology. For example, an increase in reported identity threats may simply reflect improved detection capabilities rather than a surge in actual threats.
Visibility plays a crucial role in shaping perceptions of the threat landscape. As organizations enhance their detection capabilities, they may observe an uptick in certain types of threats that were previously undetected. This does not necessarily indicate a rise in new threats but rather an improvement in monitoring.
Donahue shares insights from Red Canary's data, listing the top techniques that have consistently appeared in their reports. These techniques include:
He encourages organizations to focus their detection efforts on these techniques, as they are likely to be involved in the majority of breaches.
To illustrate his points, Donahue examines recent threat campaigns, such as Salt Typhoon and UAT-8099. He notes that while these campaigns may appear sophisticated, they often rely on established techniques that have been documented extensively in the cybersecurity community. For instance, Salt Typhoon exploits known vulnerabilities and uses rootkits, which are not new concepts in the field.
Donahue concludes his talk with practical advice for organizations:
In summary, Brian Donahue's insights challenge the prevailing narrative of an ever-evolving threat landscape. By recognizing that many adversaries recycle techniques, cybersecurity professionals can better focus their efforts on detecting and mitigating the most prevalent threats. Understanding the importance of forever techniques can lead to more effective security strategies and a more resilient defense against cyber threats.
Paste a YouTube link and let Magica create the key takeaways.
Summarize another video