Kaspersky's Anti Targeted Attack (ATA) solution incorporates Network Anomaly Detection (NAD) rules to identify and block suspicious network activity. To analyze how these rules function, we examined the use of Kerberoasting and DNS tunneling attacks as examples. Kerberoasting is a technique used by attackers to obtain sensitive information about a target's Active Directory infrastructure. By exploiting a vulnerability in the Kerberos authentication protocol, attackers can gain access to user credentials and other sensitive data. DNS tunneling, on the other hand, is a technique used to bypass network security controls by using DNS queries to transmit malicious data. In the context of NAD rules, these attacks serve as indicators of potential threats, which can be used to trigger an alert and initiate an investigation. Our analysis found that Kaspersky's NAD rules utilize a combination of machine learning algorithms and signature-based detection to identify and block suspicious activity. By analyzing network traffic patterns and applying machine learning models to detect anomalies, Kaspersky's NAD rules can detect potential threats in real-time. In addition, the solution incorporates a database of known vulnerabilities and exploits to enhance its threat detection capabilities.
Network Anomaly Detection in Kaspersky Anti Targeted Attack
An in-depth look at how Kaspersky's NAD rules utilize Kerberoasting and DNS tunneling attacks to identify potential threats
Source: Securelist (Kaspersky)