The Cyber Security Review | Thursday, June 08, 2023
Automated moving target defence (AMTD) is an emerging game-changing technology for improving cyber defence that effectively mitigates many known threats and is likely to reduce most zero-day exploits within a decade.
Anti-virus (AV) software, which performs a static analysis of binaries and files to see if they match known viruses, is where the evolution of cybersecurity began. Dynamic analysis, which runs and monitors a file in a sandboxed environment, was added by next-generation anti-virus (NGAV) software and endpoint protection systems. By using behavioural analysis, endpoint detection and response (EDR/XDR/MDR) advanced this. Computer execution is monitored, syscalls and functions are hooked, and everything that occurs before and after the binary is analysed to understand behaviour in real time.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
The system known as moving target defence (MTD) is the next step in cybersecurity, and unlike earlier solutions, it focuses on prevention rather than detection and reaction. A moving target is more challenging to assault than a fixed one, which is the fundamental tenet of MTD. To make it further sophisticated and unclear for attackers, MTD employs tactics that manage movement or changes in IT environments throughout the attack surface. Automated MTD increases the cost of reconnaissance and malicious exploitation on the attacker while decreasing exposed attack surfaces by introducing strategic change. To stop an adversary's cyber death chain, AMTD entails shifting, altering, obfuscating, or morphing attack surfaces.
Four key components are included in the technology: proactive cyber defence mechanisms, automation to orchestrate movement or change in the attack surface, the employment of deception technologies, and the capacity to carry out intelligent (preplanned) modification decisions. For instance, automated relocating target defence technology creates a randomised, dynamic runtime memory environment using system polymorphism, relocating operating system resources like application memory and APIs while leaving decoy traps in their place. As a result, threat actors will find it almost impossible to find what they're looking for. Any code that tries to run on a fake system resource is automatically reported and recorded for forensic investigation, protecting real system resources and stopping the attack.
For many years, AMTD has been successful in military doctrine when it comes to modern battle tactics. Although historically there hasn't been much AMTD deployment in business cybersecurity, things are starting to change. Various new security technologies, instantly change security protocols and supporting technologies to put more pressure on attackers, making them work harder or give up on their nefarious plans. The cybersecurity industry is currently dominated by reactive, detection-based technologies, including next-generation anti-virus (NGAV), endpoint protection platforms (EPP), and endpoint detection and response (EDR/XDR/MDR). For these technologies to function, precarious data or behavioural patterns must first be detected.
Given the effort attackers expend on attack reconnaissance to identify vulnerabilities and the best way to exploit a victim's systems, AMTD's preventive approach is especially crucial. Modern cyberattacks frequently have very precise targets and are designed to avoid and get past particular protection layers.
A host of industries and industrial settings make it challenging for hostile actors to obtain the necessary intelligence. Obfuscation and system morphing are effective AMTD techniques for defending against such narrowly focused attacks. This preventive strategy works particularly well for protecting server workloads and endpoints, which are often an organisation's biggest points of vulnerability.
By 2025, experts predict that 25 per cent of cloud apps will utilise AMTD features and concepts as integrated preventative strategies, strengthening WAAP (Cloud Web Application and API Protection). The company also projects that, up from less than two per cent in 2023, AMTD-based solutions will displace at least 15 per cent of traditional solutions that are focused on detection and response only [by 2025]. By 2030, it's expected that hardware and software built on the exploit-resistant AMTD architecture will start to appear. This shifts security focus further to business process, identity misuse, and social engineering prevention over the application, endpoint, and workload security strategies. An illustration of AMTD automation includes
• Choosing the target assets
• Choosing morphing interval
• Reconfiguring assets automatically
Malicious file signatures from prior attacks are needed for cybersecurity solutions like NGAV to recognize malicious files to detect and react to them. To identify and react to them, tools like EPP and EDR/XDR/MDR need to be able to recognize behaviour patterns from prior attacks. And under these conditions, these instruments perform admirably.
The current generation of detection-focused systems has significant flaws due to defence evasion and runtime memory attacks. These conclusions were supported by real-world data by Morphisec, which included 5,000+ customers, nine million endpoints, and 30,000 daily occurrences. At least three of the top 10 most common and harmful MITRE ATT&CK tactics are difficult for detection-based solutions to thwart, representing a major 30 per cent security gap. While these threats and more are constantly stopped by Morphisec's prevention-first, endpoint and server AMTD software.
AMTD was created primarily to solve this security hole and thwart evasive, unidentified, and runtime memory-targeting attacks. Additionally, it accomplishes this while reducing false positive alerts and the demand for analyst investigation. AMTD significantly lowers the total cost of ownership thanks to an incredibly lightweight agent that doesn't affect performance, quick deployment, simple tech stack integration, and no maintenance or updates required.
More in News