2024
DOI: 10.1109/access.2024.3357525
|View full text |Cite
|
Sign up to set email alerts
|

Effects of Removing User-Land Hooks in Endpoint Protection During Attack Experiments

Trevor M. Lewis,
Bhaskar P. Rimal

Abstract: This paper conducts research on current-generation Endpoint Detection and Response (EDR) solution design that identifies fundamental gaps in the prevention and detection of malicious cyber techniques. These fundamental gaps are the result of using "user-land hooks" or "user-mode hooks" into user and system processes as the sole mechanism to detect malicious cyber activity on endpoints (workstations and servers). When these user-land hooks are removed from processes, the EDR solution no longer has visibility in… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...

Citation Types

0
0
0

Year Published

2024
2024
2024
2024

Publication Types

Select...
1

Relationship

0
1

Authors

Journals

citations
Cited by 1 publication
references
References 9 publications
0
0
0
Order By: Relevance