CYBERSEC 2022 uses cookies to provide you with the best user experience possible. By continuing to use this site, you agree to the terms in our Privacy Policy. I Agree

bg-inner
Dr. Cheng Kun Wang

SPEAKER

Dr. Cheng Kun Wang

Researcher of Chung-Shan Institute of Science and Technology, Researcher of Telecom Labs., Chung-Hwa Telecom, Senior Consulting Engineer of Cisco System APAC, Senior Manager of Cisco System Japan, Senior Solution Architect of Cisco System Greater China, Technical Consultant of Attivo Networks.

Speech

Blue Team Forum

SEP 22

#

Why is MITRE Promoting the Engage Framework?

09/22 (Thu) 14:45 - 15:15 4F 4B
/ Dr. Cheng Kun Wang

With the help of MITRE ATT&CK, EDR technologies have improved steadily over the last few years to their current level of high maturity and sophistication. According to MITRE evaluation results, many vendors can now detect 80%, 90% of the steps of simulated attacks, while the best performing vendor can even provide 100% coverage. It is indeed a great achievement. However, in real-world scenarios, there will be a lot of noise that the attackers can leverage to hide their operation, and the task of detecting attackers is similar to “looking for a needle in a haystack.” This is the main reason why MITRE is now promoting the new Engage Framework, an active defense thinking to engage with the attackers in real-time, accurately detect their presence at very early stage of the security breach, and then cut them off to prevent damage to enterprise.