Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - Gartner Five Styles of Advanced Threat Defense – Explained
News & Analysis

Gartner Five Styles of Advanced Threat Defense – Explained

ISBuzz TeamBy ISBuzz TeamOctober 17, 2013Updated:July 3, 20244 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Gartner Logo
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Gartner last month released its “Five styles of Advanced Threat Defense” framework which attempts to update a layered defence model for enterprises to be able to protect against APTs (Advanced Persistent Threats) or ATAs (Advanced Targeted Attacks because, it says,  “traditional defence tools are failing to protect enterprises from advanced targeted attacks and the broader problem of advanced malware.  In 2013, enterprises will spend more than $13 billion on firewalls, intrusion prevention systems (IPSs), endpoint protection platforms and secure web gateways. Yet, advanced targeted attacks (ATAs) and advanced malware continue to plague enterprises.”

Commenting on this, TK Keanini CTO of network visibility and security intelligence company Lancope, said: “Good bank robbers are skilled at breaking in to banks, great bank robbers are skilled at making it out undetected.  The key issue here is advanced persistence and the cost-effective detection of such a threat.  This threat is highly skilled at going undetected and a well implemented defense is one where they have nowhere to hide.   Essentially, you have to make this hiding expensive to them.  Once detected, they have to go back and retool, they have to switch from automated to manual; all of these steps raise their cost of doing business and that is a good thing. ”

TK’s colleague and director of security research for Lancope, Tom Cross, added: ” Sophisticated attackers are able to evade many traditional defences. They are able to obfuscate malware so that it is not detected by anti-virus and they target 0-day vulnerabilities for which there is no patch and no IDS signature. Defending a network against these attackers requires having a holistic view of all of the attackers behaviour, before, during, and post compromise, and it involves being able to find things when you’re not exactly sure what you are looking for. Strategies based on white-listing known good activity and looking for behavioural anomalies are going to be more effective than strategies that focus on blacklisting known bad behaviours. In addition, enterprises need to go beyond monitoring their perimeter for attacks coming into their network and develop visibility inside their networks that allows them to hunt for compromises in progress. They also need audit trails that enable them to rewind the clock once they’ve discovered evidence of an attack and develop a complete picture of how it unfolded.”

Gartner says by combining the styles diagonally through its framework, enterprises can create the most effective APT defense technology strategy.

Conrad Constantine, research team engineer for security information and event management firm AlienVault suggests that we also need to look beyond technology and look internally to get a more holistic approach:

“My “Power 3” for making life difficult for the bad guys is completely technology-agnostic:

#1 Employ System administrators who actually reads their system’s log files!
You can hire 100 security analysts to look over your centralised log storage of every system in your infrastructure – but they will never know those systems as well as the person who administrates them on a day to day basis. The diligent sys-admin who reads the logs and can come to the security team and easily point to events, saying “This shouldn’t happen normally” can be the most powerful detection control you have.

#2 Compartmentalise and Define your Administrative Activities.
Defining what is and what is not normal within the complexities of modern computing systems can be like emptying the ocean with a cup. Instead, define what is normal for /your business procedures/ and alert on anything divergent from that. If you know that all remote desktop sessions using administrative credentials must originate from a trusted admin-only terminal server, locating the potentially malicious sessions becomes a simple process of elimination.

#3 Don’t leave instructions for an intruder!
As any professional pen-tester will tell you, the best source of information about what to attack next (and how to attack it) are often provided to them by system administrators leaving notes for themselves in ‘temporary’ documents on systems – lists of system information, plain text credentials, notes about the account they’ve just reset to a default password ‘temporarily’, while they debug a problem. An administrator’s home directory on a system is often the very first place an attacker will examine once they have control of a system – and that goes for metadata documents as well – an administrator’s command line history is an open book about the layout of the system and the other systems they work on.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read

Why OSINT deserves the same status as other intelligence disciplines

March 17, 20266 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}