THIS document discusses the importance of Network Anomaly Detection (NAD) in identifying advanced persistent threats (APTs) that utilize common protocols like Kerberos and DNS for malicious activities. It highlights the challenges conventional detection tools face in spotting such attacks, particularly Kerberoasting and DNS tunneling, which often blend with legitimate traffic.
The document explains how Kaspersky's Anti Targeted Attack (KATA) platform uses NAD to analyze traffic anomalies instead of relying solely on signatures, with examples of how to detect Kerberoasting and DNS tunneling using specific detection logic and prebuilt rules. Key takeaways include the need for tailored detection models that account for unique network behaviors and the significance of monitoring deviations from established activity baselines to enhance security responses.