V-Help
← All news
Security

Why Signature-Based Defenses Miss Attacks: Behavior vs. Signatures

Why Signature-Based Defenses Miss Attacks: Behavior vs. Signatures

Photo: BleepingComputer

Quick answer

Signature-based security systems are losing effectiveness as they fail to detect attacks with altered behavior, even when the underlying technique remains unchanged.

Research by Picus Security, based on 338 million attack simulations in real corporate environments, reveals that the effectiveness of signature-based defenses is declining. The average attack block rate has risen to 69%, but this figure obscures critical gaps. Systems configured to detect known indicators of compromise (IOCs) fail to stop attacks when adversaries modify methods while retaining the same underlying technique.

The case of Mimikatz illustrates the issue clearly. Traditional credential theft via the LSASS process memory is blocked 94% of the time, but alternative methods—such as reading data from the registry or other memory regions—are only stopped in 3–17% of attempts. This occurs because signature-based systems focus on specific artifacts rather than attack behavior.

Within corporate networks, the situation is even worse: after an account is compromised, attacks are blocked only 37% of the time. The most vulnerable activities include passive credential reading (22%) and information gathering (10%). The research underscores the need for behavior-based security testing (TTP) rather than relying solely on signatures to uncover real weaknesses in defenses.

Addressing this issue doesn’t require expanding the security stack but rather a deeper analysis of existing systems. Automated tools like Picus Swarm enable organizations to test various attack scenarios and assess how defenses respond to real adversary behavior. This approach helps security teams make informed decisions about strengthening their protections.

Common questions

Why do signature-based defenses fail against modern attacks?
Signature-based systems only block known attack variants, failing to recognize modified versions. Attackers alter methods while keeping the same technique, allowing them to bypass defenses.
How can organizations test security to identify real vulnerabilities?
Behavioral testing (TTP-based) is essential. It evaluates how systems respond to attack actions rather than relying solely on signatures, revealing critical gaps in protection.
Which attacks are most frequently missed by defensive systems?
Credential theft attacks remain highly vulnerable, especially when executed through alternative methods like registry scraping or memory reads without standard tools.
Share:

Dzen feed: /feed/dzen.xml · RSS: /feed.xml

Why trust this

Prepared by the V-Help editorial team from the primary source with a published date.

Published by: V-Help.ru news desk

Source: BleepingComputer