When the Cure Hurts: A Zero-Trust Monitoring Design for Active Directory and the Containment-Risk Trade-off
编号:86 访问权限:仅限参会人 更新:2026-10-04 23:36:57 浏览:17次 In-person

报告开始:2026年10月13日 10:00(Asia/Ho_Chi_Minh)

报告时间:15min

所在会场:[S5] Track 5: Emerging Trends of AI/ML [S5-1] Track 5: Emerging Trends of AI/ML

演示文件

提示:该报告下的文件权限为仅限参会人,您尚未登录,暂时无法查看。

摘要
Microsoft Active Directory (AD) is the identity backbone of enterprises and a prime target for adversaries. The ZeroTrust “assume breach” paradigm prescribes automated containment (disabling accounts upon alert), yet the literature focuses overwhelmingly on detection efficacy, leaving the operational risks of automated response largely unexplored. We deployed a Zero-Trust monitoring architecture for on-premises AD in an isolated laboratory: least-privilege provisioning, continuous verification (MFA with workstation restrictions), and assumebreach detection via a Wazuh SIEM with 13 custom MITREaligned rules and an Active-Response containment script. We evaluated the deployment against six end-to-end attack chains, including Shadow Credentials, AS-REP Roasting, and DCSync. The three Zero-Trust pillars intercepted exploits at distinct kill-chain stages. The deployment, however, surfaced a structural containment-risk trade-off: the automated response that halted a severe AD Certificate Services exploit also disabled the Administrator account, revealing a “privileged-account selfdenial-of-service” (self-DoS) failure mode that would paralyse the domain under a false positive. We characterise this failure mode as a structurally implied consequence of unconstrained assumebreach logic, argue its false-positive blast radius qualitatively, and leave its empirical measurement to future work. To bound this risk without sacrificing containment speed, we propose a tiered containment architecture that mandates isolation (forced re-authentication and session revocation) rather than outright disabling for privileged accounts.
关键词
Active Directory,Zero Trust,SIEM,Wazuh,automated containment,MITRE ATT&CK,incident response,AD Certificate Services
报告人
Van Quan Nguyen
student Posts and Telecommunications Institute of Technology

稿件作者
Truong Duy Dinh Posts and Telecommunications Institute of Technology
Manh Tan Tran Posts and Telecommunications Institute of Technology
Duy Thanh Bui Posts and Telecommunications Institute of Technology
Van Quan Nguyen Posts and Telecommunications Institute of Technology
Tran Duc Le University of Wisconsin-Stout Polytechnic
发表评论
验证码 看不清楚,更换一张
全部评论
重要日期
  • 会议日期

    10月11日

    2026

    至

    10月14日

    2026

  • 12月30日 2025

    报告提交截止日期

  • 09月28日 2026

    提前注册日期

  • 10月10日 2026

    初稿截稿日期

  • 10月14日 2026

    注册截止日期

主办单位
United Societies of Science
承办单位
Posts and Telecommunications Institute of Technology
协办单位
IEEE Section
IEEE Vietnam Section
移动端
在手机上打开
小程序
打开微信小程序
客服
扫码或点此咨询