Publication | Closed Access
Towards a Framework to Detect Multi-stage Advanced Persistent Threats Attacks
104
Citations
4
References
2014
Year
Unknown Venue
EngineeringInformation SecuritySoftware EngineeringApache HadoopSoftware AnalysisHardware SecurityTargeted AttackData ScienceDenial-of-service AttackSystems EngineeringThreat (Computer)Intrusion Detection SystemThreat DetectionComputer ScienceData SecurityCryptographyMalware SignaturesMalware Signature TechniquesSoftware TestingCloud ComputingIntrusion DetectionThreat HuntingCyber Threat IntelligenceThreat Model
Detecting and defending against Multi-Stage Advanced Persistent Threats (APT) Attacks is a challenge for mechanisms that are static in its nature and are based on blacklisting and malware signature techniques. Blacklists and malware signatures are designed to detect known attacks. But multi-stage attacks are dynamic, conducted in parallel and use several attack paths and can be conducted in multi-year campaigns, in order to reach the desired effect. In this paper the design principles of a framework are presented that model Multi-Stage Attacks in a way that both describes the attack methods as well as the anticipated effects of attacks. The foundation to model behaviors is by the combination of the Intrusion Kill-Chain attack model and defense patterns (i.e. a hypothesis based approach of known patterns). The implementation of the framework is made by using Apache Hadoop with a logic layer that supports the evaluation of a hypothesis.
| Year | Citations | |
|---|---|---|
Page 1
Page 1