首页> 外文会议>International workshop on information security application >N-Victims: An Approach to Determine N-Victims for APT Investigations
【24h】

N-Victims: An Approach to Determine N-Victims for APT Investigations

机译:N受害者:确定APT调查的N受害者的方法

获取原文

摘要

The advanced Persistent Threat (APT) is a sophisticated and target-oriented cyber attack for accessing valuable information. The attacker leverages the customized malware as the stepping stone to intrude into the enterprise network. For enterprises and forensic analysts, finding the victims and investigating them to evaluate the damages are critical, but the investigation is often limited by resources and time. In this paper, we propose an N-Victims approach that starts from a known malware-infected computer to determine the top N most likely victims. We test our approach in a real APT case that happened in a large enterprise network consisting of several thousand computers, which run a commercial antivirus system. N-Victims can find more malware-infected computers than N-Gram based approaches. In the top 20 detected computers, N-Victims also had a higher detection rate and a lower false positive rate than N-Gram based approaches.
机译:先进的持久威胁(APT)是一种复杂的,面向目标的网络攻击,用于访问有价值的信息。攻击者利用定制的恶意软件作为入侵企业网络的垫脚石。对于企业和法医分析师而言,找到受害者并对其进行调查以评估损失至关重要,但是调查通常受到资源和时间的限制。在本文中,我们提出了一种N-受害者方法,该方法从一台已知的感染了恶意软件的计算机开始,确定最可能的N个受害者。我们在一个实际的APT案例中测试了我们的方法,该案例发生在一个大型企业网络中,该企业网络由数千台运行商业防病毒系统的计算机组成。与基于N-Gram的方法相比,N-受害者可以找到更多受恶意软件感染的计算机。在检测到的前20名计算机中,与基于N-Gram的方法相比,N-受害者还具有更高的检测率和更低的误报率。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号