首页> 外文会议>IEEE International Conference on Intelligence and Security Informatics >Identifying mobile malware and key threat actors in online hacker forums for proactive cyber threat intelligence
【24h】

Identifying mobile malware and key threat actors in online hacker forums for proactive cyber threat intelligence

机译:在网上黑客论坛中识别移动恶意软件和关键威胁演员,以获得主动网络威胁情报

获取原文

摘要

Cyber-attacks are constantly increasing and can prove difficult to mitigate, even with proper cybersecurity controls. Currently, cyber threat intelligence (CTI) efforts focus on internal threat feeds such as antivirus and system logs. While this approach is valuable, it is reactive in nature as it relies on activity which has already occurred. CTI experts have argued that an actionable CTI program should also provide external, open information relevant to the organization. By finding information about malicious hackers prior to an attack, organizations can provide enhanced CTI and better protect their infrastructure. Hacker forums can provide a rich data source in this regard. This research aims to proactively identify mobile malware and associated key authors. Specifically, we use a state-of-the-art neural network architecture, recurrent neural networks, to identify mobile malware attachments followed by social network analysis techniques to determine key hackers disseminating the mobile malware. Results of this study indicate that many identified attachments are zipped Android apps made by threat actors holding administrative positions in hacker forums. Our identified mobile malware attachments are consistent with some of the emerging mobile malware concerns as highlighted by industry leaders.
机译:即使有适当的网络安全控制,网络攻击是不断增加的,并且可以难以减轻缓解。目前,网络威胁情报(CTI)努力专注于内部威胁饲料,如防病毒和系统日志。虽然这种方法很有价值,但它的性质是反应性,因为它依赖于已经发生的活动。 CTI专家认为,可行的CTI计划还应提供与本组织有关的外部,开放信息。通过在攻击前查找有关恶意黑客的信息,组织可以提供增强的CTI并更好地保护其基础架构。黑客论坛可以在这方面提供丰富的数据源。本研究旨在主动识别移动恶意软件和相关关键作者。具体地,我们使用最先进的神经网络架构,经常性神经网络,以识别移动恶意软件附件,然后识别社交网络分析技术,以确定传播移动恶意软件的关键黑客。本研究的结果表明,许多已识别的附件是通过威胁演员在黑客论坛中持有行政职位的威胁演员制作的Zipped Android应用程序。我们所确定的移动恶意软件附件与行业领导者突出的一些新兴的移动恶意软件担忧一致。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号