首页> 外文会议>IEEE International Symposium on Service Oriented System Engineering >Towards a Framework to Detect Multi-stage Advanced Persistent Threats Attacks
【24h】

Towards a Framework to Detect Multi-stage Advanced Persistent Threats Attacks

机译:朝着框架检测多阶段高级持续威胁攻击

获取原文

摘要

Detecting and defending against Multi-Stage Advanced Persistent Threats (APT) Attacks is a challenge for mechanisms that are static in its nature and are based on blacklisting and malware signature techniques. Blacklists and malware signatures are designed to detect known attacks. But multi-stage attacks are dynamic, conducted in parallel and use several attack paths and can be conducted in multi-year campaigns, in order to reach the desired effect. In this paper the design principles of a framework are presented that model Multi-Stage Attacks in a way that both describes the attack methods as well as the anticipated effects of attacks. The foundation to model behaviors is by the combination of the Intrusion Kill-Chain attack model and defense patterns (i.e. a hypothesis based approach of known patterns). The implementation of the framework is made by using Apache Hadoop with a logic layer that supports the evaluation of a hypothesis.
机译:检测和防御多阶段高级持久威胁(APT)攻击是对其性质静态的机制的挑战,并且基于黑名单和恶意软件签名技术。黑名单和恶意软件签名旨在检测已知的攻击。但是,多阶段攻击是动态的,并行进行并使用多个攻击路径,可以在多年的运动中进行,以达到所需的效果。在本文中,介绍了框架的设计原则,以一种模型多级攻击,以一种方式描述了攻击方法以及攻击的预期效果。模型行为的基础是通过入侵杀戮链攻击模型和防御模式的组合(即,已知模式的假设方法)。通过使用Apache Hadoop使用支持评估假设的逻辑层来实现框架的实现。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号