首页> 外文会议>European Conference on Information Warfare and Security >Proactive Cyber Defense: Understanding and Testing for Advanced Persistent Threats (APTs)
【24h】

Proactive Cyber Defense: Understanding and Testing for Advanced Persistent Threats (APTs)

机译:主动网络防御:了解和测试高级持久威胁(APTS)

获取原文

摘要

Government and critical infrastructure networks are increasingly reliant on cyberspace. This reliance is in stark contrast to the inadequacy of cybersecurity: Many of these networks used to be closed and lack the robustness needed to withstand cyber-attacks. As a result, vulnerabilities in network protocol implementations can be exploited with Internet hacking tools to disrupt operations or to steal sensitive information. Fuzzing is a black-box testing technique originally used by blackhat hackers to find exploitable vulnerabilities. In this paper, we demonstrate how specification-based fuzzers can be used to discover exploitable vulnerabilities proactively to make networks and devices more robust against cyber-attacks. Advanced Persistent Threats (APTs) typically utilize previously unknown, zero-day vulnerabilities. Thus, proactive vulnerability discovery is an essential part of effective cybersecurity.
机译:政府和关键基础设施网络越来越依赖网络空间。这种依赖性与网络安全不足的鲜明对比:许多用于关闭的这些网络中的许多网络且缺乏耐受网络攻击所需的稳健性。因此,可以利用网络协议实现中的漏洞来利用互联网黑客工具来破坏操作或窃取敏感信息。模糊是一个最初用于Blackhat黑客的黑匣子测试技术,以查找可利用的漏洞。在本文中,我们展示了基于规范的模糊,可以通过主动地发现可利用的漏洞,使网络和设备更加强大地反对网络攻击。高级持久威胁(APTS)通常利用以前未知的零漏零点。因此,主动漏洞发现是有效网络安全的重要组成部分。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号