首页> 外文期刊>Computational Social Systems, IEEE Transactions on >Creation and Management of Social Network Honeypots for Detecting Targeted Cyber Attacks
【24h】

Creation and Management of Social Network Honeypots for Detecting Targeted Cyber Attacks

机译:创建和管理用于检测目标网络攻击的社交网络蜜罐

获取原文
获取原文并翻译 | 示例
       

摘要

Reconnaissance is the initial and essential phase of a successful advanced persistent threat (APT). In many cases, attackers collect information from social media, such as professional social networks. This information is used to select members that can be exploited to penetrate the organization. Detecting such reconnaissance activity is extremely hard because it is performed outside the organization premises. In this paper, we propose a framework for management of social network honeypots to aid in detection of APTs at the reconnaissance phase. We discuss the challenges that such a framework faces, describe its main components, and present a case study based on the results of a field trial conducted with the cooperation of a large European organization. In the case study, we analyze the deployment process of the social network honeypots and their maintenance in real social networks. The honeypot profiles were successfully assimilated into the organizational social network and received suspicious friend requests and mail messages that revealed basic indications of a potential forthcoming attack. In addition, we explore the behavior of employees in professional social networks, and their resilience and vulnerability toward social network infiltration.
机译:侦察是成功的高级持续威胁(APT)的初始和必不可少的阶段。在许多情况下,攻击者从社交媒体(例如专业社交网络)收集信息。此信息用于选择可用于渗透组织的成员。检测此类侦查活动非常困难,因为它是在组织场所之外执行的。在本文中,我们提出了一个用于管理社交网络蜜罐的框架,以帮助在侦察阶段检测APT。我们讨论了这样一个框架所面临的挑战,描述了它的主要组成部分,并基于与一个大型欧洲组织合作进行的现场试验的结果提出了一个案例研究。在案例研究中,我们分析了社交网络蜜罐的部署过程及其在实际社交网络中的维护。蜜罐配置文件已成功吸收到组织的社交网络中,并收到可疑的好友请求和邮件,这些邮件显示了潜在攻击即将来临的基本迹象。此外,我们探索了员工在专业社交网络中的行为,以及他们对社交网络渗透的弹性和脆弱性。

著录项

  • 来源
  • 作者单位

    Department of Software and Information Systems Engineering, Ben-Gurion University of the Negev, Beer-Sheva, Israel;

    Department of Software and Information Systems Engineering, Ben-Gurion University of the Negev, Beer-Sheva, Israel;

    Department of Software and Information Systems Engineering, Ben-Gurion University of the Negev, Beer-Sheva, Israel;

    Department of Software and Information Systems Engineering, Ben-Gurion University of the Negev, Beer-Sheva, Israel;

    Department of Software and Information Systems Engineering, Ben-Gurion University of the Negev, Beer-Sheva, Israel;

    Deutsche Telekom AG (T-Systems and Telekom Innovation Laboratories), Berlin, Germany;

    Bosch Center for Artificial Intelligence, Renningen, Germany;

  • 收录信息
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    Social network services; Reconnaissance; Electronic mail; Tools; Companies;

    机译:社交网络服务;侦察;电子邮件;工具;公司;
  • 入库时间 2022-08-18 00:00:17

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号