首页> 外文期刊>Computers & Security >Detecting mobile advanced persistent threats based on large-scale DNS logs
【24h】

Detecting mobile advanced persistent threats based on large-scale DNS logs

机译:根据大规模DNS日志检测移动高级持久威胁

获取原文
获取原文并翻译 | 示例

摘要

Advanced persistent threats (APTs) are complex, sophisticated threats that attempt to steal sensitive information or destroy a target network system by performing continuous activities over an extended period. Originally, APT primarily target personal computers (PCs); however, experts have recently identified some APTs that attack mobile devices, i.e., mobile advanced persistent threats (MAPTs). MAPTs differ significantly from APTs that target PC platforms. MAPTs can act jointly with APTs that target PC platforms, i.e., a multiplatform APT attack that delivers payloads to both PCs and mobile devices. Multiplatform attacks render it difficult to detect APTs based on domain name system (DNS) logs. Owing to differences between mobile devices and PC devices, it is difficult to detect multiplatform APT attacks using previous detection methods. This paper analyzes several cases of MAPTs and multiplatform APT attacks and identifies some significant changes in comparison with individual MAPTs or APT attacks on PCs. Based on these changes, a method that uses DNS logs to detect multiplatform APTs is proposed. First, the proposed method determines whether the DNS request logs are a request record of a mobile device or PC. Subsequently, according to changes in the MAPT, different features are extracted from two separated parts of the data; subsequently, the detection effect is detected using several machine learning algorithms. The experiments demonstrate that the separation of DNS logs between PCs and mobile devices can increase the detection rate of multiplatform APTs by over 15%.
机译:高级持久威胁(APTS)是复杂的,复杂的威胁,试图通过在较长时期执行连续活动来窃取敏感信息或破坏目标网络系统。最初,APT主要针对个人计算机(PC);然而,专家最近确定了一些攻击移动设备的APTS,即移动高级持久威胁(MAPT)。映射从目标PC平台的APTS有显着差异。 MAPT可以与APTS共同采用,APTS以PC平台为目标PC平台,即,将有效载荷提供给PC和移动设备的多平台APT攻击。多平台攻击使得难以根据域名系统(DNS)日志来检测APTS。由于移动设备和PC设备之间的差异,难以使用先前的检测方法检测多平台APT攻击。本文分析了几个映射和多平台的情况APT攻击,并识别与个人映射或对PC的攻击相比的一些显着变化。基于这些变化,提出了一种使用DNS日志来检测多平台APTS的方法。首先,所提出的方法确定DNS请求日志是移动设备或PC的请求记录。随后,根据MAPT的变化,从数据的两个分隔部分中提取不同的特征;随后,使用多种机器学习算法检测检测效果。实验表明,PC和移动设备之间的DNS日志的分离可以将多平台APTS的检测速率增加超过15%。

著录项

  • 来源
    《Computers & Security》 |2020年第9期|101933.1-101933.12|共12页
  • 作者单位

    College of Computer Science and Technology Jilin University Changchun 130012 China;

    Key Laboratory of Symbolic Computation and Knowledge Engineering of Ministry of Education Jilin University Changchun China;

    College of Computer Science and Technology Jilin University Changchun 130012 China;

  • 收录信息 美国《科学引文索引》(SCI);美国《工程索引》(EI);
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    Multiplatform attack; Mobile advanced persistent threats (MAPTs); CC communication; DNS Logs;

    机译:多平台攻击;移动高级持久威胁(MAPT);C&C通信;DNS日志;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号