...
首页> 外文期刊>Information systems frontiers >Decepticon: a Theoretical Framework to Counter Advanced Persistent Threats
【24h】

Decepticon: a Theoretical Framework to Counter Advanced Persistent Threats

机译:Decepticon:抵御高级持续威胁的理论框架

获取原文
获取原文并翻译 | 示例
           

摘要

Deception has been proposed in the literature as an effective defense mechanism to address Advanced Persistent Threats (APT). However, administering deception in a cost-effective manner requires a good understanding of the attack landscape. The attacks mounted by APT groups are highly diverse and sophisticated in nature and can render traditional signature based intrusion detection systems useless. This necessitates the development of behavior oriented defense mechanisms. In this paper, we develop Decepticon (Deception-based countermeasure), a Hidden Markov Model based framework where the indicators of compromise (IoC) are used as the observable features to aid in detection. This theoretical framework also includes several models to represent the spread of APTs in a computer system. The presented framework can be used to select an appropriate deception script when faced with APTs or other similar malware and trigger an appropriate defensive response. The effectiveness of the models in a networked system is illustrated by considering a real APT type ransomware.
机译:在文献中提出了欺骗作为解决高级持续威胁(APT)的有效辩护机制。然而,以成本效益的方式管理欺骗需要良好地了解攻击景观。 APT组安装的攻击是高度多样化和复杂的性质,并且可以使传统的基于签名的入侵检测系统无用。这需要发展行为导向的防御机制。在本文中,我们开发了基于隐马尔可夫模型的Cafepticon(基于欺骗性的对策),其中基于Markov模型的框架,其中妥协(IOC)的指标用作可观察特征以帮助检测。该理论框架还包括多种模型来代表APTS在计算机系统中的扩展。呈现的框架可用于在面对APTS或其他类似恶意软件时选择适当的欺骗脚本,并触发适当的防御响应。通过考虑真正的APT型勒通软件,说明了网络系统中模型的有效性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号