A Framework for Advanced Persistent Threat Attribution using Zachman Ontology

被引:6
|
作者
Charan, P. V. Sai [1 ]
Chunduri, Hrushikesh [1 ]
Anand, P. Mohan [1 ]
Shukla, Sandeep K. [1 ]
机构
[1] Indian Inst Technol Kanpur, Kanpur, Uttar Pradesh, India
关键词
APT; Attribution Framework; Zachman Ontology; Cyber Criminology; Cyber Investigation;
D O I
10.1145/3590777.3590783
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Advanced Persistent Threat (APT) is a type of cyber attack that infiltrates a targeted organization and exfiltrates sensitive data over an extended period of time or to cause sabotage. Recently, there has been a trend of nation states backing APT groups in order to further their political and financial interests, making the APT attribution process increasingly important. The APT attribution process involves identifying the actors behind an attack and their motivations, using a method of logical inference called abductive reasoning to determine the most likely explanation for a set of observations. While various attribution methods and frameworks have been proposed by the security community, many of them lack granularity and are dependent on the skills of practitioners rather than a standardized process. This can hinder both the understandability and reproducibility of attribution efforts as this process is practiced but not engineered. To address these issues, we propose a new framework for the APT attribution process based on the Zachman ontology, which offers greater granularity by posing specific primitive questions at various levels of the attribution process. This allows for more accurate conclusions about the attackers and their motivations, helping organizations to better protect themselves against future attacks.
引用
收藏
页码:34 / 41
页数:8
相关论文
共 50 条
  • [1] A Novel Network Forensic Framework for Advanced Persistent Threat Attack Attribution Through Deep Learning
    Mei, Yangyang
    Han, Weihong
    Li, Shudong
    Lin, Kaihan
    Tian, Zhihong
    Li, Shumei
    IEEE TRANSACTIONS ON INTELLIGENT TRANSPORTATION SYSTEMS, 2024, 25 (09) : 12131 - 12140
  • [2] Rediscovering Zachman Framework using Ontology from a Requirement Engineering Perspective
    Chen, Zhuozhi
    Pooley, Rob
    2009 IEEE 33RD INTERNATIONAL COMPUTER SOFTWARE AND APPLICATIONS CONFERENCE, VOLS 1 AND 2, 2009, : 676 - 681
  • [3] Security Framework Using Big Data Technology for Advanced Persistent Threat
    Kim, Nanju
    Park, Joonwoo
    Choi, Euiin
    2015 INTERNATIONAL CONFERENCE ON APPLIED MECHANICS AND MECHATRONICS ENGINEERING (AMME 2015), 2015, : 574 - 578
  • [4] A Study on Security Framework Against Advanced Persistent Threat
    Zhang, Qingyun
    Li, Huan
    Hu, Jinsong
    PROCEEDINGS OF 2017 IEEE 7TH INTERNATIONAL CONFERENCE ON ELECTRONICS INFORMATION AND EMERGENCY COMMUNICATION (ICEIEC), 2017, : 128 - 131
  • [5] An Effective Threat Detection Framework for Advanced Persistent Cyberattacks
    Jeon, So-Eun
    Lee, Sun-Jin
    Lee, Eun-Young
    Lee, Yeon-Ji
    Ryu, Jung-Hwa
    Moon, Jung-Hyun
    Yi, Sun -Min
    Lee, Il-Gu
    CMC-COMPUTERS MATERIALS & CONTINUA, 2023, 75 (02): : 4231 - 4253
  • [6] Advanced Persistent Threat Mitigation Using Multi Level Security - Access Control Framework
    Zulkefli, Zakiah
    Singh, Manmeet Mahinderjit
    Malim, Nurul Hashimah Ahamed Hassain
    COMPUTATIONAL SCIENCE AND ITS APPLICATIONS - ICCSA 2015, PT IV, 2015, 9158 : 90 - 105
  • [7] A network security architecture using the zachman framework
    Ramadan, A. B.
    Hefnawi, M.
    MANAGING CRITICAL INFRASTRUCTURE RISKS: DECISION TOOLS AND APPLICATION FOR PORT SECURITY, 2007, : 133 - +
  • [8] A Survey on Advanced Persistent Threat Detection: A Unified Framework, Challenges, and Countermeasures
    Zhang, Bo
    Gao, Yansong
    Kuang, Boyu
    Yu, Changlong
    Fu, Anmin
    Susilo, Willy
    ACM COMPUTING SURVEYS, 2025, 57 (03)
  • [9] CSKG4APT: A Cybersecurity Knowledge Graph for Advanced Persistent Threat Organization Attribution
    Ren, Yitong
    Xiao, Yanjun
    Zhou, Yinghai
    Zhang, Zhiyong
    Tian, Zhihong
    IEEE TRANSACTIONS ON KNOWLEDGE AND DATA ENGINEERING, 2023, 35 (06) : 5695 - 5709
  • [10] The prevent of advanced persistent threat
    Beijing University of Posts and Telecommunications, China
    不详
    不详
    J. Chem. Pharm. Res., 7 (572-576):