A Framework for Advanced Persistent Threat Attribution using Zachman Ontology

被引:6
|
作者
Charan, P. V. Sai [1 ]
Chunduri, Hrushikesh [1 ]
Anand, P. Mohan [1 ]
Shukla, Sandeep K. [1 ]
机构
[1] Indian Inst Technol Kanpur, Kanpur, Uttar Pradesh, India
关键词
APT; Attribution Framework; Zachman Ontology; Cyber Criminology; Cyber Investigation;
D O I
10.1145/3590777.3590783
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Advanced Persistent Threat (APT) is a type of cyber attack that infiltrates a targeted organization and exfiltrates sensitive data over an extended period of time or to cause sabotage. Recently, there has been a trend of nation states backing APT groups in order to further their political and financial interests, making the APT attribution process increasingly important. The APT attribution process involves identifying the actors behind an attack and their motivations, using a method of logical inference called abductive reasoning to determine the most likely explanation for a set of observations. While various attribution methods and frameworks have been proposed by the security community, many of them lack granularity and are dependent on the skills of practitioners rather than a standardized process. This can hinder both the understandability and reproducibility of attribution efforts as this process is practiced but not engineered. To address these issues, we propose a new framework for the APT attribution process based on the Zachman ontology, which offers greater granularity by posing specific primitive questions at various levels of the attribution process. This allows for more accurate conclusions about the attackers and their motivations, helping organizations to better protect themselves against future attacks.
引用
收藏
页码:34 / 41
页数:8
相关论文
共 50 条
  • [11] A Study on Advanced Persistent Threat
    Cinar, Cihan
    Alkan, Mustafa
    Dorterler, Murat
    Dogru, Ibrahim Alper
    2018 3RD INTERNATIONAL CONFERENCE ON COMPUTER SCIENCE AND ENGINEERING (UBMK), 2018, : 116 - 121
  • [12] Enterprise Architecture Analysis Using Zachman Framework
    Nasution, Mas Ayoe Elhias
    Pane, Rahmadani
    Verina, Wiwi
    Hardianto
    Desi, Efani
    2018 6TH INTERNATIONAL CONFERENCE ON CYBER AND IT SERVICE MANAGEMENT (CITSM), 2018, : 559 - 562
  • [13] ANUBIS: A Provenance Graph-Based Framework for Advanced Persistent Threat Detection
    Anjum, Md Monowar
    Iqbal, Shahrear
    Hamelin, Benoit
    37TH ANNUAL ACM SYMPOSIUM ON APPLIED COMPUTING, 2022, : 1684 - 1693
  • [14] Advanced Persistent Threat Attack Detection using Clustering Algorithms
    Alsanad, Ahmed
    Altuwaijri, Sara
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2022, 13 (09) : 640 - 649
  • [15] Threat led advanced persistent threat penetration test
    Masarweh A.
    Al-Saraireh J.
    International Journal of Security and Networks, 2022, 17 (03): : 203 - 219
  • [16] APT-MMF: An advanced persistent threat actor attribution method based on multimodal and multilevel feature fusion
    Xiao, Nan
    Lang, Bo
    Wang, Ting
    Chen, Yikai
    COMPUTERS & SECURITY, 2024, 144
  • [17] Special Issue on Advanced Persistent Threat
    Chen, Jiageng
    Su, Chunhua
    Yeh, Kuo-Hui
    Yung, Moti
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2018, 79 : 243 - 246
  • [18] BIOS Integrity An Advanced Persistent Threat
    Butt, Muhammad Irfan Afzal
    2014 CONFERENCE ON INFORMATION ASSURANCE AND CYBER SECURITY (CIACS), 2014, : 47 - 50
  • [19] Advanced Persistent Threat Detection: A Survey
    Khalid, Adam
    Zainal, Anazida
    Maarof, Mohd Aizaini
    Ghaleb, Fuad A.
    2021 3RD INTERNATIONAL CYBER RESILIENCE CONFERENCE (CRC), 2021, : 84 - 89
  • [20] Framework of Cyber Attack Attribution Based on Threat Intelligence
    Li Qiang
    Yang Zeming
    Liu Baoxu
    Jiang Zhengwei
    Yan Jian
    INTEROPERABILITY, SAFETY AND SECURITY IN IOT, 2017, 190 : 92 - 103