A Framework for Advanced Persistent Threat Attribution using Zachman Ontology

被引:6
|
作者
Charan, P. V. Sai [1 ]
Chunduri, Hrushikesh [1 ]
Anand, P. Mohan [1 ]
Shukla, Sandeep K. [1 ]
机构
[1] Indian Inst Technol Kanpur, Kanpur, Uttar Pradesh, India
关键词
APT; Attribution Framework; Zachman Ontology; Cyber Criminology; Cyber Investigation;
D O I
10.1145/3590777.3590783
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Advanced Persistent Threat (APT) is a type of cyber attack that infiltrates a targeted organization and exfiltrates sensitive data over an extended period of time or to cause sabotage. Recently, there has been a trend of nation states backing APT groups in order to further their political and financial interests, making the APT attribution process increasingly important. The APT attribution process involves identifying the actors behind an attack and their motivations, using a method of logical inference called abductive reasoning to determine the most likely explanation for a set of observations. While various attribution methods and frameworks have been proposed by the security community, many of them lack granularity and are dependent on the skills of practitioners rather than a standardized process. This can hinder both the understandability and reproducibility of attribution efforts as this process is practiced but not engineered. To address these issues, we propose a new framework for the APT attribution process based on the Zachman ontology, which offers greater granularity by posing specific primitive questions at various levels of the attribution process. This allows for more accurate conclusions about the attackers and their motivations, helping organizations to better protect themselves against future attacks.
引用
收藏
页码:34 / 41
页数:8
相关论文
共 50 条
  • [31] An Approach for Detection of Advanced Persistent Threat Attacks
    Zou, Qingtian
    Sun, Xiaoyan
    Liu, Peng
    Singhal, Anoop
    COMPUTER, 2020, 53 (12) : 92 - 96
  • [32] A New Proposal on the Advanced Persistent Threat: A Survey
    Quintero-Bonilla, Santiago
    Martin del Rey, Angel
    APPLIED SCIENCES-BASEL, 2020, 10 (11):
  • [33] Modeling Attack Process of Advanced Persistent Threat
    Niu, Weina
    Zhan, Xiaosong
    Li, Kenli
    Yang, Guowu
    Chen, Ruidong
    SECURITY, PRIVACY, AND ANONYMITY IN COMPUTATION, COMMUNICATION, AND STORAGE, 2016, 10066 : 383 - 391
  • [34] Design & Measure RUP Development Case Using the Zachman Framework as an Aid
    Fu, Lina
    Hao, Kegang
    ADVANCED MANUFACTURING TECHNOLOGY, PTS 1-4, 2012, 472-475 : 3153 - 3158
  • [35] Research on Prevention Solution of Advanced Persistent Threat
    Liu, Xiaomei
    PROCEEDINGS OF THE 2ND INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING, KNOWLEDGE ENGINEERING AND INFORMATION ENGINEERING (SEKEIE 2014), 2014, 114 : 139 - 142
  • [36] Threat Intelligence Sharing Community: A countermeasure against Advanced Persistent Threat
    Chandel, Sonali
    Yan, Mengdi
    Chen, Shaojun
    Jiang, Huan
    Ni, Tian-Yi
    2019 2ND IEEE CONFERENCE ON MULTIMEDIA INFORMATION PROCESSING AND RETRIEVAL (MIPR 2019), 2019, : 353 - 359
  • [37] Automating threat modeling using an ontology framework: Validated with data from critical infrastructures
    Valja, Margus
    Heiding, Fredrik
    Franke, Ulrik
    Lagerstrom, Robert
    CYBERSECURITY, 2020, 3 (01)
  • [38] Detection of advanced persistent threat using machine-learning correlation analysis
    Ghafir, Ibrahim
    Hammoudeh, Mohammad
    Prenosil, Vaclav
    Han, Liangxiu
    Hegarty, Robert
    Rabie, Khaled
    Aparicio-Navarro, Francisco J.
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2018, 89 : 349 - 359
  • [39] APTGuard : Advanced Persistent Threat (APT) Detections and Predictions using Android Smartphone
    Chuan, Bernard Lee Jin
    Singh, Manmeet Mahinderjit
    Shariff, Azizul Rahman Mohd
    COMPUTATIONAL SCIENCE AND TECHNOLOGY, 2019, 481 : 545 - 555
  • [40] Anticipating Advanced Persistent Threat (APT) Countermeasures using Collaborative Security Mechanisms
    Mirza, Natasha Arjumand Shoaib
    Abbas, Haider
    Khan, Farrukh Aslam
    Al Muhtadi, Jalal
    2014 INTERNATIONAL SYMPOSIUM ON BIOMETRICS AND SECURITY TECHNOLOGIES (ISBAST), 2014, : 129 - 132