DFA-AD: a distributed framework architecture for the detection of advanced persistent threats

被引:23
|
作者
Sharma, Pradip Kumar [1 ]
Moon, Seo Yeon [1 ]
Moon, Daesung [2 ]
Park, Jong Hyuk [1 ]
机构
[1] Seoul Natl Univ Sci & Technol SeoulTech, Dept Comp Sci & Engn, Seoul, South Korea
[2] Elect & Telecommun Res Inst, Dept Network Secur Res Team, Daejeon, South Korea
关键词
Advanced persistent threats; Internet of things; Genetic programming; Classification and regression trees; Support vector machines; Dynamic Bayesian game model;
D O I
10.1007/s10586-016-0716-0
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Advanced persistent threats (APTs) are target-oriented and advanced cyber-attacks which often leverage the bot control and customized malware techniques in order to control and remotely access valuable information. APTs generally use various attack techniques to gain access to the unauthorized system and then progressively spread throughout the network. The prime objectives of APT attacks are to steal intellectual property, legal documents, sensitive internal business and other data. If an attack is successfully launched on a system, the timely detection of attack is extremely important to stop APTs from further spreading and for mitigating its impact. On the other hand, internet of things (IoT) devices quickly become ubiquitous while IoT services become pervasive. Their prosperity has not gone unnoticed, and the number of attacks and threats against IoT devices and services are also increasing. Cyber-attacks are not new to IoT, but as the IoT will be deeply intertwined in our societies and lives, it becomes essential to take cyber defense seriously. In this paper, we propose a novel distributed framework architecture for the detection of APTs named as distributed framework architecture for APTs detection (DFA-AD), which is a promising basis for modern intrusion detection systems. In contrast to other approaches, the DFA-AD technique for detecting APT attack is based on multiple parallel classifiers, which classify the events in a distributed environment and event correlation among those events. Each classifier method is focused on detecting the APT's attack technique independently. The evaluation results show that the proposed approach achieves greater effectiveness and accuracy.
引用
收藏
页码:597 / 609
页数:13
相关论文
共 49 条
  • [1] DFA-AD: a distributed framework architecture for the detection of advanced persistent threats
    Pradip Kumar Sharma
    Seo Yeon Moon
    Daesung Moon
    Jong Hyuk Park
    [J]. Cluster Computing, 2017, 20 : 597 - 609
  • [2] Surviving advanced persistent threats in a distributed environment - Architecture and analysis
    Mehresh, Ruchika
    Upadhyaya, Shambhu
    [J]. INFORMATION SYSTEMS FRONTIERS, 2015, 17 (05) : 987 - 995
  • [3] Surviving advanced persistent threats in a distributed environment – Architecture and analysis
    Ruchika Mehresh
    Shambhu Upadhyaya
    [J]. Information Systems Frontiers, 2015, 17 : 987 - 995
  • [4] A Context-Based Detection Framework for Advanced Persistent Threats
    Giura, Paul
    Wang, Wei
    [J]. 2012 ASE INTERNATIONAL CONFERENCE ON CYBER SECURITY (CYBERSECURITY), 2012, : 69 - 74
  • [5] Advanced Persistent Threats - Detection and Defense
    Vukalovic, J.
    Delija, D.
    [J]. 2015 8TH INTERNATIONAL CONVENTION ON INFORMATION AND COMMUNICATION TECHNOLOGY, ELECTRONICS AND MICROELECTRONICS (MIPRO), 2015, : 1324 - 1330
  • [6] Surviving Advanced Persistent Threats - a Framework and Analysis
    Mehresh, Ruchika
    Upadhyaya, Shambhu
    [J]. PROCEEDINGS OF THE 10TH INTERNATIONAL CONFERENCE ON CYBER WARFARE AND SECURITY (ICCWS-2015), 2015, : 445 - 454
  • [7] Decepticon: a Theoretical Framework to Counter Advanced Persistent Threats
    Baksi, Rudra P.
    Upadhyaya, Shambhu J.
    [J]. INFORMATION SYSTEMS FRONTIERS, 2021, 23 (04) : 897 - 913
  • [8] Decepticon: a Theoretical Framework to Counter Advanced Persistent Threats
    Rudra P. Baksi
    Shambhu J. Upadhyaya
    [J]. Information Systems Frontiers, 2021, 23 : 897 - 913
  • [9] Detection of previously unknown Advanced Persistent Threats through Visual Analytics with the MASFAD framework
    Nikolov, Georgi
    Mees, Wim
    [J]. 2023 INTERNATIONAL CONFERENCE ON MILITARY COMMUNICATIONS AND INFORMATION SYSTEMS, ICMCIS, 2023,
  • [10] Evidence-Based Detection of Advanced Persistent Threats
    Tecuci, Gheorghe
    Marcu, Dorin
    Meckl, Steven
    Boicu, Mihai
    [J]. COMPUTING IN SCIENCE & ENGINEERING, 2018, 20 (06) : 54 - 65