Maximizing the effectiveness of an advanced persistent threat

نویسندگان

  • Xiaofan Yang
  • Tianrui Zhang
  • Luxing Yang
  • Luosheng Wen
  • Yuan Yan Tang
چکیده

As a new type of cyber attacks, advanced persistent threats (APTs) pose a severe threat to modern society. This paper focuses on the assessment of the risk of APTs. Based on a dynamic model characterizing the time evolution of the state of an organization, the organization’s risk is defined as its maximum possible expected loss, and the risk assessment problem is modeled as a constrained optimization problem. The influence of different factors on an organization’s risk is uncovered through theoretical analysis. Based on extensive experiments, we speculate that the attack strategy obtained by applying the hill-climbing method to the proposed optimization problem, which we call the HC strategy, always leads to the maximum possible expected loss. We then present a set of five heuristic attack strategies and, through comparative experiments, show that the HC strategy causes a higher risk than all these heuristic strategies do, which supports our conjecture. Finally, the impact of two factors on the attacker’s HC cost profit is determined through computer simulations. These findings help understand the risk of APTs in a quantitative manner.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Towards an Operational Semantic Theory of Cyber Defense Against Advanced Persistent Threats

This paper presents current work on developing an operational semantic theory of cyber defense against advanced persistent threats (APTs), which is grounded in cyber threat analytics, science of evidence, knowledge engineering, and machine learning. After introducing advanced persistent threats, it overviews a systematic APT detection framework and the corresponding APT detection models, the fo...

متن کامل

Sherlock Holmes and the Case of the Advanced Persistent Threat

An Advanced Persistent Threat (APT) is a targeted attack against a high-value asset or a physical system. Drawing from analogies in the Sherlock Holmes stories of Sir Arthur Conan Doyle, we illustrate potential strategies of deception and evasion available in this setting, and caution against overly narrow characterization of APTs.

متن کامل

Political Communication and Financial Performance in Banks: Opportunity or Threat

 Political relationships can have both a positive and a negative impact on bank performance, which requires an empirical analysis to identify its impact. In this regard, the purpose of this study is to investigate the relationship between political communication and financial performance of banks accepted in Tehran Stock Exchange and OTC. In this study, in order to test the research hypothesis,...

متن کامل

Disguised executable files in spear-phishing emails: Detecting the point of entry in advanced persistent threat

Advanced Persistent Threat (APT) is one of the most serious types of cyber attacks, which is a new and more complex version of multi-step attack. Within the APT life cycle, the most common technique used to get the point of entry is spear-phishing emails which may contain disguised executable files. This paper presents the disguised executable file detection (DeFD) module, which aims at detecti...

متن کامل

The Making of “The Advanced Persistent Threat You Have: Google Chrome”

Google’s software update system can serve as a model Advanced Persistent Threat (APT). APTs often embed programs in a penetrated system. These programs wake up from time to time, call home, download additional programs and instructions to carry out, and modify systems. Google’s software update performs all these steps too. Furthermore, because the Google Chrome browser is so widely used and upd...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:
  • CoRR

دوره abs/1707.02437  شماره 

صفحات  -

تاریخ انتشار 2017