Understanding, Denying and Detecting
نویسندگان
چکیده
One of the leading problems in cyber security today is the emergence of targeted attacks conducted by adversaries with access to sophisticated tools, sometimes referred to as Advanced Persistent Threats (APTs). These attacks target specific organisations or individuals and aim at establishing a continuous and undetected presence in the targeted infrastructure. The goal of these attacks is often espionage: stealing valuable intellectual property and confidential documents. As trends and anecdotal evidence show, providing effective defences against targeted attacks is a challenging task. In this report, we restrict our attention to a specific part of this problem: specifically, we look at the Command and Control (C2) channel establishment, which, as we will see, is an essential step of current attacks. Our goals are to understand C2 establishment techniques, and to review approaches for the detection and disruption of C2 channels. More precisely, we first briefly review the current state of cyber attacks, highlighting significant recent changes in how and why such attacks are performed. This knowledge is foundational to understand C2 techniques and to design effective countermeasures. We then investigate the “mechanics” of C2 establishment: we provide a comprehensive review of the techniques used by attackers to set up such a channel and to hide its presence from the attacked parties and the security tools they use. Finally, we switch to the defensive side of the problem, and review approaches that have been proposed for the detection and disruption of C2 channels. We also map such techniques to widely-adopted security controls, emphasizing gaps or limitations (and success stories) in current best practices. We would like to acknowledge the help and support of CPNI in researching this topic and producing the accompanying products. PAGE 2 Command & Control: Understanding, Denying and Detecting FEBRUARY 2014 University of Birmingham | CPNI.gov.uk
منابع مشابه
Command & Control: Understanding, Denying and Detecting
One of the leading problems in cyber security today is the emergence of targeted attacks conducted by adversaries with access to sophisticated tools, sometimes referred to as Advanced Persistent Threats (APTs). These attacks target specific organisations or individuals and aim at establishing a continuous and undetected presence in the targeted infrastructure. The goal of these attacks is often...
متن کاملTopographies of Hate: Islamophobia in Cyberia
Islamophobia’s occurrence in any particular country has little do with the presence of Muslim; it is possible to be Islamophobic when there are virtually no Muslim around. This because the lack of Muslims is filled by the surplus of Islamophobic representations. This surplus of representations is now increasingly reliant on the internet. There are many studies reporting on Islamophobia on the i...
متن کاملAn Investigation on the Youssef Dare Haddad’s Reasons in Denying the Prophet’s Mission with an Emphasis on the Cited Verses by him
The personality and tradition of the prophet, as messenger of Islam, have always captured the attention of scholars. Orientalists have also been concerned about this issue by maintaining different motivations. The main purposes of the Evangelical Christian Orientalists have included fighting against the true religion of Islam as well as denying the Prophet’s mission which have been always on th...
متن کاملSociological analysis of the lived experience of disabled people in Ahvaz city in facing family and society
Introduction: Disabled people are special social groups that are more exposed to deprivation and lack of benefit from social opportunities and facilities due to physical or mental defects. The current research was conducted with the aim of sociological analysis and understanding of the lived experience of disabled people in Ahvaz city in facing family and society. Method: This research is of ...
متن کاملSociological analysis of the lived experience of disabled people in Ahvaz city in facing family and society
Introduction: Disabled people are special social groups that are more exposed to deprivation and lack of benefit from social opportunities and facilities due to physical or mental defects. The current research was conducted with the aim of sociological analysis and understanding of the lived experience of disabled people in Ahvaz city in facing family and society. Method: This research is of ...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2014