Automatic recognition of advanced persistent threat tactics for enterprise security

16Citations
Citations of this article
41Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Advanced Persistent Threats (APT) has become the concern of many enterprise networks. APT can remain undetected for a long time span and lead to undesirable consequences such as stealing of sensitive data, broken workflow, and so on. To achieve the attack goal, attackers usually leverage specific tactics that utilize a variety of techniques. This paper explores the recognition of APT tactics through synthesized analysis and correlation of data from various sources.We propose a framework for detecting the APT tactics and discuss the application of different APT technique identification methods. Our framework can be used by the security analysts for effective detection of APT attacks. The evaluation of our approach shows that it can detect APT tactics with high accuracy and low false positive rate. Therefore, it can be used for tactic-centric APT detection and effective implementation of cyber security response operations.

Cite

CITATION STYLE

APA

Zou, Q., Singhal, A., Sun, X., & Liu, P. (2020). Automatic recognition of advanced persistent threat tactics for enterprise security. In IWSPA 2020 - Proceedings of the 6th International Workshop on Security and Privacy Analytics (pp. 43–52). Association for Computing Machinery. https://doi.org/10.1145/3375708.3380314

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free