A Framework for Advanced Persistent Threat Attribution using Zachman Ontology

被引:6
|
作者
Charan, P. V. Sai [1 ]
Chunduri, Hrushikesh [1 ]
Anand, P. Mohan [1 ]
Shukla, Sandeep K. [1 ]
机构
[1] Indian Inst Technol Kanpur, Kanpur, Uttar Pradesh, India
关键词
APT; Attribution Framework; Zachman Ontology; Cyber Criminology; Cyber Investigation;
D O I
10.1145/3590777.3590783
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Advanced Persistent Threat (APT) is a type of cyber attack that infiltrates a targeted organization and exfiltrates sensitive data over an extended period of time or to cause sabotage. Recently, there has been a trend of nation states backing APT groups in order to further their political and financial interests, making the APT attribution process increasingly important. The APT attribution process involves identifying the actors behind an attack and their motivations, using a method of logical inference called abductive reasoning to determine the most likely explanation for a set of observations. While various attribution methods and frameworks have been proposed by the security community, many of them lack granularity and are dependent on the skills of practitioners rather than a standardized process. This can hinder both the understandability and reproducibility of attribution efforts as this process is practiced but not engineered. To address these issues, we propose a new framework for the APT attribution process based on the Zachman ontology, which offers greater granularity by posing specific primitive questions at various levels of the attribution process. This allows for more accurate conclusions about the attackers and their motivations, helping organizations to better protect themselves against future attacks.
引用
收藏
页码:34 / 41
页数:8
相关论文
共 50 条
  • [41] Evolving Advanced Persistent Threat Detection using Provenance Graph and Metric Learning
    Ayoade, Gbadebo
    Akbar, Khandakar Ashrafi
    Sahoo, Pracheta
    Gao, Yang
    Agarwal, Anmol
    Jee, Kangkook
    Khan, Latifur
    Singhal, Anoop
    2020 IEEE CONFERENCE ON COMMUNICATIONS AND NETWORK SECURITY (CNS), 2020,
  • [42] Advanced Persistent Threat Detection Using Optimized and Hybrid Deep Learning Approach
    Almazmomi, Najah Kalifah
    SECURITY AND PRIVACY, 2025, 8 (02):
  • [43] Cyber threat attribution using unstructured reports in cyber threat intelligence
    Irshad, Ehtsham
    Siddiqui, Abdul Basit
    EGYPTIAN INFORMATICS JOURNAL, 2023, 24 (01) : 43 - 59
  • [44] Performance evaluation of a fast and efficient intrusion detection framework for advanced persistent threat-based cyberattacks
    Park, Na-Eun
    Lee, Yu-Rim
    Joo, Soyoung
    Kim, So-Yeon
    Park, Ju-Young
    Kim, Seo-Yi
    Lee, Il-Gu
    COMPUTERS & ELECTRICAL ENGINEERING, 2023, 105
  • [45] XFedGraph-Hunter: An Interpretable Federated Learning Framework for Hunting Advanced Persistent Threat in Provenance Graph
    Ngo Duc Hoang Son
    Huynh Thai Thi
    Phan The Duy
    Van-Hau Pham
    INFORMATION SECURITY PRACTICE AND EXPERIENCE, ISPEC 2023, 2023, 14341 : 546 - 561
  • [46] Advanced Persistent Threats (APT): evolution, anatomy, attribution and countermeasures
    Sharma A.
    Gupta B.B.
    Singh A.K.
    Saraswat V.K.
    Journal of Ambient Intelligence and Humanized Computing, 2023, 14 (07) : 9355 - 9381
  • [47] Detection of advanced persistent threat: A genetic programming approach
    Al Mamun, Abdullah
    Al-Sahaf, Harith
    Welch, Ian
    Mansoori, Masood
    Camtepe, Seyit
    APPLIED SOFT COMPUTING, 2024, 167
  • [48] Construction of Index System Based on Advanced Persistent Threat
    Lin, Jia
    Jiang, Rong
    Qi, Yu-Lu
    Yang, Shu-Qiang
    Li, Ai-Ping
    4TH ANNUAL INTERNATIONAL CONFERENCE ON INFORMATION TECHNOLOGY AND APPLICATIONS (ITA 2017), 2017, 12
  • [49] Domain adaptation for Windows advanced persistent threat detection
    Coulter, Rory
    Zhang, Jun
    Pan, Lei
    Xiang, Yang
    COMPUTERS & SECURITY, 2022, 112
  • [50] An Efficient Classification Model for Detecting Advanced Persistent Threat
    Chandran, Saranya
    Hrudya, P.
    Poornachandran, Prabaharan
    2015 INTERNATIONAL CONFERENCE ON ADVANCES IN COMPUTING, COMMUNICATIONS AND INFORMATICS (ICACCI), 2015, : 2001 - 2009