Advanced Persistent Threat and Spear Phishing Emails

Advanced Persistent Threat and Spear Phishing Emails
复制标题

高级持续威胁和鱼叉式网络钓鱼电子邮件

DOI:
--
复制
发表时间:
2015
期刊:
影响因子:
--
通讯作者:
Václav Přenosil
Václav Přenosil
中科院分区:
--
文献类型:
--
作者:
Ibrahim Ghafir;Václav Přenosil

文献摘要

被引文献

相似文献

近年来,网络剥削和恶意活动 变得越来越复杂、有针对性和严肃。 高级持续性威胁或APT是一种新的、更 已知多步攻击场景的复杂版本。他们 是专门针对实现特定目标,大多数 经常是间谍。这些APT对当前的 因为这些方法依赖于已知的 攻击和APT的签名大量使用未知的 攻击的安全漏洞。在本文中,我们提出两个 基于黑名单的检测方法 网络钓鱼电子邮件,这是APT中最常用的技术 攻击第一种方法是恶意域检测方法, 第二种是恶意文件哈希检测方法。的 黑名单每天自动更新, 是在真实的时间里。
In recent years, cyber exploitation and malicious activity are becoming increasingly sophisticated, targeted, and serious. Advanced persistent threats or APTs are a new and more sophisticated version of known multistep attack scenarios. They are targeted specifically to achieve a specific goal, most often espionage. These APTs form a problem for the current detection methods because these methods depend on known signatures of attacks and APTs make heavy use of unknown security holes for attacks. In this paper we propose two blacklist-based detection methods for detecting a spear phishing email, which is the most common technique used in APT attack. The first method is malicious domain detection method, and the second one is malicious file hash detection method. The blacklists are automatically updated each day and the detection is in the real time.