Advanced Persistent Threat and Spear Phishing Emails
Advanced Persistent Threat and Spear Phishing Emails
复制标题
高级持续威胁和鱼叉式网络钓鱼电子邮件
DOI:
--
复制
发表时间:
2015
期刊:
影响因子:
--
通讯作者:
Václav Přenosil
中科院分区:
文献类型:
--
作者:
Ibrahim Ghafir;Václav Přenosil
In recent years, cyber exploitation and malicious activity are
becoming increasingly sophisticated, targeted, and serious.
Advanced persistent threats or APTs are a new and more
sophisticated version of known multistep attack scenarios. They
are targeted specifically to achieve a specific goal, most
often espionage. These APTs form a problem for the current
detection methods because these methods depend on known
signatures of attacks and APTs make heavy use of unknown
security holes for attacks. In this paper we propose two
blacklist-based detection methods for detecting a spear
phishing email, which is the most common technique used in APT
attack. The first method is malicious domain detection method,
and the second one is malicious file hash detection method. The
blacklists are automatically updated each day and the detection
is in the real time.