A Survey on Advanced Persistent Threats: Techniques, Solutions, Challenges, and Research Opportunities

A Survey on Advanced Persistent Threats: Techniques, Solutions, Challenges, and Research Opportunities
复制标题

DOI:
10.1109/comst.2019.2891891
复制
发表时间:
2019-01-01
影响因子:
35.6
通讯作者:
Huang, Dijiang
Huang, Dijiang
中科院分区:
计算机科学1区
文献类型:
--
作者:
Alshamrani, Adel;Myneni, Sowmya;Huang, Dijiang

文献摘要

被引文献

相似文献

主要针对民族国家及其相关实体的威胁已经扩大了目标区域,包括私营部门和企业部门。这类威胁被称为高级持续性威胁(APT),是每个国家和组织都担心并希望保护自己免受的威胁。虽然国家赞助的APT攻击总是以其复杂性为特征,但在企业部门中变得突出的APT攻击并没有使组织的挑战性降低。攻击工具和技术的发展速度使任何现有的安全措施都不足以应对。随着防御者努力保护网络中的每个端点和每个链路,攻击者正在寻找新的方法渗透到目标系统中。每天都有新形式的恶意软件出现,具有新的签名和接近正常的行为,单一的威胁检测系统将无法满足需求。虽然执行APT需要时间和耐心,但需要适应APT攻击者不断变化的行为的解决方案。已经发表了几篇关于在其一个或两个阶段检测APT攻击的文章,但是在从侦察到清除的整个过程中检测APT的研究非常有限,因为这样的解决方案需要对网络内和网络间的用户和系统进行复杂的相关性和细粒度的行为分析。通过这份调查报告,我们打算带来所有可用于检测APT攻击的不同阶段的方法和技术,学习需要应用的方法,以及在哪里使您的威胁检测框架变得智能,并且对于那些适应APT攻击者来说无法破译。我们还提出了不同的案例研究的APT攻击,不同的监控方法,以及缓解方法,用于细粒度控制的网络系统的安全性。最后,我们总结了防范APT的不同挑战和进一步研究的机会,并总结了我们在撰写本文期间学到的东西。
Threats that have been primarily targeting nation states and their associated entities have expanded the target zone to include the private and corporate sectors. This class of threats, well known as advanced persistent threats (APTs), are those that every nation and well-established organization fears and wants to protect itself against. While nation-sponsored APT attacks will always be marked by their sophistication, APT attacks that have become prominent in corporate sectors do not make it any less challenging for the organizations. The rate at which the attack tools and techniques are evolving is making any existing security measures inadequate. As defenders strive to secure every endpoint and every link within their networks, attackers are finding new ways to penetrate into their target systems. With each day bringing new forms of malware, having new signatures and behavior that is close to normal, a single threat detection system would not suffice. While it requires time and patience to perform APT, solutions that adapt to the changing behavior of APT attacker(s) are required. Several works have been published on detecting an APT attack at one or two of its stages, but very limited research exists in detecting APT as a whole from reconnaissance to cleanup, as such a solution demands complex correlation and tine-grained behavior analysis of users and systems within and across networks. Through this survey paper, we intend to bring all those methods and techniques that could be used to detect different stages of APT attacks, learning methods that need to be applied and where to make your threat detection framework smart and undecipherable for those adapting APT attackers. We also present different case studies of APT attacks, different monitoring methods, and mitigation methods to be employed for fine-grained control of security of a networked system. We conclude this paper with different challenges in defending against APT and opportunities for further research, ending with a note on what we learned during our writing of this paper.