【24h】

Advanced Persistent Threats - detection and defense

机译:高级持续威胁-检测和防御

获取原文

摘要

The term “Advanced Persistent Threat” refers to a well-organized, malicious group of people who launch stealthy attacks against computer systems of specific targets, such as governments, companies or military. The attacks themselves are long-lasting, difficult to expose and often use very advanced hacking techniques. Since they are advanced in nature, prolonged and persistent, the organizations behind them have to possess a high level of knowledge, advanced tools and competent personnel to execute them. The attacks are usually preformed in several phases - reconnaissance, preparation, execution, gaining access, information gathering and connection maintenance. In each of the phases attacks can be detected with different probabilities. There are several ways to increase the level of security of an organization in order to counter these incidents. First and foremost, it is necessary to educate users and system administrators on different attack vectors and provide them with knowledge and protection so that the attacks are unsuccessful. Second, implement strict security policies. That includes access control and restrictions (to information or network), protecting information by encrypting it and installing latest security upgrades. Finally, it is possible to use software IDS tools to detect such anomalies (e.g. Snort, OSSEC, Sguil).
机译:术语“高级持久威胁”是指组织良好的恶意团体,它们对特定目标的计算机系统(例如政府,公司或军方)发起隐形攻击。攻击本身是持久的,难以暴露,并且经常使用非常先进的黑客技术。由于它们具有先进性,长期性和持久性,因此其背后的组织必须拥有高水平的知识,先进的工具和称职的人员来执行它们。攻击通常分为几个阶段进行:侦查,准备,执行,获取访问权限,信息收集和连接维护。在每个阶段中,可以以不同的概率检测攻击。有多种方法可以提高组织的安全级别,以应对这些事件。首先,有必要对用户和系统管理员进行不同的攻击媒介教育,并为他们提供知识和保护,以使攻击不会成功。二是实施严格的安全政策。其中包括访问控制和限制(对信息或网络的限制),通过对信息进行加密和安装最新的安全性升级来保护信息。最后,可以使用软件IDS工具检测此类异常(例如Snort,OSSEC,Sguil)。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号