首页> 外文期刊>IEICE transactions on information and systems >Modeling Attack Process of Advanced Persistent Threat Using Network Evolution
【24h】

Modeling Attack Process of Advanced Persistent Threat Using Network Evolution

机译:使用网络演化对高级持续威胁的攻击过程进行建模

获取原文
           

摘要

Advanced Persistent Threat (APT) is one of the most serious network attacks that occurred in cyberspace due to sophisticated techniques and deep concealment. Modeling APT attack process can facilitate APT analysis, detection, and prediction. However, current techniques focus on modeling known attacks, which neither reflect APT attack dynamically nor take human factors into considerations. In order to overcome this limitation, we propose a Targeted Complex Attack Network (TCAN) model for APT attack process based on dynamic attack graph and network evolution. Compared with current models, our model addresses human factors by conducting a two-layer network structure. Meanwhile, we present a stochastic model based on states change in the target network to specify nodes involved in the procedure of this APT. Besides, our model adopts time domain to expand the traditional attack graph into dynamic attack network. Our model is featured by flexibility, which is proven through changing the related parameters. In addition, we propose dynamic evolution rules based on complex network theory and characteristics of the actual attack scenarios. Finally, we elaborate a procedure to add nodes by a matrix operation. The simulation results show that our model can model the process of attack effectively.
机译:高级持久威胁(APT)是由于复杂的技术和深层的隐瞒而在网络空间中发生的最严重的网络攻击之一。对APT攻击过程进行建模可以促进APT分析,检测和预测。但是,当前的技术侧重于对已知攻击进行建模,既不能动态反映APT攻击,也不会考虑人为因素。为了克服这一限制,我们提出了一种基于动态攻击图和网络演化的针对APT攻击过程的目标复杂攻击网络(TCAN)模型。与当前模型相比,我们的模型通过进行两层网络结构处理人为因素。同时,我们提出了一种基于目标网络中状态变化的随机模型,以指定此APT过程中涉及的节点。此外,我们的模型采用时域将传统攻击​​图扩展为动态攻击网络。我们的模型具有灵活性,可以通过更改相关参数来证明。此外,我们基于复杂网络理论和实际攻击场景的特征提出了动态演化规则。最后,我们详细说明了通过矩阵运算添加节点的过程。仿真结果表明,该模型可以有效地对攻击过程进行建模。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号