DocumentCode
228866
Title
Anticipating Advanced Persistent Threat (APT) countermeasures using collaborative security mechanisms
Author
Mirza, Natasha Arjumand Shoaib ; Abbas, Haider ; Khan, Faheem ; Al Muhtadi, Jalal
Author_Institution
Nat. Univ. of Sci. & Technol., Islamabad, Pakistan
fYear
2014
fDate
26-27 Aug. 2014
Firstpage
129
Lastpage
132
Abstract
Information and communication security has gained significant importance due to its wide spread use, increased sophistication and complexity in its deployment. On the other hand, more sophisticated and stealthy techniques are being practiced by the intruder´s group to penetrate and exploit the technology and attack detection. One such treacherous threat to all critical assets of an organization is Advanced Persistent Threat (APT). Since APT attack vector is not previously known, consequently this can harm the organization´s assets before the patch for this security flaw is released/available. This paper presents a preliminary research effort to counter the APT or zero day attacks at an early stage by detecting malwares. Open Source version of Security Information and Event Management (SIEM) is used to detect denial of service attack launched through remote desktop service. The framework presented in this paper also shows the efficiency of the technique and it can be enhanced with more sophisticated mechanisms for APT attack detection.
Keywords
computational complexity; invasive software; public domain software; APT attack detection; APT attack vector; SIEM; advanced persistent threat countermeasures; collaborative security mechanisms; deployment complexity; information and communication security; malwares; open source version; organization assets; remote desktop service; security information and event management; stealthy techniques; zero day attacks; Intrusion detection; Kernel; Malware; Monitoring; Neural networks; Organizations; Advanced Persistent Threat; Security Information and Event Management; Zero Day Exploits;
fLanguage
English
Publisher
ieee
Conference_Titel
Biometrics and Security Technologies (ISBAST), 2014 International Symposium on
Conference_Location
Kuala Lumpur
Print_ISBN
978-1-4799-6443-7
Type
conf
DOI
10.1109/ISBAST.2014.7013108
Filename
7013108
Link To Document