• DocumentCode
    228866
  • Title

    Anticipating Advanced Persistent Threat (APT) countermeasures using collaborative security mechanisms

  • Author

    Mirza, Natasha Arjumand Shoaib ; Abbas, Haider ; Khan, Faheem ; Al Muhtadi, Jalal

  • Author_Institution
    Nat. Univ. of Sci. & Technol., Islamabad, Pakistan
  • fYear
    2014
  • fDate
    26-27 Aug. 2014
  • Firstpage
    129
  • Lastpage
    132
  • Abstract
    Information and communication security has gained significant importance due to its wide spread use, increased sophistication and complexity in its deployment. On the other hand, more sophisticated and stealthy techniques are being practiced by the intruder´s group to penetrate and exploit the technology and attack detection. One such treacherous threat to all critical assets of an organization is Advanced Persistent Threat (APT). Since APT attack vector is not previously known, consequently this can harm the organization´s assets before the patch for this security flaw is released/available. This paper presents a preliminary research effort to counter the APT or zero day attacks at an early stage by detecting malwares. Open Source version of Security Information and Event Management (SIEM) is used to detect denial of service attack launched through remote desktop service. The framework presented in this paper also shows the efficiency of the technique and it can be enhanced with more sophisticated mechanisms for APT attack detection.
  • Keywords
    computational complexity; invasive software; public domain software; APT attack detection; APT attack vector; SIEM; advanced persistent threat countermeasures; collaborative security mechanisms; deployment complexity; information and communication security; malwares; open source version; organization assets; remote desktop service; security information and event management; stealthy techniques; zero day attacks; Intrusion detection; Kernel; Malware; Monitoring; Neural networks; Organizations; Advanced Persistent Threat; Security Information and Event Management; Zero Day Exploits;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Biometrics and Security Technologies (ISBAST), 2014 International Symposium on
  • Conference_Location
    Kuala Lumpur
  • Print_ISBN
    978-1-4799-6443-7
  • Type

    conf

  • DOI
    10.1109/ISBAST.2014.7013108
  • Filename
    7013108