DocumentCode
2126602
Title
Towards Offensive Cyber Counterintelligence: Adopting a Target-Centric View on Advanced Persistent Threats
Author
Sigholm, Johan ; Bang, Martin
Author_Institution
Dept. of Mil. Studies, Swedish Nat. Defence Coll., Stockholm, Sweden
fYear
2013
fDate
12-14 Aug. 2013
Firstpage
166
Lastpage
171
Abstract
Although the traditional strategies for cyber defense in use today are necessary to mitigate broad ranges of common threats, they are not well-suited to protect against a persistent antagonist with access to advanced system exploitation techniques and knowledge of existing but yet undiscovered software vulnerabilities. Addressing the threat caused by such antagonists requires a fast and offensive Cyber Counterintelligence (CCI) process, and a more efficient inter-organizational information exchange. This paper proposes a framework for offensive CCI based on technical tools and techniques for data mining, anomaly detection, and extensive sharing of cyber threat data. The framework is placed within the distinct context of military intelligence, in order to achieve a holistic, offensive and target-centric view of future CCI. The main contributions offered are (i) a comprehensive process that bridges the gap between the various actors involved in CCI, (ii) an applied technical architecture to support detection and identification of data leaks emanating from cyber espionage, and (iii) deduced intelligence community requirements.
Keywords
data mining; security of data; CCI; advanced persistent threats; advanced system exploitation techniques; anomaly detection; cyber defense; cyber espionage; cyber threat data sharing; data leaks; data mining; deduced intelligence community requirements; offensive cyber counterintelligence; persistent antagonist; software vulnerabilities; target-centric view; Communities; Cyberspace; Fingerprint recognition; Organizations; Security; Software; Standards organizations; anomaly detection; attribution; counterintelligence; cyber; espionage;
fLanguage
English
Publisher
ieee
Conference_Titel
Intelligence and Security Informatics Conference (EISIC), 2013 European
Conference_Location
Uppsala
Type
conf
DOI
10.1109/EISIC.2013.37
Filename
6657147
Link To Document