• DocumentCode
    2126602
  • Title

    Towards Offensive Cyber Counterintelligence: Adopting a Target-Centric View on Advanced Persistent Threats

  • Author

    Sigholm, Johan ; Bang, Martin

  • Author_Institution
    Dept. of Mil. Studies, Swedish Nat. Defence Coll., Stockholm, Sweden
  • fYear
    2013
  • fDate
    12-14 Aug. 2013
  • Firstpage
    166
  • Lastpage
    171
  • Abstract
    Although the traditional strategies for cyber defense in use today are necessary to mitigate broad ranges of common threats, they are not well-suited to protect against a persistent antagonist with access to advanced system exploitation techniques and knowledge of existing but yet undiscovered software vulnerabilities. Addressing the threat caused by such antagonists requires a fast and offensive Cyber Counterintelligence (CCI) process, and a more efficient inter-organizational information exchange. This paper proposes a framework for offensive CCI based on technical tools and techniques for data mining, anomaly detection, and extensive sharing of cyber threat data. The framework is placed within the distinct context of military intelligence, in order to achieve a holistic, offensive and target-centric view of future CCI. The main contributions offered are (i) a comprehensive process that bridges the gap between the various actors involved in CCI, (ii) an applied technical architecture to support detection and identification of data leaks emanating from cyber espionage, and (iii) deduced intelligence community requirements.
  • Keywords
    data mining; security of data; CCI; advanced persistent threats; advanced system exploitation techniques; anomaly detection; cyber defense; cyber espionage; cyber threat data sharing; data leaks; data mining; deduced intelligence community requirements; offensive cyber counterintelligence; persistent antagonist; software vulnerabilities; target-centric view; Communities; Cyberspace; Fingerprint recognition; Organizations; Security; Software; Standards organizations; anomaly detection; attribution; counterintelligence; cyber; espionage;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Intelligence and Security Informatics Conference (EISIC), 2013 European
  • Conference_Location
    Uppsala
  • Type

    conf

  • DOI
    10.1109/EISIC.2013.37
  • Filename
    6657147