论文标题
高级持续威胁:检测和防御
Advanced Persistent Threat: Detection and Defence
论文作者
论文摘要
本文介绍的批判性评估探讨了与网络安全的高级持续威胁(APT)分支有关的现有研究,并运用了从这项研究中提取的知识来讨论,评估和评估讨论领域,并在该领域中涉及个人经验和知识。当前文献的综合探索功能和技术以及针对APT的组织的防御解决方案。高层检测和防御策略对较大的组织具有更大的重要性;特别是政府部门或工作对公众大规模影响的组织。成功的APT攻击可能会导致敏感数据,网络停机时间和机器的感染的渗透,从而可以从命令和控制(C2)服务器远程访问。本文对先进的持续威胁问题进行了全面的分析,并提供了有关如何减轻安全风险的良好结论。
The critical assessment presented within this paper explores existing research pertaining to the Advanced Persistent Threat (APT) branch of cyber security, applying the knowledge extracted from this research to discuss, evaluate and opinionate upon the areas of discussion as well as involving personal experiences and knowledge within this field. The synthesis of current literature delves into detection capabilities and techniques as well as defensive solutions for organisations with respect to APTs. Higher-tier detection and defensive strategies bear greater importance with larger organisations; especially government departments or organisations whose work impacts the public on a large scale. Successful APT attacks can result in the exfiltration of sensitive data, network down time and the infection of machines which allow for remote access from Command-and-control (C2) servers. This paper presents a well-rounded analysis of the Advanced Persistent Threat problem and provides well-reasoned conclusions of how to mitigate the security risk.