Unveiling hidden adversaries - detecting command & control servers
摘要
The increasingly advanced forms of cyber-attacks have highlighted the importance of advanced threat hunting as a necessary skillset. The current research examines the effectiveness of using Elasticsearch, Kibana, and Lucene for an intelligence-driven threat hunting to identify attack infrastructure or a Command & Control (C2) server. By aggregating all system traffic logs and security artifacts into a single data lake/warehouse, organizations are able to leverage centralized analysis of information from different sources on a corporate scale. Utilizing Kibana’s ability to perform network and log analysis, using Lucene’s rich syntax to make sophisticated queries will empower individuals to make valuable findings from log and network traffic logs that identify behaviours and patterns typical of C2 activities. A novel intelligence-based threat hunting approach is presented here that utilizes Elasticsearch, with domain-specific language additions to refine search queries and investigate for C2 related activity. A detailed analysis of the research based on real-world datasets is conducted to evaluation the threat hunting framework’s abilities in detecting C2 servers and minimize true/false positives in relation to organizational security concerns.