The modern cyberspace is evolving with novel technologies, where cyber adversaries are deploying revolutionary defense evasive payloads, tools and technologies to achieve objectives like cyber espionage, cyber defacing, privacy violations and cyber crime for financial gains etc. Some of the most sophisticated cyber attacks in modern digital era are Advanced Persistent Threats (APT) which are generally sponsored by Nation or Nation States and Syndicates against specific adversaries. The APT attack payloads and tools are specially crafted and highly customized to suit victim’s digital environment by evading victim’s security defenses like perimeter gateways and system security solutions. So the modern security industry need to endure by developing innovative defense mechanisms against these attacks. The primary and most important requirement to develop defenses against APT attacks are qualitative and quantitative APT attack vector data i.e. payloads and tools employed in various APT attacks. The collection of this data is challenging because of the limited exposure with extensive customization of the payloads. However, the security community across the world report various indicators of APT attacks to assist and combat these attacks to make the digital world safe and secure. The information spreads across various open-web (Social media like Twitter, Facebook and Security Blogs etc.) resources and closed-web resources (Dark-Net) etc. The manual collection process is very time consuming and error prone, to correlate all the data and collect unique APT payloads. To address the above problems, we have developed a semi-automated APT malware Collector to acquire, process and correlate APT attack vector data across various resources and collect APT samples based on the indicators and store them securely. The proposed collector acquired 18608 unique APT payload/tool hashes by parsing various threat intelligence reports and collected 5854 unique payloads belong to 323 APT groups. One of the primary application of the research is to provide qualitative and qualitative APT attack vector dataset to assist in developing defense mechanisms and performing APT attribution by correlating various Tactics, Techniques and Procedures (TTPs) of the APT groups.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Advanced Malware Collector: A Semi-Automated Framework for Hunting Advanced Persistent Threat Malware and Tools

  • Amit Sharma,
  • Brij B. Gupta,
  • Awadhesh Kumar Singh,
  • V. K. Saraswat

摘要

The modern cyberspace is evolving with novel technologies, where cyber adversaries are deploying revolutionary defense evasive payloads, tools and technologies to achieve objectives like cyber espionage, cyber defacing, privacy violations and cyber crime for financial gains etc. Some of the most sophisticated cyber attacks in modern digital era are Advanced Persistent Threats (APT) which are generally sponsored by Nation or Nation States and Syndicates against specific adversaries. The APT attack payloads and tools are specially crafted and highly customized to suit victim’s digital environment by evading victim’s security defenses like perimeter gateways and system security solutions. So the modern security industry need to endure by developing innovative defense mechanisms against these attacks. The primary and most important requirement to develop defenses against APT attacks are qualitative and quantitative APT attack vector data i.e. payloads and tools employed in various APT attacks. The collection of this data is challenging because of the limited exposure with extensive customization of the payloads. However, the security community across the world report various indicators of APT attacks to assist and combat these attacks to make the digital world safe and secure. The information spreads across various open-web (Social media like Twitter, Facebook and Security Blogs etc.) resources and closed-web resources (Dark-Net) etc. The manual collection process is very time consuming and error prone, to correlate all the data and collect unique APT payloads. To address the above problems, we have developed a semi-automated APT malware Collector to acquire, process and correlate APT attack vector data across various resources and collect APT samples based on the indicators and store them securely. The proposed collector acquired 18608 unique APT payload/tool hashes by parsing various threat intelligence reports and collected 5854 unique payloads belong to 323 APT groups. One of the primary application of the research is to provide qualitative and qualitative APT attack vector dataset to assist in developing defense mechanisms and performing APT attribution by correlating various Tactics, Techniques and Procedures (TTPs) of the APT groups.