Advanced Persistent Threats—Techniques, Detection and Defences
摘要
Advanced Persistent Threats (APTs) are the most concerning challenge in today’s cybersecurity landscape, which is increasing rapidly. APTs are sophisticated, covert and typically launched by highly skilled attackers, who are typically sponsored by governments or criminal organisations. The objectives of such attackers may vary, but they predominantly conduct their attacks to steal information or disrupt operations over an extended period of time. The consequences of APT attacks usually include severe financial losses and reputational damage, which impacts the targeted entities as well as their stakeholders. One of the characteristics of APTs is the usage of advanced techniques, such as sophisticated malware, social engineering, and exploitation of undiscovered vulnerabilities (zero-days). All these characteristics make the detection of an APT attack a difficult task. Hence, We conducted a systematic literature review (SLR) on the recent APT-related research papers to evaluate the existing APT detection and defence techniques, as well as their efficiency and limitations. The SLR also examined the feasibility of using new technologies such as Artificial Intelligence (AI), Machine Learning (ML) and Deep Learning (DL) to detect and predict APTs at early stages. We have found that there are gaps and contradictions in the experiment results of different researchers, which will be discussed later.