Amalgamation of Divergent Logs for Detection of Advanced Persistent Threats in Cyber Threat Analysis
摘要
Cyber world is penetrating all domains of technology, and it has become increasingly evident that digitization poses threat to security and stability of a country. The attacks launched by cyber criminals have compounded, with sophisticated and hard to detect attack techniques, challenging existing security measures. Advanced persistent threats (APTs) are nation-state attacks targeting critical information infrastructure systems. The threat posed by such attacks is catastrophic to enterprises. The dynamic and evolving nature of APTs makes them unique, and security solutions for their detection are required to be adaptive and dynamic to the changing nature of these attacks. This chapter analyzes APT attacks from different perspectives and presents recent methodologies that were proposed for detection of APTs. The concept study of amalgamation of signature-based logs and anomalous logs for effective APT detection is presented in this paper.