mailto:uumlib@uum.edu.my 24x7 Service; AnyTime; AnyWhere

A framework of APT detection based on packets analysis and host destination

Alminshid, Khalid Abdulrazzaq Abdulnabi and Omar, Mohd Nizam (2020) A framework of APT detection based on packets analysis and host destination. Iraqi Journal of Science, 2020, 61 (1). pp. 215-22. ISSN 0067-2904

[thumbnail of IJS 60 1 2020 215 222.pdf] PDF
Restricted to Registered users only

Download (560kB) | Request a copy

Abstract

So far, APT (Advanced Persistent Threats) is a constant concern for information security. Despite that, many approaches have been used in order to detect APT attacks, such as change controlling, sandboxing and network traffic analysis. However, success of 100% couldn’t be achieved. Current studies have illustrated that APTs adopt many complex techniques to evade all detection types. This paper describes and analyzes APT problems by analyzing the most common techniques, tools and pathways used by attackers. In addition, it highlights the weaknesses and strengths of the existing security solutions that have been used since the threat was identified in 2006 until 2019. Furthermore, this research proposes a new framework that can be used to repel this threat based on APT activity with network traffic through packets analysis and host destination.

Item Type: Article
Uncontrolled Keywords: detection, APT, Advanced Persistent Threats, traffic, intrusion
Subjects: Q Science > QA Mathematics > QA75 Electronic computers. Computer science
Divisions: School of Computing
Depositing User: Mrs. Norazmilah Yaakub
Date Deposited: 12 Feb 2020 07:20
Last Modified: 12 Feb 2020 07:20
URI: https://repo.uum.edu.my/id/eprint/26786

Actions (login required)

View Item View Item