Araştırma Makalesi

A YARA-based approach for detecting cyber security attack types

Cilt: 2 Sayı: 2 14 Haziran 2023
PDF İndir
EN

A YARA-based approach for detecting cyber security attack types

Öz

Technological advancements have recently propelled individuals, institutions, and organizations to conduct their business processes on information systems. However, keeping personal and corporate data on information systems has given rise to issues related to data security. The accessibility of data on information systems has made it vulnerable to theft and exploitation by malicious groups or individuals, thus posing a significant risk to data security. Consequently, the demand for data security has led to a new business sector offering various cybersecurity solutions to protect organizations' systems. This paper presents an analysis of the prevalent types of cyber attacks worldwide. The study aims to create a virtual environment with Windows and Linux systems in Forensic Informatics and Incident Response processes to apply frequently used cyber attack methods, develop defense mechanisms against these methods, and contribute to revealing the root cause by solving the incident pattern. Furthermore, this application demonstrates how manual techniques and open-source solutions, such as YARA, can be used to detect malware derivatives commonly found in Windows systems.

Anahtar Kelimeler

Kaynakça

  1. [1] Abomhara M, Køien GM. "Cyber security and the internet of things: vulnerabilities, threats, intruders and attacks". Journal of Cyber Security and Mobility, 65–88, 2015.
  2. [2] Eggers S. "A novel approach for analyzing the nuclear supply chain cyber-attack surface". Nuclear Engineering and Technology, 53(3), 879-887, 2021.
  3. [3] Freilin FC, Holz T Wicherski G. "Botnet tracking: Exploring a root-cause methodology to prevent distributed denial-of-service attacks". Computer Security–ESORICS 2005: 10th European Symposium on Research in Computer Security, Milan, Italy, September 12-14, 2005. Proceedings 10, 2005: Springer, 319-335.
  4. [4] Auty M. "Anatomy of an advanced persistent threat". Network Security, 4, 13-16, 2015.
  5. [5] Ahmad A, Webb J, Desouza KC, Boorman J. "Strategically-motivated advanced persistent threat: Definition, process, tactics and a disinformation model of counterattack". Computers & Security, 86, 402-418, 2019.
  6. [6] Schneier B. "The future of incident response". IEEE Security & Privacy, 12(5), 96-96, 2014.
  7. [7] Bhatt P, Yano ET, Gustavsson P. "Towards a framework to detect multi-stage advanced persistent threats attacks". in 2014 IEEE 8th international symposium on service oriented system engineering, IEEE, 390-395, 2014.
  8. [8] Itodo C, Varlioglu S, Elsayed N. "Digital forensics and incident response (DFIR) challenges in IoT platforms". 4th International Conference on Information and Computer Technologies (ICICT), IEEE, 199-203, 2021.

Ayrıntılar

Birincil Dil

İngilizce

Konular

Bilgisayar Yazılımı

Bölüm

Araştırma Makalesi

Yayımlanma Tarihi

14 Haziran 2023

Gönderilme Tarihi

1 Mart 2023

Kabul Tarihi

10 Mayıs 2023

Yayımlandığı Sayı

Yıl 2023 Cilt: 2 Sayı: 2

Kaynak Göster

APA
Ildırım, K. Y., Demır, M. E., Keles, T., Yıldız, A. M., Dogan, S., & Tuncer, T. (2023). A YARA-based approach for detecting cyber security attack types. Firat University Journal of Experimental and Computational Engineering, 2(2), 55-68. https://doi.org/10.5505/fujece.2023.09709
AMA
1.Ildırım KY, Demır ME, Keles T, Yıldız AM, Dogan S, Tuncer T. A YARA-based approach for detecting cyber security attack types. Firat University Journal of Experimental and Computational Engineering. 2023;2(2):55-68. doi:10.5505/fujece.2023.09709
Chicago
Ildırım, Kubra Y, Mustafa Emre Demır, Tugce Keles, Arif Metahan Yıldız, Sengul Dogan, ve Turker Tuncer. 2023. “A YARA-based approach for detecting cyber security attack types”. Firat University Journal of Experimental and Computational Engineering 2 (2): 55-68. https://doi.org/10.5505/fujece.2023.09709.
EndNote
Ildırım KY, Demır ME, Keles T, Yıldız AM, Dogan S, Tuncer T (01 Haziran 2023) A YARA-based approach for detecting cyber security attack types. Firat University Journal of Experimental and Computational Engineering 2 2 55–68.
IEEE
[1]K. Y. Ildırım, M. E. Demır, T. Keles, A. M. Yıldız, S. Dogan, ve T. Tuncer, “A YARA-based approach for detecting cyber security attack types”, Firat University Journal of Experimental and Computational Engineering, c. 2, sy 2, ss. 55–68, Haz. 2023, doi: 10.5505/fujece.2023.09709.
ISNAD
Ildırım, Kubra Y - Demır, Mustafa Emre - Keles, Tugce - Yıldız, Arif Metahan - Dogan, Sengul - Tuncer, Turker. “A YARA-based approach for detecting cyber security attack types”. Firat University Journal of Experimental and Computational Engineering 2/2 (01 Haziran 2023): 55-68. https://doi.org/10.5505/fujece.2023.09709.
JAMA
1.Ildırım KY, Demır ME, Keles T, Yıldız AM, Dogan S, Tuncer T. A YARA-based approach for detecting cyber security attack types. Firat University Journal of Experimental and Computational Engineering. 2023;2:55–68.
MLA
Ildırım, Kubra Y, vd. “A YARA-based approach for detecting cyber security attack types”. Firat University Journal of Experimental and Computational Engineering, c. 2, sy 2, Haziran 2023, ss. 55-68, doi:10.5505/fujece.2023.09709.
Vancouver
1.Kubra Y Ildırım, Mustafa Emre Demır, Tugce Keles, Arif Metahan Yıldız, Sengul Dogan, Turker Tuncer. A YARA-based approach for detecting cyber security attack types. Firat University Journal of Experimental and Computational Engineering. 01 Haziran 2023;2(2):55-68. doi:10.5505/fujece.2023.09709

Cited By

Malware Detection and Analysis Using YARA Tool

International Journal of Advanced Research in Science, Communication and Technology

https://doi.org/10.48175/IJARSCT-22623

LEVERAGING YARA AND SIGMA RULES TO DETECT CHINESE STATE-SPONSORED HACKING GROUPS OF THE "TYPHOON" TYPE

ENVIRONMENT. TECHNOLOGY. RESOURCES. Proceedings of the International Scientific and Practical Conference

https://doi.org/10.17770/etr2025vol2.8617