Araştırma Makalesi

DETECTION OF ADVANCED PERSISTENT THREATS USING SIEM RULESETS

Cilt: 7 Sayı: 3 31 Aralık 2023
PDF İndir
EN

DETECTION OF ADVANCED PERSISTENT THREATS USING SIEM RULESETS

Öz

Cyber-attacks move towards a sophisticated, destructive, and persistent position, as in the case of Stuxnet, Dark Hotel, Poseidon, and Carbanak. These attacks are called Advanced Persistent Threats (APTs), in which an intruder establishes an undetected presence in a network to steal sensitive data over a prolonged period. APT attacks threaten the main critical areas of today's digitalized life. This threat covers critical infrastructures, finance, energy, and aviation agencies. One of the most significant APT attacks was Stuxnet, which targeted the software controlling the programmable logic controllers (PLCs) that are, in turn, used to automate machine processes. The other one was the Deep Panda attack discovered in 2015, which compromised over 4 million US personnel records because of the ongoing cyberwar between China and the US. This paper explains the difficulties of detecting APTs and examines some of the research in this area. In addition, we also present a new approach to detecting APTs using the Security Information and Event Management (SIEM) solution. In this approach, we recommend establishing APT rulesets in SIEM solutions using the indicators left behind by the attacks. The three basic indicator types are considered in the rulesets and are examined in detail.

Anahtar Kelimeler

Kaynakça

  1. 1. J. Lee, B. Bagheri, H. Kao, "A Cyber-Physical Systems architecture for Industry 4.0-based manufacturing systems", Manufacturing Letters, Vol. 3, January 2015, Pages 18-23.
  2. 2. C. Tankard, "Advanced Persistent threats and how to monitor and deter them", Network Security, Vol. 2011, Issue 8, 2011, Pages 16-19.
  3. 3. Harknett, R. J. and Stever, J. A., "The New Policy World of Cybersecurity", Public Administration Review, Vol. 71, 2011, Pages 455-460. 4. M. Kenney, “Cyber-terrorism in a post-stuxnet world,” Orbis, Vol. 59, Issue 1, Pages. 111–128, 2015.
  4. 5. Kaspersky Lab, "The Darkhotel Apt - A Story Of Unusual Hospitality", Version 1.1, November 2014.
  5. 6. Kaspersky Lab, "Poseidon Group: a Targeted Attack Boutique specializing in global cyber-espionage", https://securelist.com/poseidon-group-a-targeted-attack-boutique-specializing-in-global-cyber-espionage/73673/, October 1, 2018.
  6. 7. Group IB and Fox It, "Anunak: APT Against Financial Institutions". https://www.group-ib.com/resources/research-hub/anunak-apt/, October 2, 2018.
  7. 8. P. S. Radzikowski, "CyberSecurity: Expanded Look at the APT Life Cycle and Mitigation", http://drshem.com/2016/02/11/cybersecurity-expanded-look-apt-life-cycle-mitigation/#footnote-dsp-5061.2, October 10, 2018.
  8. 9. Dell, "Lifecycle of an Advanced Persistent Threat", 2012, http://www.redteamusa.com/PDF/Lifecycle%20of%20an%20Advanced%20Persistent%20Threat.pdf, October 10, 2018.

Ayrıntılar

Birincil Dil

İngilizce

Konular

Yazılım Mühendisliği (Diğer)

Bölüm

Araştırma Makalesi

Erken Görünüm Tarihi

25 Aralık 2023

Yayımlanma Tarihi

31 Aralık 2023

Gönderilme Tarihi

31 Ağustos 2023

Kabul Tarihi

13 Aralık 2023

Yayımlandığı Sayı

Yıl 2023 Cilt: 7 Sayı: 3

Kaynak Göster

APA
Şimşek, A., & Koltuksuz, A. (2023). DETECTION OF ADVANCED PERSISTENT THREATS USING SIEM RULESETS. International Journal of 3D Printing Technologies and Digital Industry, 7(3), 471-477. https://doi.org/10.46519/ij3dptdi.1353341
AMA
1.Şimşek A, Koltuksuz A. DETECTION OF ADVANCED PERSISTENT THREATS USING SIEM RULESETS. IJ3DPTDI. 2023;7(3):471-477. doi:10.46519/ij3dptdi.1353341
Chicago
Şimşek, Adem, ve Ahmet Koltuksuz. 2023. “DETECTION OF ADVANCED PERSISTENT THREATS USING SIEM RULESETS”. International Journal of 3D Printing Technologies and Digital Industry 7 (3): 471-77. https://doi.org/10.46519/ij3dptdi.1353341.
EndNote
Şimşek A, Koltuksuz A (01 Aralık 2023) DETECTION OF ADVANCED PERSISTENT THREATS USING SIEM RULESETS. International Journal of 3D Printing Technologies and Digital Industry 7 3 471–477.
IEEE
[1]A. Şimşek ve A. Koltuksuz, “DETECTION OF ADVANCED PERSISTENT THREATS USING SIEM RULESETS”, IJ3DPTDI, c. 7, sy 3, ss. 471–477, Ara. 2023, doi: 10.46519/ij3dptdi.1353341.
ISNAD
Şimşek, Adem - Koltuksuz, Ahmet. “DETECTION OF ADVANCED PERSISTENT THREATS USING SIEM RULESETS”. International Journal of 3D Printing Technologies and Digital Industry 7/3 (01 Aralık 2023): 471-477. https://doi.org/10.46519/ij3dptdi.1353341.
JAMA
1.Şimşek A, Koltuksuz A. DETECTION OF ADVANCED PERSISTENT THREATS USING SIEM RULESETS. IJ3DPTDI. 2023;7:471–477.
MLA
Şimşek, Adem, ve Ahmet Koltuksuz. “DETECTION OF ADVANCED PERSISTENT THREATS USING SIEM RULESETS”. International Journal of 3D Printing Technologies and Digital Industry, c. 7, sy 3, Aralık 2023, ss. 471-7, doi:10.46519/ij3dptdi.1353341.
Vancouver
1.Adem Şimşek, Ahmet Koltuksuz. DETECTION OF ADVANCED PERSISTENT THREATS USING SIEM RULESETS. IJ3DPTDI. 01 Aralık 2023;7(3):471-7. doi:10.46519/ij3dptdi.1353341

Cited By

 download

Uluslararası 3B Yazıcı Teknolojileri ve Dijital Endüstri Dergisi Creative Commons Atıf-GayriTicari 4.0 Uluslararası Lisansı ile lisanslanmıştır.