Review

Provisioning the external infrastructure for Cyberspace Operations. A spotlight on Russian APT groups

Volume: 13 Number: 2 June 30, 2024
EN

Provisioning the external infrastructure for Cyberspace Operations. A spotlight on Russian APT groups

Abstract

Advanced threat actors conduncting operations in cyberspace require the utilization of external infrastructure. This referes to elements of infrastructure available on the Internet, situated outside the target’s own premises. The analysis of this infrastructure and the techniques employed to bring it to full operational capacity constitute a pivotal factor in characterizing threat actors and their operations. However, the majority of the existing scientific and technical literature found focuses on internal infrastructure elements, particularly on malware implants, as well as on the tactics and techniques employed by the threat actor within their victim’s infrastructure. In this work a comprehensive analysis of this external infrastructure and its provisioning techniques is presented. While our research has primarily concentrated on Russian APT groups and their operations, our findings are equally applicable to all advanced groups and operations. The outcomes of our study can greatly assist analysts in characterizing these groups and their operations, especially with regards to attribution efforts. Our proposal follows a logical structure that can be easy to expand and adapt, and it can be used to improve commonly accepted industry standards such as MITRE ATT&CK.

Keywords

References

  1. [1] R. Ross et al., SP 800-39. Managing information security risk: Organization, mission, and information system view. National Institute of Standards & Technology, 2011.
  2. [2] P. Chen, L. Desmet, and C. Huygens, “A study on advanced persistent threats,” in Communications and Multimedia Security: 15th IFIP TC 6/TC 11 International Conference, CMS 2014, Aveiro, Portugal, September 25-26, 2014. Proceedings 15. Springer, 2014, pp. 63–72.
  3. [3] J. Carr, Inside cyber warfare: Mapping the cyber underworld. O’Reilly Media, Inc., 2012.
  4. [4] K. Giles, “Information Troops. a russian cyber command?” in 2011 3rd International Conference on Cyber Conflict. IEEE, 2011, pp. 1–16.
  5. [5] M. Connell and S. Vogler, “Russia’s approach to cyber warfare,” [Online]. Available: https://www.cna.org/archive/ CNA Files/pdf/dop-2016-u-014231-1rev.pdf, Center for Naval Analyses, Tech. Rep., September 2016.
  6. [6] V. Akimenko and K. Giles, “Russia’s cyber and information warfare,” Asia policy, vol. 15, no. 2, pp. 67–75, 2020.
  7. [7] M. Grzegorzewski, “Russian cyber operations: The relationship between the state and cybercriminals,” in Historical and legal aspects of cyber attacks on critical infrastructure, D. Caleta and J. F. Powers, Eds. Ministry of Defense, Republic of Slovenia, 2020, pp. 53–64.
  8. [8] R. Morgus, B. Fonseca, K. Green, and A. Crowther, “Are china and russia on the cyber offensive in latin america and the caribbean? a review of their cyber capabilities and the implications for the US and its partners in the region,” [Online]. Available: http://newamerica.org/cybersecurity-initiative/reports/russiachina- cyber-offensive-latam-caribbean/, Tech. Rep., July 2019.

Details

Primary Language

English

Subjects

System and Network Security

Journal Section

Review

Publication Date

June 30, 2024

Submission Date

March 21, 2024

Acceptance Date

April 14, 2024

Published in Issue

Year 2024 Volume: 13 Number: 2

APA
Villalon-huerta, A., Ripoll-ripoll, I., & Marco-gisbert, H. (2024). Provisioning the external infrastructure for Cyberspace Operations. A spotlight on Russian APT groups. International Journal of Information Security Science, 13(2), 1-32. https://doi.org/10.55859/ijiss.1431064
AMA
1.Villalon-huerta A, Ripoll-ripoll I, Marco-gisbert H. Provisioning the external infrastructure for Cyberspace Operations. A spotlight on Russian APT groups. IJISS. 2024;13(2):1-32. doi:10.55859/ijiss.1431064
Chicago
Villalon-huerta, Antonio, Ismael Ripoll-ripoll, and Hector Marco-gisbert. 2024. “Provisioning the External Infrastructure for Cyberspace Operations. A Spotlight on Russian APT Groups”. International Journal of Information Security Science 13 (2): 1-32. https://doi.org/10.55859/ijiss.1431064.
EndNote
Villalon-huerta A, Ripoll-ripoll I, Marco-gisbert H (June 1, 2024) Provisioning the external infrastructure for Cyberspace Operations. A spotlight on Russian APT groups. International Journal of Information Security Science 13 2 1–32.
IEEE
[1]A. Villalon-huerta, I. Ripoll-ripoll, and H. Marco-gisbert, “Provisioning the external infrastructure for Cyberspace Operations. A spotlight on Russian APT groups”, IJISS, vol. 13, no. 2, pp. 1–32, June 2024, doi: 10.55859/ijiss.1431064.
ISNAD
Villalon-huerta, Antonio - Ripoll-ripoll, Ismael - Marco-gisbert, Hector. “Provisioning the External Infrastructure for Cyberspace Operations. A Spotlight on Russian APT Groups”. International Journal of Information Security Science 13/2 (June 1, 2024): 1-32. https://doi.org/10.55859/ijiss.1431064.
JAMA
1.Villalon-huerta A, Ripoll-ripoll I, Marco-gisbert H. Provisioning the external infrastructure for Cyberspace Operations. A spotlight on Russian APT groups. IJISS. 2024;13:1–32.
MLA
Villalon-huerta, Antonio, et al. “Provisioning the External Infrastructure for Cyberspace Operations. A Spotlight on Russian APT Groups”. International Journal of Information Security Science, vol. 13, no. 2, June 2024, pp. 1-32, doi:10.55859/ijiss.1431064.
Vancouver
1.Antonio Villalon-huerta, Ismael Ripoll-ripoll, Hector Marco-gisbert. Provisioning the external infrastructure for Cyberspace Operations. A spotlight on Russian APT groups. IJISS. 2024 Jun. 1;13(2):1-32. doi:10.55859/ijiss.1431064

Cited By