Journals / Süleyman Demirel Üniversitesi Fen Bilimleri Enstitüsü Dergisi / 2018 / Cilt: 22 - Sayı: Özel
A Flow Based Approach to Detect Advanced Persistent Threats in Communication Systems
- Pages
- 519–528
- DOI
- —
Abstract
The expansive usage of the Internet has set the stage for advancedpersistent threats that has increased costs considerably in cyber space. Most of thetime, entities exchange information and they are controlled remotely via manycommunication systems with a rich connectivity options on the Internet. Intrudersaccomplish advanced persistent threats by using such a rich connectivity options.These threats are extremely complex and they have unique features. Detectingsuch threats and corresponding attacks are therefore very difficult thatcircumstance makes classical intrusion detection systems impossible to deal withthem. In this paper, a flow-based approach to detect advanced persistent threats ispresented with a new model, namely FD-APT. The approach considers advancedpersistent threats based attacks that are carried out with advanced malware.Moreover, FD-APT model distinguishes properties of malware types. The newapproach is also analyzed with two case studies to highlight capabilities of FD-APT.The analyses results show that FD-APT helps to detect advanced persistent threatsthat are based on advanced malware.
Özet
Internet’in yaygın kullanımı, gelişmiş sürekli tehditlerin ortaya çıkmasına ve dolayısı ile siber uzaydaki maliyetlerin önemli ölçüde artmasına sebep olmaktadır. Çoğu zaman Internet, haberleşme sistemlerini kullanarak etmenler için bilgi alış verişini gerçekleştirmektedir ve bunların uzaktan kontrolü için zengin bir bağlantı seçeneği sunmaktadır. Saldırganlar, gelişmiş sürekli tehditleri bu zengin bağlantı seçeneği ile ellerinde bulundururlar. Bu tehditler son derece karmaşıktır ve benzersiz özelliklere sahiptirler. Bundan dolayı bu tehditleri tespit etmek son derece zordur, öyle ki klasik saldırı tespit sistemlerinin bunları tespit etmesi olanaksızdır. Bu makalede, gelişmiş sürekli tehditleri tespit etmek için akış tabanlı bir yaklaşım ve adını FD-APT verdiğimiz ilgili bir model önerilmiştir. Önerilen yaklaşım, gelişmiş sürekli tehditler tabanlı ve gelişmiş zararlı yazılımlar ile yapılan saldırıları dikkate almaktadır. Üstelik FD-APT gelişmiş zararlı yazılımların ayırt edici özelliklerine göre tasarlanmıştır. Önerilen yeni yaklaşımın kabiliyetlerini ortaya çıkarmak için iki örnek olay ile analiz çalışması yapılmıştır. Analiz sonuçları göstermektedir ki FD-APT gelişmiş zararlı yazılım tabanlı gelişmiş sürekli tehditlerin tespitine yardımcı olabilmektedir.