APTs: a poorly understood challenge

Gordon Thomson · Network Security · 2011

The first half of 2011 witnessed a seemingly non-stop array of data breaches directed at companies, and sometimes individuals, across many sectors. Equally as diverse as the targets were the motivations behind the attacks. In many of the breach incidents, customer data was stolen and publicly published. In some of those cases, the attackers claimed the motive was to shed light on security issues. But in other cases of stolen and published customer data, attackers claimed to be doing it for the simple pleasure of mayhem – for the ‘lulz’. Advanced Persistent Threat (APT) attacks have been the subject of much debate, but there's no escaping the fact that they're real and widespread. Organisations are at extremely high risk and need advanced detection capabilities. The state-of-the-art response to APTs does not involve new magic software or hardware solutions divining for APT, but relies more on asking the right questions and being able to effectively use the existing detection tools, according to Gordon Thomson of Cisco Security EMEA.

Read the paper · More papers on PaperTik