A Framework of APT Detection Based on Dynamic Analysis
Yunfei Su, Mengjun Li, Chaojing Tang, Rongjun Shen · 2016
Advanced persistent threat (APT) is sophisticated cyber-attack and has attracted lots of attention in cyberspace.Traditional defense measures based on signature matching are insufficient to detect APT, such as Stuxnet, Operation Aurora, Duqu, Flame, Red October, Miniduke and so on.In this paper, we proposed a framework of APT detection which includes network traffic redirection module, user agent, reconstruction module, dynamic analysis module and decision module.The framework could effectively detect APT attacks compared with current defense systems.We provide a detailed example to illustrate how the framework detects APT attacks especially passive attacks.