A study on security framework against advanced persistent threat
Qingyun Zhang, Huan Li, Jinsong Hu · 2017
Advanced Persistent Threat (APT) and traditional cyber attacks are different in kinds of aspects, which make the traditional defense is difficult to detect APT and protect the network. Therefore, an APT detection framework based on OpenIOC is established for the characteristics of APT system attack. Firstly, real-time attack data related to APT from massive fragmented threat data is output. Secondly, the data is transformed into real-time OpenIOC threat information by IOC which is used to measure the similarity with the history APT organization's OpenIOC threat information. Finally, the relationship between real-time attack characteristics and APT organization is analyzed, and history APT organization's attack behavior will be discovered.