A Collaborative Forensic Framework for Detecting Advanced Persistent Threats
Weifeng Xu · Proceedings/Proceedings of the ... International Conference on Software Engineering and Knowledge Engineering · 2021
An advanced persistent threat (APT) is one type of cybercrime that steals valuable information over an extended period through malicious activities.The paper proposes a collaborative framework to systematically detect APTs by analyzing the Cyber Forensic Evidence (CFE) collected from a System Under Investigation (SUI).It is a post-compromise analysis based on Forensic-Evidence-Driven Finite State Machines (FED-FSM) modeled from an SUI.A FED-FSM extends an FSM by defining a set of forensic evidence patterns as guided conditions that trigger the state changes of FSM.The approach consists of three tasks (1) collecting shared CFE and formalizing patterns of CFE, (2) modeling the security status of an SUI in a FED-FSM, and (3) building a Threat Activity Detection Engine to match the observed CFE from SUI logs with the CFE patterns in the FED-FSM.An empirical study shows the framework can be used to detect malicious activities of Poison Ivy, which utilizes a remote access tool to control computers.