The Reliability Assessment for Advanced Persistent Threat Defense based on Correlation Evidence Reasoning Rule
Guozhu Wang, Guanyu Hu · 2021 CAA Symposium on Fault Detection, Supervision, and Safety for Technical Processes (SAFEPROCESS) · 2021
Advanced Persistent Threat (APT) is a cyber-attack method targeting large corporations, national institutions, and research institutes. APT attacks are multi-stage, long duration, and difficult to detect. Hacking actions that carry out APT attacks to steal important data and disrupt systems have become more frequent and rampant in recent years. Therefore, assessing the reliability of APT defense for complex network systems helps to develop plans to upgrade defense methods. In this paper, a framework including four aspects is established, and a correlation evidence reasoning (CER) model is proposed to assess the reliability of APT defense. Finally, a case study is constructed to illustrate the actual effect of the proposed method.