Journal of System Simulation ›› 2018, Vol. 30 ›› Issue (10): 3796-3806.doi: 10.16182/j.issn1004731x.joss.201810025

Previous Articles     Next Articles

APT-oriented Dynamic Assessment of Attack Behaviors

Wang Jindong, Yang Haopu, Zhang Hengwei, Li Tao   

  1. Information Engineering University, Zhengzhou 450001, China
  • Received:2016-09-08 Revised:2016-12-19 Online:2018-10-10 Published:2019-01-04

Abstract: The existing attack assessment methods cannot effectively deal with the long-term concealment in APT attack. Aiming at the accurate assessment of attack behaviors in APT attack, the APT-oriented dynamic assessment of attack behaviors which focuses on both the space dimension and the time dimension is proposed. The attack behaviors are correlated in the causality-diversion among the whole network system to discover the attack paths. The attack paths are modified in the time-diversion to get the dynamic causal attack traces. The attack traces are quantified based on CVSS standard. The experimental result shows that the proposed method can correctly reflect the attack status and effectively assess the attack behavior.

Key words: APT attack, attack quantification, dynamic assessment, causal correlation

CLC Number: