Title
Framework of Cyber Attack Attribution Based on Threat Intelligence.
Abstract
With the rapid growth of information technology, more and more devices are connected to the network. Cyber security environment has become increasingly complicated. In the face of advanced threats, such as targeted attack and advanced persistent threat, traditional security measures of accumulating security devices to protect relevant systems and networks had been proved to be an unqualified failure. Aiming at this situation, this paper proposed a framework of cyber attack attribution based on threat intelligence. At first, after surveying and analyzing related academic research and industry solutions, this paper used the local advantage model to analysis the process of cyber attack. According to the definitions of seven steps in intrusion kill chains and six phases of F2T2EA model, this model proposed a method of collecting threat intelligence data and detecting and response to cyber attacks, so as to achieve the goals of early-warming, processing detection and response and posting attribution analysis, and finally to reverse the security situation. Then, this paper designed a framework of cyber attack attribution based on threat intelligence. The framework is composed by Start of analysis, Threat intelligence and Attribution analysis. The three main parts indicated the architecture of cyber attack attribution. Finally, we tested the framework by practical case. The case study shows that the proposed framework can provide some help in attribution analysis.
Year
DOI
Venue
2016
10.1007/978-3-319-52727-7_11
Lecture Notes of the Institute for Computer Sciences, Social Informatics, and Telecommunications Engineering
Keywords
DocType
Volume
Cyber attack attribution,Framework,Threat intelligence,Intrusion kill chains,Advanced threat
Conference
190
ISSN
Citations 
PageRank 
1867-8211
0
0.34
References 
Authors
0
5
Name
Order
Citations
PageRank
Qiang Li101.01
Zeming Yang200.68
Baoxu Liu300.68
Zhengwei Jiang424.76
Jian Yan500.68