引用本文:杨秀璋,彭国军,刘思德,田杨,李晨光,傅建明.面向APT攻击的溯源和推理研究综述.软件学报,2025,36(1):203-252
【打印本页】   【下载PDF全文】   查看/发表评论  【EndNote】   【RefMan】   【BibTex】
←前一篇|后一篇→ 过刊浏览    高级检索
本文已被:浏览 3508次   下载 2933 本文二维码信息
码上扫一扫!
分享到: 微信 更多
面向APT攻击的溯源和推理研究综述
杨秀璋1,2,3, 彭国军1,2, 刘思德1,2, 田杨1,2, 李晨光1,2, 傅建明1,2
1.武汉大学 国家网络安全学院, 湖北 武汉 430072;2.空天信息安全与可信计算教育部重点实验室 (武汉大学 国家网络安全学院), 湖北 武汉 430072;3.贵州大学 贵州省大数据产业发展应用研究院, 贵州 贵阳 550025
摘要:
高级可持续性威胁(advanced persistent threat, APT)是一种新型网络攻击, 具有极强的组织性、隐蔽性、持续性、对抗性和破坏性, 给全球网络安全带来严重危害. 传统APT攻击防御倾向于构建模型检测攻击的恶意性或识别家族类别, 以被动防御为主, 缺乏全面及深入地梳理APT攻击溯源和推理领域的工作. 基于此, 围绕APT攻击的溯源和推理的智能化方法开展综述性研究. 首先, 提出APT攻击防御链, 有效地将APT攻击检测、溯源和推理进行区分和关联; 其次, 详细比较APT攻击检测4个任务的相关工作; 然后, 系统总结面向区域、组织、攻击者、地址和攻击模型的APT攻击溯源工作; 再次, 将APT攻击推理划分为攻击意图推理、攻击路径感知、攻击场景还原、攻击阻断和反制这4个方面, 对相关研究进行详细总结和对比; 最后, 讨论APT攻击防御领域的热点主题、发展趋势和挑战.
关键词:  高级可持续威胁  网络安全  攻击溯源  攻击推理  人工智能
DOI:10.13328/j.cnki.jos.007162
分类号:
基金项目:国家自然科学基金(62172308, 61972297, 62172144, U1636107, 62062019)
Survey on Attribution and Inference Research for APT Attacks
YANG Xiu-Zhang1,2,3, PENG Guo-Jun1,2, LIU Si-De1,2, TIAN Yang1,2, LI Chen-Guang1,2, FU Jian-Ming1,2
1.School of Cyber Science and Engineering, Wuhan University, Wuhan 430072, China;2.Key Laboratory of Aerospace Information Security and Trusted Computing of Ministry of Education (School of Cyber Science and Engineering, Wuhan University), Wuhan 430072, China;3.Guizhou Big Data Academy, Guizhou University, Guiyang 550025, China
Abstract:
Advanced persistent threat (APT) is a novel form of cyberattack that is well-organized, stealthy, persistent, adversarial, and destructive, resulting in catastrophic consequences for global network security. Traditional APT attack defenses tend to construct models to detect whether the attacks are malicious or identify the malicious family categories, primarily employing a passive defense strategy and lacking comprehensive and in-depth exploration of the field of APT attack attribution and inference. In light of this, this study focuses on the intelligent methods of APT attack attribution and inference to conduct a survey study. Firstly, an overall defense chain framework for APT attacks is proposed, which can effectively distinguish and correlate APT attack detection, attribution, and inference. Secondly, the work related to the four tasks of APT attack detection is reviewed in detail. Thirdly, APT attack attribution research is systematically summarized for regions, organizations, attackers, addresses, and attack models. Then, APT attack inference is divided into four aspects: attack intent inference, attack path perception, attack scenario reconstruction, and attack blocking and countermeasures, and relevant works are summarized and compared in detail. Finally, the hot topics, development trends, and challenges in the field of APT attack defense are discussed.
Key words:  advanced persistent threat (APT)  network security  attack attribution  attack inference  artificial intelligence

引用本文:
【打印本页】   【下载PDF全文】   查看/发表评论  【EndNote】   【RefMan】   【BibTex】
←前一篇|后一篇→ 过刊浏览    高级检索
本文已被:浏览次   下载  
分享到: 微信 更多
摘要:
关键词:  
DOI:
分类号:
基金项目:
Abstract:
Key words: