Telecommunications Science ›› 2016, Vol. 32 ›› Issue (1): 82-87.doi: 10.11959/j.issn.1000-0801.2016012

• Ressearch and development • Previous Articles     Next Articles

A discovery strategy for APT anomaly based on homologous behavior analysis

Yihan YU,Yu FU,Xiaoping WU,Hongcheng LI   

  1. Department of Information Security,Naval University of Engineering,Wuhan 430033,China
  • Online:2016-01-20 Published:2017-06-23
  • Supported by:
    The National Natural Science Foundation of China;The Natrual Science Foudation of Hubei;Project of National Defense Key Laboratory of Information Security Technology

Abstract:

As APT(advanced persistent threat)attacks are increasingly frequently,higher requirements for the detection of APT attacks were proposed.It was an effective method to early discover the attack behavior of APT based on homologous behavior analysis.Aiming at the problem of low efficiency of data authentication caused by excessive data,the historical behavior database with data label technology was established and the database was stored in the cloud.Relying on the Hadoop platform and the aggregate computing ability of MapReduce and the pseudorandom permutation technique,the whole traffic parallel detection of the network was realized.In order to determine whether there was a APT attack behavior,the detection of APT attacks was implemented by comparing the data labels in the database.Test results show that the proposed method can detect the abnormal behavior of APT from the network as soon as possibleand improve the efficiency of the whole data flow detection.

Key words: APT defense, homologous strategy, real-time detection, data label, pseudorandom permutation

No Suggested Reading articles found!