Advanced Persistent Threat and Spear Phishing Emails
The result's identifiers
Result code in IS VaVaI
<a href="https://www.isvavai.cz/riv?ss=detail&h=RIV%2F00216224%3A14330%2F15%3A00080499" target="_blank" >RIV/00216224:14330/15:00080499 - isvavai.cz</a>
Result on the web
<a href="http://dlsc.unob.cz/data/Proceedings%20of%20the%20DLSC%202015%20conference.pdf" target="_blank" >http://dlsc.unob.cz/data/Proceedings%20of%20the%20DLSC%202015%20conference.pdf</a>
DOI - Digital Object Identifier
—
Alternative languages
Result language
angličtina
Original language name
Advanced Persistent Threat and Spear Phishing Emails
Original language description
In recent years, cyber exploitation and malicious activity are becoming increasingly sophisticated, targeted, and serious. Advanced persistent threats or APTs are a new and more sophisticated version of known multistep attack scenarios. They are targetedspecifically to achieve a specific goal, most often espionage. These APTs form a problem for the current detection methods because these methods depend on known signatures of attacks and APTs make heavy use of unknown security holes for attacks. In thispaper we propose two blacklist-based detection methods for detecting a spear phishing email, which is the most common technique used in APT attack. The first method is malicious domain detection method, and the second one is malicious file hash detection method. The blacklists are automatically updated each day and the detection is in the real time.
Czech name
—
Czech description
—
Classification
Type
D - Article in proceedings
CEP classification
IN - Informatics
OECD FORD branch
—
Result continuities
Project
<a href="/en/project/OFMASUN201301" target="_blank" >OFMASUN201301: CIRC - Mobile dedicated devices to fulfilling ability to respond to cyber incidents</a><br>
Continuities
P - Projekt vyzkumu a vyvoje financovany z verejnych zdroju (s odkazem do CEP)<br>S - Specificky vyzkum na vysokych skolach
Others
Publication year
2015
Confidentiality
S - Úplné a pravdivé údaje o projektu nepodléhají ochraně podle zvláštních právních předpisů
Data specific for result type
Article name in the collection
Proceedings of International Conference Distance Learning, Simulation and Communication
ISBN
9788072319923
ISSN
—
e-ISSN
—
Number of pages
8
Pages from-to
34-41
Publisher name
University of Defence
Place of publication
Brno, Czech Republic
Event location
Brno, Czech Republic
Event date
May 19, 2015
Type of event by nationality
WRD - Celosvětová akce
UT code for WoS article
—