Review article - advanced persistent threat

Assignment Help Software Engineering
Reference no: EM132082059

You need to review this article with references.

An advanced persistent threat (APT) is a broad term used to describe an attack campaign in which an intruder, or team of intruders, establishes an illicit, long-term presence on a network in order to mine highly sensitive data (Incapsula, 2018).

To better understand how to defend against an APT the organization must know how an APT conducts their operations. FireEye lists six steps of an APT attack.

First the cyber criminal, or threat actor, gains entry through an email, network, file, or application vulnerability and inserts malware into an organization's network.

The network is considered compromised but not breached. Second, the advanced malware probes for additional network access and vulnerabilities or communicates with command-and-control (CnC) servers to receive additional instructions and/or malicious code. Next, the malware typically establishes additional points of compromise to ensure that the cyber attack can continue if one point is closed.

Next, once a threat actor determines that they have established reliable network access, they gather target data, such as account names and passwords.

Even though passwords are often encrypted, encryption can be cracked. Once that happens, the threat actor can identify and access data. Next, the malware collects data on a staging server, then exfiltrates the data off the network and under the full control of the threat actor.

At this point, the network is considered breached. Finally, evidence of the APT attack is removed, but the network remains compromised.

The cyber criminal can return at any time to continue the data breach (FireEye, 2018). It is important to understand that traditional cyber security methods, such as defense-in-depth, firewalls, and antivirus cannot protect an organization from an APT threat. Using a more adaptive defense method can be the key to an organization's ability to defend against APTs.

Some methods to improve an organization's ability to defend against APTs include: use big data for analysis/detection, share information with the right people, understand the "kill chain", look for indicators of compromise (IOCs), test your network, and support more training for APT hunters (Armerding, 2014).

The overall theme between these methods is the assumption that the network is already compromised so defense includes finding the threat within the perimeter. Additional recommendations include: focus on solutions that address the malware risk, pay more attention to targeted attacks, develop expertise to handle the risk posed by Java and Adobe Readers, make the business case for investing in technologies that address APTs, understand the financial consequences of APTs, adopt new approaches to fight APTs, and endpoint security is an important part of an APT security strategy (Ponemon, 2014).

Some estimates of the costs of APT attacks are approximately $10 million. This makes a strong case for the business to invest in new techniques and technologies to combat the APT threat. Since the beginning of time, Satan has been attempting to corrupt this world and us. He could be considered the ultimate APT.

Just like cyber attackers, Satan seeks out the weak points in us to gain a foothold to slowly erode our faith. One specific example of how Satan finds and corrupts the weak is his interactions with Peter. During the difficult time of Jesus' capture Peter denied Jesus three times, "But Peter said, "Man I do not know what you are talking about." And immediately, while he was still speaking, the rooster crowed." (Luke 22:60).

This shows that even the people with the closest relationship with God can fall victim to the persistent threat. Also, similar to how APTs target government agencies and large corporation due to the potential for sensitive or valuable information, Satan attacks big targets such as Jesus, "Then Jesus was led by the Spirit into the wilderness to be tempted by the devil." (Matthew 4:1)

Regardless of the situation it is good to know that there are defenses against APTs and Satan's threats.

Attachment:- References.rar

Verified Expert

The task is associated with APTs. The APTs cannot be eliminated entirely for which damage related factors can not be managed. The APTs are becoming a challenge of security in today’s era. The risk related factor in relation with the with malware has been discussed in the task. For internet security related factor regarding the working of APTs must be known by the users.

Reference no: EM132082059

Questions Cloud

Describes motivational approaches utilized by organizations : The textbook describes motivational approaches utilized by organizations.
What specific techniques could smith use to increase ethics : The business has had several brushes with the law during the past few years, dealing with claims of false advertising and wrongful termination of employees.
Possible lurking variables : Since there is no random assignment and there may have been lurking variables, this conclusion is not justified. Which of the following are possible lurking.
What are the aspect of social media use in the workplace : The co ntent should focus on some aspect of social media use in the workplace. Potential examples include the importance of companies embracing social media.
Review article - advanced persistent threat : Review article - advanced persistent threat - describe an attack campaign in which an intruder, or team of intruders, establishes an illicit, long-term presence
Describe some trade-offs of using an instant stock : Describe some trade-offs of using an "instant" stock versus making one from scratch. List and discuss more than one.
How much profit will the company make : The company's break-even sales volume is $120,000. How much profit will the company make if it sells 4,000 units
Describe a product or service of a specific low-labor-cost : Describe a product or service of a specific low-labor-cost country as an example.
What is the volume of sales in units required : Zoro, Inc. produces a product that has a variable cost of $6.00 per unit. What is the volume of sales in units required to achieve the target profit

Reviews

inf2082059

11/1/2018 1:47:27 AM

Dear expert team well-written assignment..must appreciate. Highly recommended, Projects team went out of their way to get this assignment done in the short span of time. I have used their service so many times, I am fully satisfied by their outstanding work. thank you, team !!

Write a Review

Software Engineering Questions & Answers

  Research report on software design

Write a Research Report on software design and answer diffrent type of questions related to design. Report contain diffrent basic questions related to software design.

  A case study in c to java conversion and extensibility

A Case Study in C to Java Conversion and Extensibility

  Create a structural model

Structural modeling is a different view of the same system that you analyzed from a functional perspective. This model shows how data is organized within the system.

  Write an report on a significant software security

Write an report on a significant software security

  Development of a small software system

Analysis, design and development of a small software system.

  Systems analysis and design requirements

Systems Analysis and Design requirements

  Create a complete limited entry decision table

Create a complete limited entry decision table

  Explain flow boundaries map

Explain flow boundaries map the dfd into a software architecture using transform mapping.

  Frame diagrams

Prepare a frame diagram for the software systems.

  Identified systems and elements of the sap system

Identify computing devices, which could be used to support Your Improved Process

  Design a wireframe prototype

Design a wireframe prototype to meet the needs of the personas and requirements.

  Explain the characteristics of visual studio 2005

Explain the characteristics of Visual Studio 2005.

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd