MultiRHM: Defeating multi-staged enterprise intrusion attacks through multi-dimensional and multi-parameter host identity anonymization

Computers & Security(2023)

引用 0|浏览3
暂无评分
摘要
Advanced and persistent multi-staged intrusion attacks are usually conducted by elite well-resourced cyber threat actors with the goal of bypassing the defense-in-depth and zoning policies of enterprise networks and accessing critical internal assets which are embedded deep in the target network (Hutchins, Cloppert, Amin, et al., 2011, Wilkens, Ortmann, Haas, Vallentin, Fischer). Starting from an externally reachable host, these attacks compromise a chain of network hosts until they reach their targets. Each compromised host could provide attackers access to new systems and network zones, thus enabling them to intrude deeper into the network. While conventional detection-based mechanisms are necessary to defeat such attacks, they are not enough as they can be evaded by stealthy or zero-day attack techniques.
更多
查看译文
关键词
Cyber deception,Cyber agility,Multi-staged intrusions,IP randomization,Honeypots,Reconnaissance,Cyber Kill-Chain
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要