Cyberespionnage : the APT threat

Add to my library

H5842 V1 Quizzed article

Cyberespionnage : the APT threat

Author : Cédric PERNET

Publication date: January 10, 2020, Review date: June 23, 2021 | Lire en français

Add to my library Add to my library

Logo Techniques de l'Ingenieur You do not have access to this resource.
Request your free trial access! Free trial

Already subscribed?

Overview

ABSTRACT

This article offers to help understanding the “APT” computer attacks, APT standing for “Advanced Persistent Threat”. These attacks enable attackers to get computer access to a targeted company network, in order to steal information like intellectual property or industrial secrets. Those attacks are cyberespionnage operations built and run by attackers who all follow the same modus operandi: collection of information about the target, initial compromise, continuously strengthening the accesses, discovery and data exfiltration. The paper also provides a list of detection methods.

Read this article from a comprehensive knowledge base, updated and supplemented with articles reviewed by scientific committees.

Read the article

AUTHOR

 INTRODUCTION

APT (Advanced Persistent Threat) attacks are computer attacks designed to compromise and maintain access to an entity's information system for the purpose of stealing information and data, usually from a private company or government body. The first of these attacks was publicized at the beginning of this century, but visibility of this type of threat really exploded in 2010 with Operation Aurora, targeting Google in particular.

The modus operandi of these attacks, described in this article, varies little and can be summarized as follows. The attackers first study their target, in order to obtain the elements they need to carry out an initial compromise of the system. Once access has been obtained, they deploy on the system, reinforcing existing access (by adding backdoors or remote control tools) and gaining extended rights on the network. They then target the desired information and exfiltrate it. They generally maintain their access for weeks, months or, in some cases, years.

What makes these attacks difficult to detect and combat is that the adversary maintains access over time by regularly changing the tools deployed on the system. Malware and software useful to the attacker are updated, and the servers controlling this malware also change regularly.

We will nevertheless propose solutions for detecting and maintaining this type of attack on a computer system.

You do not have access to this resource.
Logo Techniques de l'Ingenieur

Exclusive to subscribers. 97% yet to be discovered!

You do not have access to this resource. Click here to request your free trial access!

Already subscribed?


KEYWORDS

malware   |   cyberespionnage   |   computer threat

Ongoing reading
Cyberespionnage : the APT threat

Article included in this offer

"Security of information systems"

( 92 articles )

Complete knowledge base

Updated and enriched with articles validated by our scientific committees

Services

A set of exclusive tools to complement the resources

View offer details

Dans les ressources documentaires

Sécurité de l’information, cybersécurité et protection des données de vie privée - NF EN ISO/IEC 27001 : 2023

La sécurité de l'information fait partie du périmètre de la normalisation (ISO et AFNOR). À savoir les no...

Cloud Computing - Informatique en nuage

Le Cloud Computing est une révolution dans la manière d’organiser, de gérer et de distribuer des ressourc...

Technologies d’identification et d’authentification pour un système de traçabilité

La traçabilité consiste à retrouver à tout moment l’historique des événements de la vie d’un produit au m...

Système d’information hybride et sécurité : un retour à la réalité

La conception des architectures sécurisées des systèmes d’information a beaucoup évolué au cours des...

Tous les livres blancs
Article Internet décentralisé : retour au Web 1.0 !
10 October 2018
Internet décentralisé : retour au Web 1.0 !

Désinformation, surveillance étatique, fuites de données... Le web actuel souffre de différents maux. Avec des réseaux décentralisés, les utilisateurs garderaie...

Toutes les actualités
Contact us