3. APT attack detection methods
Detecting this type of attack is difficult, and requires multiple methods on several levels.
Quite often, detection comes from a source outside the company. For example, government agencies, private companies or CERT/CSIRT (Computer Emergency Response Team / Computer Security Incident Response Team) structures notify "victim" companies. In the course of their incident response, these structures may come across elements that point to other victims. This could be malware containing strings linked to other companies, or domain names close to company names, etc.
In the end, detecting APT incidents always comes down to two things:
detect malware or attacker tools on one or more company workstations or servers;
detect communications between malware or tools and servers...
Exclusive to subscribers. 97% yet to be discovered!
Already subscribed? Log in!
APT attack detection methods
Article included in this offer
"Security of information systems"
(
92 articles
)
Updated and enriched with articles validated by our scientific committees
A set of exclusive tools to complement the resources
Bibliography
- (1) - ICANN WHOIS - Aperçu technique du protocole Whois. - https://whois.icann.org/fr/aperçu-technique
- (2) - Phishing box - Symantec Internet...
Exclusive to subscribers. 97% yet to be discovered!
Already subscribed? Log in!