APT attack detection methods
Cyberespionnage : the APT threat

Add to my library

H5842 V1 Quizzed article

APT attack detection methods
Cyberespionnage : the APT threat

Author : Cédric PERNET

Review date: June 23, 2021 | Lire en français

Add to my library Add to my library

Logo Techniques de l'Ingenieur You do not have access to this resource.
Request your free trial access! Free trial

Already subscribed?

3. APT attack detection methods

Detecting this type of attack is difficult, and requires multiple methods on several levels.

Quite often, detection comes from a source outside the company. For example, government agencies, private companies or CERT/CSIRT (Computer Emergency Response Team / Computer Security Incident Response Team) structures notify "victim" companies. In the course of their incident response, these structures may come across elements that point to other victims. This could be malware containing strings linked to other companies, or domain names close to company names, etc.

In the end, detecting APT incidents always comes down to two things:

  • detect malware or attacker tools on one or more company workstations or servers;

  • detect communications between malware or tools and servers...

You do not have access to this resource.
Logo Techniques de l'Ingenieur

Exclusive to subscribers. 97% yet to be discovered!

You do not have access to this resource. Click here to request your free trial access!

Already subscribed?


Ongoing reading
APT attack detection methods

Article included in this offer

"Safety and risk management"

( 477 articles )

Complete knowledge base

Updated and enriched with articles validated by our scientific committees

Services

A set of exclusive tools to complement the resources

View offer details
Contact us