Cyber-attack group analysis method based on association of cyber-attack information

Citations

WEB OF SCIENCE

4
Citations

SCOPUS

6

초록

Cyber-attacks emerge in a more intelligent way, and various security technologies are applied to respond to such attacks. Still, more and more people agree that individual response to each intelligent infringement attack has a fundamental limit. Accordingly, the cyber threat intelligence analysis technology is drawing attention in analyzing the attacker group, interpreting the attack trend, and obtaining decision making information by collecting a large quantity of cyber-attack information and performing relation analysis. In this study, we proposed relation analysis factors and developed a system for establishing cyber threat intelligence, based on malicious code as a key means of cyber-attacks. As a result of collecting more than 36 million kinds of infringement information and conducting relation analysis, various implications that cannot be obtained by simple searches were derived. We expect actionable intelligence to be established in the true sense of the word if relation analysis logic is developed later.

키워드

Cyber Threat IntelligenceClusteringIndicatorAttack InformationRelationshipCyber-attacker
제목
Cyber-attack group analysis method based on association of cyber-attack information
저자
Son, Kyung-hoKim, Byung-ikLee, Tae-jin
DOI
10.3837/tiis.2020.01.015
발행일
2020-01-31
유형
Article
저널명
KSII Transactions on Internet and Information Systems
14
1
페이지
260 ~ 280