• DocumentCode
    1775299
  • Title

    Flow based analysis of Advanced Persistent Threats detecting targeted attacks in cloud computing

  • Author

    Vance, Andrew

  • Author_Institution
    Dept. of Cybersecurity & Inf. Assurance, Univ. of Maryland Univ. Coll., Adelphi, MD, USA
  • fYear
    2014
  • fDate
    14-17 Oct. 2014
  • Firstpage
    173
  • Lastpage
    176
  • Abstract
    Cloud computing provides industry, government, and academic users´ convenient and cost-effective access to distributed services and shared data via the Internet. Due to its distribution of diverse users and aggregation of immense data, cloud computing has increasingly been the focus of targeted attacks. Meta-analysis of industry studies and retrospective research involving cloud service providers reveal that cloud computing is demonstrably vulnerable to a particular type of targeted attack, Advanced Persistent Threats (APTs). APTs have proven to be difficult to detect and defend against in cloud based infocommunication systems. The prevalent use of polymorphic malware and encrypted covert communication channels make it difficult for existing packet inspecting and signature based security technologies such as; firewalls, intrusion detection sensors, and anti-virus systems to detect APTs. In this paper, we examine the application of an alternative security approach which applies an algorithm derived from flow based monitoring to successfully detect APTs. Results indicate that statistical modeling of APT communications can successfully develop deterministic characteristics for detection is a more effective and efficient way to protect against APTs.
  • Keywords
    cloud computing; security of data; statistical analysis; APT; Internet; advanced persistent threats; cloud based infocommunication systems; cloud computing; flow based analysis; flow based monitoring; packet inspection; signature based security technologies; statistical modeling; targeted attack detection; Cloud computing; Computer security; Logic gates; Telecommunication traffic; Vectors; Advanced Persistent Threats; Cloud Computing; Cyber Security; Flow Based Analysis; Threat Detection;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Infocommunications Science and Technology, 2014 First International Scientific-Practical Conference Problems of
  • Conference_Location
    Kharkov
  • Print_ISBN
    978-1-4799-7342-2
  • Type

    conf

  • DOI
    10.1109/INFOCOMMST.2014.6992342
  • Filename
    6992342