,Under false flag: using technical artifacts for cyber attack attribution

来源 :网络空间安全科学与技术(英文版) | 被引量 : 0次 | 上传用户:wwwvvv79
下载到本地 , 更方便阅读
声明 : 本文档内容版权归属内容提供方 , 如果您对本文有版权争议 , 可与客服联系进行内容授权或下架
论文部分内容阅读
The attribution of cyber attacks is often neglected.The consensus still is that little can be done to prosecute the perpetrators-and unfortunately,this might be right in many cases.What is however only of limited interest for the private industry is in the center of interest for nation states.Investigating if an attack was carried out in the name of a nation state is a crucial task for secret services.Many methods,tools and processes exist for network-and computer forensics that allow the collection of traces and evidences.They are the basis to associate adversarial actions to threat actors.However,a serious problem which has not got the appropriate attention from research yet,are false flag campaigns,cyber attacks which apply covert tactics to deceive or misguide attribution attempts-either to hide traces or to blame others.In this paper we provide an overview of prominent attack techniques along the cyber kill chain.We investigate traces left by attack techniques and which questions in course of the attribution process are answered by investigating these traces.Eventually,we assess how easily traces can be spoofed and rate their relevancy with respect to identifying false flag campaigns.
其他文献
为对抗反舰导弹对水面舰艇的攻击,根据特种泡沫云的干扰机理和当前反舰导弹制导技术的现状,分析了特种泡沫云干扰反舰导弹的主要干扰样式,确定其干扰施放时机,并对干扰所需的
为适应信息化条件下海战的特点和发展,提出海上蜂群战的概念,探究其机理,研究实施海上蜂群战的可行性、兵力需求和构成,以及战术运用等问题,所得结果对海上蜂群战的理论研究
流动性、安全性和赢利性是现代商业银行经营管理中所必须遵循的三项基本原则,而其中,流动性又是安全性和赢利性的前提。因此,从这个意义上讲,流动性是商业银行的生命线,保持适度的
学位
Recently released Intel processors have been equipped with hardware instruction tracing facilities to securely and efficiently record the program execution path
Security vulnerability is one of the root causes of cyber-security threats.To discover vulnerabilities and fix them in advance,researchers have proposed several
军事航线优选必须综合考虑舰艇航渡在准时、隐蔽、安全等方面的要求.这些优选条件本身的不确定性和模糊性使得优选信息的定量化处理和集成较为困难,因而限制了计算机辅助优选
进行舰载导弹武器系统瞄准精度试验,以确定系统瞄准误差,是舰载导弹武器系统鉴定所不可或缺的一个环节;在传统试验数据处理算法的基础上,对算法加以改进,使计算结果更为精确,
文章从作战使用条件对反舰导弹射击精度的影响入手,探讨了反舰导弹射击精度试验的阶段目标管理,给出了试验的流程,明确了试验结果的分析方法,对反舰导弹射击精度试验模式转变
提出了一种在大型水面舰艇编队航渡中,伴随配置潜艇进行反潜警戒行动的方法--“蝙搜”伴随法,阐明了定义、相关概念和具体行动方法,进行了初步的研究,并通过仿真提出了潜艇的
多用途化,是舰炮弹药的重要发展方向;分析了舰炮多用途子母弹的军事需求,提出舰炮多用途子母弹的总体技术方案,并对其技术可行性及装备效能进行分析,方案在实现弹丸多用途要