信息安全研究 ›› 2020, Vol. 6 ›› Issue (6): 0-0.

• 检测预警与态势感知专题 •    下一篇

面向高级持续性威胁的态势感知概念模型

孙岩炜,刘照辉,蒋仲白,孟祥杰,胡卫华   

  1. 中国信息安全测评中心
  • 收稿日期:2020-06-08 出版日期:2020-06-05 发布日期:2020-06-09
  • 通讯作者: 孙岩炜

A Situation Awareness Conceptual Model for Advanced Persistent Threat

  • Received:2020-06-08 Online:2020-06-05 Published:2020-06-09

摘要: 现有关于高级持续性威胁的研究大多聚焦于威胁的检测发现,对威胁的描述刻画并不全面.网络安全态势感知从整体角度出发,为决策者提供清晰的网络状态,有助于对威胁的全面认知.虽然国内外学者围绕态势感知开展了大量研究,但大多关注自身状态,仅仅达到“知己”的效果,“知彼”方面的研究相对较少.在态势感知模型的基础上,结合杀伤链模型、ATT&CK框架等相关研究,提出面向高级持续性威胁的态势感知概念模型.从敌我2方面综合讨论态势获取、理解、预测等环节的功能任务和相关技术,给出各环节形式化定义,为高级持续性威胁的认知及检测提供理论基础. 关键词 高级持续性威胁;态势感知;攻击链;概念模型;态势预测;

关键词: 高级持续性威胁, 态势感知, 攻击链, 概念模型, 态势预测

Abstract: Most existing researches on advanced persistent threats focus on the detection and discovery of threats, and the description of threats is not comprehensive. Network security situational awareness provides a clear network status for decision makers from a holistic perspective, which helps to comprehensively understand threats. Although scholars have carried out a lot of researches on situational awareness, most of them focus on their own state, only achieving the effect of "know ourselves", and relatively few studies on "know the enemy". Based on the situational awareness model, combined with related research such as the kill chain model, a conceptual situational awareness model for advanced persistent threats is proposed. This paper comprehensively discussed the functional tasks and related technologies of situation acquisition, understanding, and prediction from both perspectives. And then we made a discussion on the formal definition of each phase, providing a theoretical basis for advanced persistent threat detection and recognition.

Key words: advanced persistent threats, situation awareness, kill chain, conceptual model, situation projection