Passer à la navigation principale Passer à la recherche Passer au contenu principal

Enhancing Cyber Situation Awareness: Visualizing Advanced Persistent Threats as Complex Systems: Visualizing Advanced Persistent Threats as Complex Systems

  • Georgi Nikolov
  • , Margaret Varga
  • , April Rose Panganiban
  • , Kaur Kullman
  • , Valérie Lavigne
  • University of Oxford
  • Air Force Research Laboratory
  • University of Maryland Baltimore County
  • DRDC

Résultats de recherche: Chapitre dans un livre, un rapport, des actes de conférencesContribution à une conférenceRevue par des pairs

Résumé

In recent years the field of Information Technologies has become ubiquitous, it is used to implement and manage private, public, government and military installations. This has led to massive growth in the threat landscape, attackers have ample time, resources, technologies and tools to design highly sophisticated attacks implementing Zero-Day Vulnerabilities and complex algorithms using polymorphic behaviour, putting a major strain on defenders. Rapid advancement of Advanced Persistent Threats (APT) poses a major security risk for online services, but even more so for critical government, financial, healthcare and military infrastructures. The difficulty in counteracting APTs is amplified by the increasing challenge of identifying and preparing countermeasures in time. There is ample research and documentation available, describing the life-cycle of various APTs and their Tactics Techniques and Practices (TTPs), but a lack of deeper understanding hinders timely detection to halt the attack. To better understand APTs and how they function, we propose addressing emergent cyber attacks from the perspective of Complex Systems and the application of Visual Analytics and visualization to enhance the level of understanding and Situation Awareness. In this paper, we discuss how we can analyse APTs from a Complex System perspective, the visualization techniques and visual analytics approaches used and how they can be applied for better detection, understanding and management.

langue originaleAnglais
titreAvailability, Reliability and Security - ARES 2025 International Workshops, Proceedings
Sous-titreARES 2025
rédacteurs en chefBart Coppens, Bruno Volckaert, Bjorn De Sutter, Vincent Naessens
EditeurSpringer
Pages90-107
Nombre de pages18
ISBN (Electronique)978-3-032-00633-2
ISBN (imprimé)978-3-032-00632-5
Les DOIs
étatPublié - 9 août 2025
EvénementInternational Workshops on Availability, Reliability and Security, held under the umbrella of the 20th International conference on Availability, Reliability and Security, ARES 2025 - Ghent, Belgique
Durée: 11 août 202514 août 2025

Série de publications

NomLecture Notes in Computer Science
Volume15995 LNCS
ISSN (imprimé)0302-9743
ISSN (Electronique)1611-3349

Une conférence

Une conférenceInternational Workshops on Availability, Reliability and Security, held under the umbrella of the 20th International conference on Availability, Reliability and Security, ARES 2025
Pays/TerritoireBelgique
La villeGhent
période11/08/2514/08/25

Empreinte digitale

Examiner les sujets de recherche de « Enhancing Cyber Situation Awareness: Visualizing Advanced Persistent Threats as Complex Systems: Visualizing Advanced Persistent Threats as Complex Systems ». Ensemble, ils forment une empreinte digitale unique.

Contient cette citation