Abstract

The rise of emerging cyberthreats has led to a shift of focus on identifying the source of threat instead of the type of attack to provide a more effective defense to compromised environments against malicious acts. The most complex type of cyberthreat is the Advanced Persistent Threat (APT) attack that is usually backed by one or more states and lunched using a range of clandestine techniques aiming at high-value targets. Finding the source of the attackers and the associated campaign behind the threats can lead to taking an optimum defense decision in a more timely fashion. Threat attribution is an act of attributing an attack to the source of the attack. Threat attribution can not be fully achieved by a single piece of evidence (i.e. single view) from malicious actors as the evidence could get obfuscated by the actor to evade the detection mechanism. In this article, we propose a multi-view fuzzy consensus clustering model for attributing cyber threat payloads (malware) to its actor. We conduct over 4000 experiments to find out the best combinations of all 12 extracted views for the attribution task. Our experiments use five well-know APT families payloads. To avoid bias in the results, we apply a fuzzy pattern tree and multi-modal fuzzy classifier for our inference engines of all views. To define an optimum distinction among the malicious actor’s behavior we implemented the consensus clustering technique. The comparison analysis of a single-view versus multi-view result justifies a significant improvement in the accuracy rate of attribution for all actors. The obtained results from the multi-view aspect of our proposed model give 95.2% accuracy.

Highlights

  • Nowadays, cyberthreats are becoming more complex in their tactics, techniques, and procedures (TTP)

  • Most large-scale malware threats follow similar procedures that exist in highly risk threats named Advanced Persistent Threat (APT) attacks [2]

  • We propose a multi-view fuzzy consensus clustering model for attributing APT malware groups based on their different associated artifacts

Read more

Summary

INTRODUCTION

Cyberthreats are becoming more complex in their tactics, techniques, and procedures (TTP). H. Haddadpajouh et al.: MVFCC: A Multi-View Fuzzy Consensus Clustering Model for Malware Threat Attribution and building a complete picture that depicts possible sources of an attack. Haddadpajouh et al.: MVFCC: A Multi-View Fuzzy Consensus Clustering Model for Malware Threat Attribution and building a complete picture that depicts possible sources of an attack This is an even more complicated task in the cyber domain. This makes multi-view AI systems an optimal choice for threat attribution activities These systems evaluate sources of an attack based on remnants collected from different views and provide a good estimate of all possible sources of a campaign. We propose a multi-view fuzzy consensus clustering model for attributing APT malware groups based on their different associated artifacts.

RELATED WORK
EXPERIMENTAL RESULTS
CONCLUSION AND FUTURE WORKS
Full Text
Paper version not known

Talk to us

Join us for a 30 min session where you can share your feedback and ask us any queries you have

Schedule a call

Disclaimer: All third-party content on this website/platform is and will remain the property of their respective owners and is provided on "as is" basis without any warranties, express or implied. Use of third-party content does not indicate any affiliation, sponsorship with or endorsement by them. Any references to third-party content is to identify the corresponding services and shall be considered fair use under The CopyrightLaw.