Modelling Disruptive APTs targeting Critical Infrastructure using Military Theory | IEEE Conference Publication | IEEE Xplore

Modelling Disruptive APTs targeting Critical Infrastructure using Military Theory


Abstract:

Disruptive Advanced Persistent Threats (D-APTs) are a new sophisticated class of cyberattacks targeting critical infrastructures. Whereas regular APTs are well-described ...Show More

Abstract:

Disruptive Advanced Persistent Threats (D-APTs) are a new sophisticated class of cyberattacks targeting critical infrastructures. Whereas regular APTs are well-described in the literature, no existing APT kill chain model incorporates the disruptive actions of D-APTs and can be used to represent DAPTs in data. To this aim, the contribution of this paper is twofold: first, we review the evolution of existing APT kill chain models. Second, we present a novel D-APT model based on existing ATP models and military theory. The model describes the strategic objective setting, the operational kill chain and the tactics of the attacker, as well as the defender’s critical infrastructure, processes and societal function.
Date of Conference: 06-10 September 2021
Date Added to IEEE Xplore: 29 October 2021
ISBN Information:

ISSN Information:

Conference Location: Vienna, Austria

Funding Agency:

Eindhoven University of Technology
TNO
Eindhoven University of Technology

I. Introduction

Cyberattacks span a range of attack techniques, levels of sophistication and stealthiness. In the upper-echelons of cyberspace we find Advanced Persistent Threats (APTs), highly sophisticated cyberattacks potentially posing a signifi-cant threat to national security [1]. Traditionally, APTs focus mainly on espionage. In recent years they have shown to be capable of disrupting important infrastructures such as the power grid [2] and nuclear facilities [3]. Changing the objective from stealthy extraction of information to disruption of ongoing processes distinguishes a new class of Disruptive APT (D-APT) attacks: sophisticated cyberattacks aimed at disrupting the normal operation of critical infrastructures.

Eindhoven University of Technology
TNO
Eindhoven University of Technology
Contact IEEE to Subscribe

References

References is not available for this document.