Yunfei Su, Mengjun Li, Chaojing Tang, Rongjun Shen
{"title":"APT Detection with Concolic Execution","authors":"Yunfei Su, Mengjun Li, Chaojing Tang, Rongjun Shen","doi":"10.14257/IJHIT.2017.10.7.01","DOIUrl":null,"url":null,"abstract":"Advanced persistent threat (APT) is sophisticated cyber-attack and has attracted lots of attention of security researchers in cybersecurity. Traditional defense measures based on signature matching such as antivirus products and IDS/IPS are insufficient to detect APT. Concolic(a portmanteau of CONCrete and SymbOLIC) execution is a hybrid software verification technique that performs symbolic execution which could be used for APT detection. In this paper, we proposed a framework of APT detection which includes network traffic redirection module, user agent, reconstruction module, dynamic analysis module and response module. With the help of concolic execution in dynamic analysis module, the framework could effectively and accurately detect APT attacks compared with current defense systems. We provide a detailed example to illustrate how the framework works against APT attacks especially passive attacks.","PeriodicalId":170772,"journal":{"name":"International Journal of Hybrid Information Technology","volume":"60 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2017-07-31","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"International Journal of Hybrid Information Technology","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.14257/IJHIT.2017.10.7.01","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0
Abstract
Advanced persistent threat (APT) is sophisticated cyber-attack and has attracted lots of attention of security researchers in cybersecurity. Traditional defense measures based on signature matching such as antivirus products and IDS/IPS are insufficient to detect APT. Concolic(a portmanteau of CONCrete and SymbOLIC) execution is a hybrid software verification technique that performs symbolic execution which could be used for APT detection. In this paper, we proposed a framework of APT detection which includes network traffic redirection module, user agent, reconstruction module, dynamic analysis module and response module. With the help of concolic execution in dynamic analysis module, the framework could effectively and accurately detect APT attacks compared with current defense systems. We provide a detailed example to illustrate how the framework works against APT attacks especially passive attacks.