Visible to the public Modelling Disruptive APTs targeting Critical Infrastructure using Military Theory

TitleModelling Disruptive APTs targeting Critical Infrastructure using Military Theory
Publication TypeConference Paper
Year of Publication2021
AuthorsMeijaard, Yoram, Meiler, Peter-Paul, Allodi, Luca
Conference Name2021 IEEE European Symposium on Security and Privacy Workshops (EuroS PW)
Date Publishedsep
Keywordsadvanced persistent threat, Computer crime, critical infrastructure, cyber situational awareness, Data Model, Data models, Human Behavior, Metrics, pubcrawl, Resiliency, Scalability
AbstractDisruptive Advanced Persistent Threats (D-APTs) are a new sophisticated class of cyberattacks targeting critical infrastructures. Whereas regular APTs are well-described in the literature, no existing APT kill chain model incorporates the disruptive actions of D-APTs and can be used to represent DAPTs in data. To this aim, the contribution of this paper is twofold: first, we review the evolution of existing APT kill chain models. Second, we present a novel D-APT model based on existing ATP models and military theory. The model describes the strategic objective setting, the operational kill chain and the tactics of the attacker, as well as the defender's critical infrastructure, processes and societal function.
DOI10.1109/EuroSPW54576.2021.00026
Citation Keymeijaard_modelling_2021