Detection of advanced persistent threats using SIEM rulesets

dc.contributor.authorŞimşek, Adem
dc.contributor.authorKoltuksuz, Ahmet Hasan
dc.date.accessioned2024-08-20T20:25:45Z
dc.date.available2024-08-20T20:25:45Z
dc.date.issued2023
dc.departmentAntalya Belek Üniversitesien_US
dc.description.abstractCyber-attacks move towards a sophisticated, destructive, and persistent position, as in the case of Stuxnet, Dark Hotel, Poseidon, and Carbanak. These attacks are called Advanced Persistent Threats (APTs), in which an intruder establishes an undetected presence in a network to steal sensitive data over a prolonged period. APT attacks threaten the main critical areas of today's digitalized life. This threat covers critical infrastructures, finance, energy, and aviation agencies. One of the most significant APT attacks was Stuxnet, which targeted the software controlling the programmable logic controllers (PLCs) that are, in turn, used to automate machine processes. The other one was the Deep Panda attack discovered in 2015, which compromised over 4 million US personnel records because of the ongoing cyberwar between China and the US. This paper explains the difficulties of detecting APTs and examines some of the research in this area. In addition, we also present a new approach to detecting APTs using the Security Information and Event Management (SIEM) solution. In this approach, we recommend establishing APT rulesets in SIEM solutions using the indicators left behind by the attacks. The three basic indicator types are considered in the rulesets and are examined in detail.en_US
dc.identifier.doi10.46519/ij3dptdi.1353341
dc.identifier.endpage477en_US
dc.identifier.issn2602-3350
dc.identifier.issue3en_US
dc.identifier.startpage471en_US
dc.identifier.trdizinid1217898en_US
dc.identifier.urihttps://doi.org/10.46519/ij3dptdi.1353341
dc.identifier.urihttps://search.trdizin.gov.tr/tr/yayin/detay/1217898
dc.identifier.urihttps://hdl.handle.net/20.500.14591/81
dc.identifier.volume7en_US
dc.indekslendigikaynakTR-Dizinen_US
dc.language.isoenen_US
dc.relation.ispartofInternational Journal of 3D Printing Technologies and Digital Industryen_US
dc.relation.publicationcategoryMakale - Ulusal Hakemli Dergi - Kurum Öğretim Elemanıen_US
dc.rightsinfo:eu-repo/semantics/openAccessen_US
dc.subjectCyber Securityen_US
dc.subjectCyber Waren_US
dc.subjectAPTen_US
dc.subjectSIEMen_US
dc.subjectIntrusion Detection Systemen_US
dc.titleDetection of advanced persistent threats using SIEM rulesetsen_US
dc.typeArticleen_US

Files

Original bundle
Now showing 1 - 1 of 1
No Thumbnail Available
Name:
adem-simsek.pdf
Size:
613.46 KB
Format:
Adobe Portable Document Format