Advanced persistent threats (APTs) have rocketed over the last years. Unfortunately, their technical characterization is incomplete--it is still unclear if they are advanced usages of regular malware or a different form of malware. This is key to develop an effective cyberdefense. To address this issue, in this paper we analyze the techniques and tactics at stake for both regular and APT-linked malware. To enable reproducibility, our approach leverages only publicly available datasets and analysis tools. Our study involves 11,651 regular malware and 4686 APT-linked ones. Results show that both sets are not only statistically different, but can be automatically classified with F1 > 0.8 in most cases. Indeed, 8 tactics reach F1 > 0.9. Beyond the differences in techniques and tactics, our analysis shows thats actors behind APTs exhibit higher technical competence than those from non-APT malwares.

A technical characterization of APTs by leveraging public resources

Lombardi, Flavio;
2023

Abstract

Advanced persistent threats (APTs) have rocketed over the last years. Unfortunately, their technical characterization is incomplete--it is still unclear if they are advanced usages of regular malware or a different form of malware. This is key to develop an effective cyberdefense. To address this issue, in this paper we analyze the techniques and tactics at stake for both regular and APT-linked malware. To enable reproducibility, our approach leverages only publicly available datasets and analysis tools. Our study involves 11,651 regular malware and 4686 APT-linked ones. Results show that both sets are not only statistically different, but can be automatically classified with F1 > 0.8 in most cases. Indeed, 8 tactics reach F1 > 0.9. Beyond the differences in techniques and tactics, our analysis shows thats actors behind APTs exhibit higher technical competence than those from non-APT malwares.
2023
Istituto Applicazioni del Calcolo ''Mauro Picone''
Advanced persistent threat; APTs; Malware; MITRE ATT and CK
File in questo prodotto:
File Dimensione Formato  
prod_489993-doc_204107.pdf

accesso aperto

Descrizione: A technical characterization of APTs by leveraging public resources
Tipologia: Versione Editoriale (PDF)
Licenza: Creative commons
Dimensione 933.06 kB
Formato Adobe PDF
933.06 kB Adobe PDF Visualizza/Apri

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/20.500.14243/451864
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 10
  • ???jsp.display-item.citation.isi??? 10
social impact