Identifying Vulnerabilities of Advanced Persistent Threats: An Organizational Perspective

被引:6
|
作者
Nicho, Mathew [1 ]
Khan, Shafaq [2 ]
机构
[1] Univ Dubai, Coll Informat Technol, MSc Program, Dubai, U Arab Emirates
[2] Univ Dubai, Coll Informat Technol, Dubai, U Arab Emirates
关键词
Advanced Persistent Threats; APT; Data Breach; Information Security; Phishing; Social Engineering; Spear-Phishing;
D O I
10.4018/ijisp.2014010101
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
One of the most serious and persistent threat that has emerged in recent years combining technical as well as non-technical skills is the Advanced Persistent Threat, commonly known as APT where hackers circumvent the organizational defenses and instead target the naivety of the employees in making an unintentional mistake. While this threat has gained prominence in recent years, research on its cause and mitigation is still at the infancy stage. In this paper the authors explore APT vulnerabilities from an organizational perspective to create a taxonomy of non-technical and technical vulnerabilities. The objective is to enhance awareness and detection of APT vulnerabilities by managers and end users. To this end, the authors conducted interviews with senior IT managers in three large organizations in Dubai, United Arab Emirates. The analysis of the findings suggested that the APT threat environment is affected by multiple factors spanning primarily nontechnical as well as technical vulnerabilities.
引用
收藏
页码:1 / 18
页数:18
相关论文
共 50 条
  • [1] Dimensions of 'Socio' Vulnerabilities of Advanced Persistent Threats
    Nicho, Mathew
    McDermott, Christopher D.
    2019 27TH INTERNATIONAL CONFERENCE ON SOFTWARE, TELECOMMUNICATIONS AND COMPUTER NETWORKS (SOFTCOM), 2019, : 521 - 525
  • [2] Systems Dynamics Modeling for Evaluating SocioTechnical Vulnerabilities in Advanced Persistent Threats
    Nicho, Mathew
    Girija, Shini
    2022 15TH INTERNATIONAL CONFERENCE ON HUMAN SYSTEM INTERACTION (HSI), 2022,
  • [3] Advanced Persistent Threats Based on Supply Chain Vulnerabilities: Challenges, Solutions, and Future Directions
    Tan, Zhuoran
    Parambath, Shameem Puthiya
    Anagnostopoulos, Christos
    Singer, Jeremy
    Marnerides, Angelos K.
    IEEE INTERNET OF THINGS JOURNAL, 2025, 12 (06): : 6371 - 6395
  • [4] Advanced Persistent Threats
    Ozzengin, Yavuz Selim
    Sakiz, Fatih
    Benzer, Recep
    2016 24TH SIGNAL PROCESSING AND COMMUNICATION APPLICATION CONFERENCE (SIU), 2016, : 1845 - 1848
  • [5] A Study on Advanced Persistent Threats
    Chen, Ping
    Desmet, Lieven
    Huygens, Christophe
    COMMUNICATIONS AND MULTIMEDIA SECURITY, CMS 2014, 2014, 8735 : 63 - 72
  • [6] A Practical Study on Advanced Persistent Threats
    Jeun, Inkyung
    Lee, Youngsook
    Won, Dongho
    COMPUTER APPLICATIONS FOR SECURITY, CONTROL AND SYSTEM ENGINEERING, 2012, 339 : 144 - +
  • [7] Advanced Persistent Threats & Social Engineering
    Weippl, Edgar
    2014 11TH INTERNATIONAL CONFERENCE ON E-BUSINESS (ICE-B), 2014, : IS21 - IS21
  • [8] Advanced Persistent Threats - Detection and Defense
    Vukalovic, J.
    Delija, D.
    2015 8TH INTERNATIONAL CONVENTION ON INFORMATION AND COMMUNICATION TECHNOLOGY, ELECTRONICS AND MICROELECTRONICS (MIPRO), 2015, : 1324 - 1330
  • [9] Advanced Persistent Threats: Behind the Scenes
    Ussath, Martin
    Jaeger, David
    Cheng, Feng
    Meinel, Christoph
    2016 ANNUAL CONFERENCE ON INFORMATION SCIENCE AND SYSTEMS (CISS), 2016,
  • [10] Advanced Persistent Threats & Social Engineering
    Weippl, Edgar
    2014 INTERNATIONAL CONFERENCE ON SIGNAL PROCESSING AND MULTIMEDIA APPLICATIONS (SIGMAP), 2014, : IS13 - IS13