Tracking Advanced Persistent Threats in Critical Infrastructures through Opinion Dynamics

TitleTracking Advanced Persistent Threats in Critical Infrastructures through Opinion Dynamics
Publication TypeConference Paper
Year of Publication2018
AuthorsJ. E. Rubio, R. Roman, C. Alcaraz, and Y. Zhang
Conference NameEuropean Symposium on Research in Computer Security (ESORICS 2018)
Date Published08/2018
Conference LocationBarcelona, Spain
KeywordsAdvanced Persistent Threat, Detection, Opinion Dynamics, Traceability

Advanced persistent threats pose a serious issue for modern industrial environments, due to their targeted and complex attack vectors that are difficult to detect. This is especially severe in critical infrastructures that are accelerating the integration of IT technologies. It is then essential to further develop effective monitoring and response systems that ensure the continuity of business to face the arising set of cyber-security threats. In this paper, we study the practical applicability of a novel technique based on opinion dynamics, that permits to trace the attack throughout all its stages along the network by correlating different anomalies measured over time, thereby taking the persistence of threats and the criticality of resources into consideration. The resulting information is of essential importance to monitor the overall health of the control system and correspondingly deploy accurate response procedures.

Citation KeyRubioRomanAlcarazZhang2018
Paper File:

Supported by SADCIP DISS-IIoT