论文部分内容阅读
目前针对APT攻击的检测技术比较多样,这是由攻击本身所具有的复杂性导致。Gartner在2013年将APT检测技术主要分为5种,如图1所示。其分类并不能完整呈现针对APT攻击的检测手段,但是对几个主要检测技术方向做了较好的阐述,本章将逐项分析各类技术发展现状:1网络流量分析该技术包含了多种传统的网络检测分析思路,比如依靠DNS或Netflow的流量规律进行基线学习和分析。此类技术发展历史
At present, the detection technologies for APT attacks are quite varied, which is caused by the complexity of the attack itself. In 2013, Gartner divided APT detection technologies into five types, as shown in Figure 1. The classification does not fully present the detection means for APT attack, but a few expositions are made on the direction of several major detection techniques. In this chapter, the status quo of various technologies will be analyzed one by one: 1 Network Traffic Analysis This technology includes many traditional Network detection and analysis ideas, such as relying on DNS or Netflow traffic rules for baseline learning and analysis. History of such technology development