Cargando…

A systematic literature review for APT detection and Effective Cyber Situational Awareness (ECSA) conceptual model

Advancements in computing technology and the growing number of devices (e.g., computers, mobile) connected to networks have contributed to an increase in the amount of data transmitted between devices. These data are exposed to various types of cyberattacks, one of which is advanced persistent threa...

Descripción completa

Detalles Bibliográficos
Autores principales: Salim, Duraid Thamer, Singh, Manmeet Mahinderjit, Keikhosrokiani, Pantea
Formato: Online Artículo Texto
Lenguaje:English
Publicado: Elsevier 2023
Materias:
Acceso en línea:https://www.ncbi.nlm.nih.gov/pmc/articles/PMC10336420/
https://www.ncbi.nlm.nih.gov/pubmed/37449192
http://dx.doi.org/10.1016/j.heliyon.2023.e17156
_version_ 1785071206019366912
author Salim, Duraid Thamer
Singh, Manmeet Mahinderjit
Keikhosrokiani, Pantea
author_facet Salim, Duraid Thamer
Singh, Manmeet Mahinderjit
Keikhosrokiani, Pantea
author_sort Salim, Duraid Thamer
collection PubMed
description Advancements in computing technology and the growing number of devices (e.g., computers, mobile) connected to networks have contributed to an increase in the amount of data transmitted between devices. These data are exposed to various types of cyberattacks, one of which is advanced persistent threats (APTs). APTs are stealthy and focus on sophisticated, specific targets. One reason for the detection failure of APTs is the nature of the attack pattern, which changes rapidly based on advancements in hacking. The need for future researchers to understand the gap in the literature regarding APT detection and to explore improved detection techniques has become crucial. Thus, this systematic literature review (SLR) examines the different approaches used to detect APT attacks directed at the network system in terms of approach and assessment metrics. The SLR includes papers on computer, mobile, and internet of things (IoT) technologies. We performed an SLR by searching six leading scientific databases to identify 75 studies that were published from 2012 to 2022. The findings from the SLR are discussed in terms of the literature's research gaps, and the study provides essential recommendations for designing a model for early APT detection. We propose a conceptual model known as the Effective Cyber Situational Awareness Model to Detect and Predict Mobile APTs (ECSA-tDP-MAPT), designed to effectively detect and predict APT attacks on mobile network traffic.
format Online
Article
Text
id pubmed-10336420
institution National Center for Biotechnology Information
language English
publishDate 2023
publisher Elsevier
record_format MEDLINE/PubMed
spelling pubmed-103364202023-07-13 A systematic literature review for APT detection and Effective Cyber Situational Awareness (ECSA) conceptual model Salim, Duraid Thamer Singh, Manmeet Mahinderjit Keikhosrokiani, Pantea Heliyon Review Article Advancements in computing technology and the growing number of devices (e.g., computers, mobile) connected to networks have contributed to an increase in the amount of data transmitted between devices. These data are exposed to various types of cyberattacks, one of which is advanced persistent threats (APTs). APTs are stealthy and focus on sophisticated, specific targets. One reason for the detection failure of APTs is the nature of the attack pattern, which changes rapidly based on advancements in hacking. The need for future researchers to understand the gap in the literature regarding APT detection and to explore improved detection techniques has become crucial. Thus, this systematic literature review (SLR) examines the different approaches used to detect APT attacks directed at the network system in terms of approach and assessment metrics. The SLR includes papers on computer, mobile, and internet of things (IoT) technologies. We performed an SLR by searching six leading scientific databases to identify 75 studies that were published from 2012 to 2022. The findings from the SLR are discussed in terms of the literature's research gaps, and the study provides essential recommendations for designing a model for early APT detection. We propose a conceptual model known as the Effective Cyber Situational Awareness Model to Detect and Predict Mobile APTs (ECSA-tDP-MAPT), designed to effectively detect and predict APT attacks on mobile network traffic. Elsevier 2023-06-16 /pmc/articles/PMC10336420/ /pubmed/37449192 http://dx.doi.org/10.1016/j.heliyon.2023.e17156 Text en © 2023 The Authors https://creativecommons.org/licenses/by/4.0/This is an open access article under the CC BY license (http://creativecommons.org/licenses/by/4.0/).
spellingShingle Review Article
Salim, Duraid Thamer
Singh, Manmeet Mahinderjit
Keikhosrokiani, Pantea
A systematic literature review for APT detection and Effective Cyber Situational Awareness (ECSA) conceptual model
title A systematic literature review for APT detection and Effective Cyber Situational Awareness (ECSA) conceptual model
title_full A systematic literature review for APT detection and Effective Cyber Situational Awareness (ECSA) conceptual model
title_fullStr A systematic literature review for APT detection and Effective Cyber Situational Awareness (ECSA) conceptual model
title_full_unstemmed A systematic literature review for APT detection and Effective Cyber Situational Awareness (ECSA) conceptual model
title_short A systematic literature review for APT detection and Effective Cyber Situational Awareness (ECSA) conceptual model
title_sort systematic literature review for apt detection and effective cyber situational awareness (ecsa) conceptual model
topic Review Article
url https://www.ncbi.nlm.nih.gov/pmc/articles/PMC10336420/
https://www.ncbi.nlm.nih.gov/pubmed/37449192
http://dx.doi.org/10.1016/j.heliyon.2023.e17156
work_keys_str_mv AT salimduraidthamer asystematicliteraturereviewforaptdetectionandeffectivecybersituationalawarenessecsaconceptualmodel
AT singhmanmeetmahinderjit asystematicliteraturereviewforaptdetectionandeffectivecybersituationalawarenessecsaconceptualmodel
AT keikhosrokianipantea asystematicliteraturereviewforaptdetectionandeffectivecybersituationalawarenessecsaconceptualmodel
AT salimduraidthamer systematicliteraturereviewforaptdetectionandeffectivecybersituationalawarenessecsaconceptualmodel
AT singhmanmeetmahinderjit systematicliteraturereviewforaptdetectionandeffectivecybersituationalawarenessecsaconceptualmodel
AT keikhosrokianipantea systematicliteraturereviewforaptdetectionandeffectivecybersituationalawarenessecsaconceptualmodel