Method for determining false flag of cyber attack and apparatus for performing same
The method and device for determining cyber attack camouflage tactics address the limitations of existing methods by analyzing cyber attack information from both security analyst and hacker perspectives, enabling a more effective response to cyber attacks.
Patent Information
- Application Number
- PCT/KR2024/003144
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-08
- Filing Date
- 2024-03-12
- Publication Date
- 2025-06-12
AI Technical Summary
Existing breach incident analysis and attacker tracking methods struggle to effectively respond to cyber attackers' camouflage tactics due to their reliance on the analyst's experience and security perspective, lacking the perspective of the attacker.
A method and device for determining cyber attack camouflage tactics by collecting and analyzing cyber attack information, selecting relevant artifacts, classifying them based on evaluation indices, and calculating a camouflage tactic index that considers the perspectives of both security analysts and hackers.
This approach enables a more systematic and objective determination of cyber attack camouflage tactics, allowing for a more effective response to cyber attacks by considering the attacker's perspective.
Smart Images

Figure KR2024003144_12062025_PF_FP_ABST
Abstract
Description
Method for determining camouflage tactics of cyberattacks and device for performing the same
[0001] Embodiments of the present invention relate to a method for determining camouflage tactics of a cyber attack.
[0002]
[0003] In the cyber world, attacks by hackers and the defenses of security analysts are locked in a tense standoff. A cyber war unfolds, with attackers striving to conceal their activities and analysts tackling the attackers' identities. In this situation, security analysts have no choice but to analyze attackers' hacking activities based on artifacts collected from breach incidents, and they rely on these traces.
[0004] However, as cyberattack technology advances, so too do attackers' false flag tactics, making analysts vulnerable to deception. Consequently, existing breach analysis and attacker tracking methods are increasingly difficult to counter. Inadequate breach response can result in financial losses and budget waste.
[0005] In other words, existing breach analysis and attacker tracking methods only consider the analyst's experience and security perspective, so they exclude the perspective of the attacker who actually executes cyber camouflage tactics, making it difficult to actually respond to camouflage tactics.
[0006]
[0007] Embodiments of the present invention are intended to determine the camouflage tactics of cyber attacks based on artifacts that reflect the perspectives of a hacker, the attacker, as well as the perspectives of a security analyst, the defender of a cyber attack.
[0008]
[0009] According to an exemplary embodiment of the present invention, a method for judging a camouflage tactic of a cyberattack is provided, which is performed in a computing device having one or more processors and a memory storing one or more programs executed by the one or more processors, the method comprising: collecting cyberattack information from an external server in the computing device; selecting artifacts from the collected cyberattack information according to preset criteria in the computing device; classifying the selected artifacts into evaluation indices according to attributes of the selected artifacts in the computing device; and calculating a camouflage tactic index based on the classified evaluation indices in the computing device.
[0010] The method for determining camouflage tactics of the above cyber attack may further include a step of determining, in the computing device, camouflage tactics for the collected cyber attack information based on the calculated camouflage tactics index; and a step of providing the determination result to the user.
[0011] The step of collecting the above cyber breach information may further include a step of classifying the collected cyber breach information by attacker and storing the cyber breach information by attacker in the computing device.
[0012] The above artifacts include internet protocol (IP), domain, port, uniform resource locator (URL), command and control server (C2), server hosting records, HTTP referrer, log, email address, cryptocurrency address, hardware information, encryption / decryption method, obfuscation, metadata, digital certificate, packing, development information, time stamp, region, language, hash value, file type, behavior pattern, library, zero-day, N-day, remote code execution (RCE), privilege escalation, shellcode, decoy document. It can be one or more of document, phishing & pharming, SNS account, and attack target.
[0013] The above evaluation indicators may be one or more of anti-debugging, development environment, malware, vulnerability, and social engineering based on network, server, host, and attack technique-related attack factors based on fundamental factors related to infrastructure.
[0014] The step of calculating the camouflage tactic index may further include: a step of calculating, in the computing device, an attack index for each of the selected artifacts; a step of calculating, in the computing device, an attack index for each evaluation indicator based on the calculated attack index for each artifact; a step of calculating, in the computing device, a total attack index by adding up all of the calculated attack indices for each evaluation indicator; a step of calculating, in the computing device, an actual attack index based on a weight according to a correlation between the calculated total attack index and the evaluation indicators; and a step of calculating, in the computing device, the camouflage tactic index based on the calculated actual attack index.
[0015] The step of calculating the attack index for each selected artifact may further include a step of, in the computing device, assigning preset weights to each of the selected artifacts to set weights for each artifact; a step of, in the computing device, calculating a similarity for each artifact by comparing previously stored artifacts and the selected artifacts; and a step of, in the computing device, calculating the attack index for each artifact based on the preset weights for each artifact and the calculated similarity for each artifact.
[0016] The step of calculating the artifact-specific similarity may further include a step of extracting, in the computing device, an artifact for a specific attacker from among previously stored artifacts for each attacker; and a step of calculating, in the computing device, the artifact-specific similarity for the specific attacker by comparing the extracted artifact for the specific attacker with the selected artifact.
[0017] The step of calculating the attack index for each evaluation metric may further include a step of calculating the attack index for each evaluation metric by adding up the artifact attack indices included in each evaluation metric according to the classified evaluation metric in the computing device.
[0018] According to another exemplary embodiment of the present invention, a cyber attack camouflage tactic judgment device is provided, including: an information collection unit that collects cyber intrusion information from an external server; an artifact selection unit that selects artifacts from the collected cyber intrusion information according to preset criteria; an evaluation index classification unit that classifies the selected artifacts into evaluation indices according to attributes; and a camouflage tactic index calculation unit that calculates a camouflage tactic index based on the classified evaluation indices.
[0019]
[0020] According to embodiments of the present invention, by determining the camouflage tactics of a cyber attack based on an artifact that reflects the perspective of a hacker, the attacker, as well as the perspective of a security analyst, the defender of a cyber attack, the camouflage tactics of a cyber attack can be determined more systematically and objectively, and a more effective response to the attack can be made.
[0021] In addition, according to embodiments of the present invention, by using pre-stored cyber-invasion information for each hacker and collected cyber-invasion information, the cyber-invasion traces can be used to determine the camouflage tactics of the hacker who performed the cyber-attack, thereby enabling more systematic and objective judgment of the camouflage tactics of the cyber-attack and more effective response to the attack.
[0022]
[0023] Figure 1 is a configuration diagram for explaining a cyber attack camouflage tactic judgment device according to one embodiment of the present invention.
[0024] Figure 2 is a flowchart for explaining a method for determining camouflage tactics of a cyber attack according to one embodiment of the present invention.
[0025] Figure 3 is a flowchart for explaining step 340 of a method for determining camouflage tactics of a cyber attack according to one embodiment of the present invention.
[0026] FIG. 4 is a block diagram illustrating a computing environment including a computing device suitable for use in exemplary embodiments.
[0027]
[0028] Hereinafter, specific embodiments of the present invention will be described with reference to the drawings. The following detailed description is provided to facilitate a comprehensive understanding of the methods, devices, and / or systems described herein. However, these are merely examples and the present invention is not limited thereto.
[0029] In describing embodiments of the present invention, if a detailed description of a known technology related to the present invention is judged to unnecessarily obscure the gist of the present invention, the detailed description will be omitted. In addition, the terms described below are terms defined in consideration of their functions in the present invention, and this may vary depending on the intention or custom of the user or operator. Therefore, the definitions should be made based on the contents throughout this specification. The terminology used in the detailed description is only for the purpose of describing embodiments of the present invention and should not be limited in any way. Unless clearly used otherwise, the singular form includes the plural form. In this description, expressions such as "comprises" or "having" are intended to indicate certain features, numbers, steps, operations, elements, parts or combinations thereof, and should not be construed to exclude the presence or possibility of one or more other features, numbers, steps, operations, elements, parts or combinations thereof other than those described.
[0030] In the following description, the terms "transmission," "communication," "sending," "receiving," and other similar terms for signals or information include not only the direct transmission of signals or information from one component to another, but also transmission via another component. In particular, "transmitting" or "sending" a signal or information to one component indicates the final destination of the signal or information, and does not mean the direct destination. The same applies to "receiving" a signal or information. In addition, in this specification, the "relationship" of two or more pieces of data or information means that when one piece of data (or information) is acquired, at least a portion of the other piece of data (or information) can be acquired based on it.
[0031]
[0032] FIG. 1 is a configuration diagram for explaining a cyber attack camouflage tactic judgment device (100) according to one embodiment of the present invention.
[0033] Referring to FIG. 1, a cyber attack camouflage tactic judgment device (100) according to one embodiment of the present invention may include an information collection unit (110), an artifact selection unit (120), an evaluation index classification unit (130), a camouflage tactic index calculation unit (140), and a camouflage tactic judgment unit (150).
[0034] Meanwhile, the cyberattack camouflage tactic judgment device (100) collects various breach incident information related to cyberattacks and analyzes the collected breach incident information to determine the camouflage tactics of the hacker who carried out the cyberattack. Here, a cyberattack refers to any act that can cause social or economic damage by attacking networks or computer systems using information and communication technologies such as hacking and computer viruses. Furthermore, breach incident information related to a cyberattack includes all types of breach incident information directly or indirectly related to the cyberattack. Among the breach incident information, digital traces or evidence left by the hacker during the cyberattack process are called artifacts. These artifacts can be used to identify the hacker's actions, attack methods, intrusion paths, and traces of malicious activity through cyberattack investigations and post-incident analysis. Furthermore, camouflage tactics refer to the hacker's methods of deceiving or misleading others by revealing their origin, identity, attack techniques, and other characteristics.
[0035] That is, the cyber attack camouflage tactic judgment device (100) according to one embodiment of the present invention uses pre-stored cyber attack information for each hacker and collected cyber attack information to determine the possibility that the cyber attack trace is a camouflage tactic of the hacker who performed the cyber attack.
[0036]
[0037] The information collection unit (110) can collect cyber breach information. Specifically, the information collection unit (110) can collect cyber breach information regarding cyber attacks from multiple information sharing channels. For example, the multiple information sharing channels can be a cyber black box, C-share (a breach incident information sharing system operated by the Korea Internet & Security Agency), DNSBL (Domain Name Server based Black List), distribution / malicious code sharing channels (e.g., virusshare.com, etc.). Here, the cyber breach information can include indicators of compromise (IOC), indicators of attack (IOA), and indicators of behavior (IOB). Indicators of compromise refer to indicators that can identify hackers when an incident occurs, indicators of attack refer to preemptive measures taken before a successful attack (e.g., code execution, command and control, persistent concealment, diffusion, etc.), and behavioral indicators refer to specific behavioral patterns observed in a system or network. At this time, the information collection unit (110) can collect cyber infringement information by major attacker (hacker) and classify cyber infringement information by attacker.
[0038]
[0039] The artifact selection unit (120) can select artifacts from cyber breach information. Specifically, the artifact selection unit (120) can select artifacts from cyber breach information based on preset criteria. For example, the artifact selection unit (120) can select 33 artifacts by categorizing cyber breach information into infrastructure-related fundamental factors and attack factors related to attack techniques.
[0040] Artifacts include internet protocol (IP), domain, port, uniform resource locator (URL), command and control server (C2), server hosting records, HTTP referrer, log, email address, cryptocurrency address, hardware information, encryption / decryption method, obfuscation, metadata, digital certificate, packing, development information, time stamp, region, language, hash value, file type, behavior pattern, library, zero-day, N-day, remote code execution (RCE), privilege escalation, shellcode, decoy document, This may include phishing and pharming, social media accounts, and attack targets. These artifacts can be organized based on the Analytic Hierarchy Process (AHP), selecting artifacts useful for analyzing cyber breach information and disguise tactics, taking into account the perspectives of both the attacker (hacker) and the defender (security analyst).Meanwhile, the present invention has been described as selecting 33 artifacts from among cyber breach information, but it is not limited thereto, and more or less artifacts than 33 may be selected depending on the perspective of the hacker and security analyst.
[0041]
[0042] The evaluation indicator classification unit (130) can classify artifacts into evaluation indicators according to their properties. Specifically, the evaluation indicator classification unit (130) can classify 33 artifacts selected by the artifact selection unit (120) into evaluation indicators according to their properties. For example, the evaluation indicators classified according to the properties of the artifacts can include Network, Server, Host based on infrastructure-related fundamental factors, and Anti-debugging, Development Environment, Malware, Vulnerability, and Social Engineering based on attack factors related to attack techniques.
[0043] The contents of the main evaluation indicators are summarized below.
[0044] - Network is a basic element of cybersecurity incident analysis and may include IP, domain, and port.
[0045] An IP address can refer to a unique identifier assigned to a device connected to the Internet. Hackers attempt to disguise IP addresses by utilizing VPNs, proxies, or hacking techniques like spoofing. IP addresses can be useful for spoofing tactics, as their impermanence and high volatility make them difficult to track. In cybersecurity incidents, repeated detections of the same computer or digital device using the same infrastructure can serve as evidence.
[0046] A domain can refer to a system that names a device, service, or related entity connected to the Internet. Hackers often control domains through hosting provider accounts. These domains can serve as evidence in cybersecurity investigations.
[0047] A port can represent a communication channel. Ports can be changed as needed, and hackers can use them to disguise malicious traffic as legitimate TLS traffic.
[0048] - Server is an important element in attack propagation and may include uniform resource locator (URL), Command & Control server (C2 server), server hosting records, HTTP referrer, and log.
[0049] A URL can be an address for exchanging data between multiple computers on the Internet, and it can also indicate the location of a web page. URLs can be exploited for spoofing tactics using various techniques. For example, URL spoofing can be used to disguise or disguise the address displayed on the Internet, making it appear as if it's a different site.
[0050] C2 servers can be a key component of spoofing tactics, used to control victim systems and issue commands via malware. For example, even if a hacker's C2 server, used for malware and system hacking, is blocked and inaccessible, the server can still be managed by logging in with an account maintained by the hosting provider. Consequently, hackers can legitimately utilize the C2 server managed by the hosting provider or use hacking techniques to spoof it.
[0051] Server hosting records can refer to hosting records provided by a hosting provider. Hackers often rent C2 servers from hosting providers to communicate with malware. They can track these records by verifying server hosting records from the hosting provider through specific procedures or by examining information provided by web engines.
[0052] The HTTP referrer can indicate the source of the current webpage. By transmitting this information to the server, administrators can identify the source of user traffic. However, referrer data can be spoofed through firewalls and proxy systems, or disguised by manipulating the HTTP Uniform Resource Identifier (URI) header field.
[0053] Logs can refer to files that record the operational activities of an operating system or software. Logs are commonly used to analyze attack methods during cybersecurity incident investigations. Hackers can use tools built into the operating system to operate covertly, deleting log files or making attack detection difficult.
[0054] - Host is an element for tracking information related to hacker and victim hosts, and may include email address, cryptocurrency address, and hardware information.
[0055] Email addresses can be spoofed to lure victims or conceal the hacker's identity. Email addresses are vulnerable to vulnerabilities in the SMTP protocol, which handles email transmission, allowing email headers to be spoofed to appear to come from a different source. This allows hackers to conceal their identities and utilize spoofing tactics.
[0056] Cryptocurrency can refer to computer code that facilitates transactions without disclosing account holder information. Cryptocurrencies operate through blockchain technology, allowing for money laundering outside of the traditional banking system.
[0057] Hardware information may include data about the system's hardware components, such as the hard drive, network interface card, MAC address, SIM card, and IMEI number. Hardware information can be used to identify the system.
[0058] - Anti-debugging is a factor that complicates intrusion analysis and can include encryption / decryption methods, obfuscation, metadata, digital certificates, and packing.
[0059] Encryption / decryption methods allow hackers to use encryption technology to enhance communication security or hide communication data and attack code from malware. Ransomware, in particular, often uses unique encryption methods to encrypt target files, which can reveal the characteristics of a hacker.
[0060] Obfuscation can refer to techniques hackers use to make malicious or attack code difficult to analyze. Different hackers use different obfuscation methods, which can reveal their unique characteristics.
[0061] Metadata can refer to information used for quick retrieval according to specific rules, such as author information, permission conditions, usage conditions, and usage history.
[0062] A digital certificate can be a certificate issued by a certification authority. Signing an executable file with a digital certificate can establish its security. However, these digital certificates can be bypassed by antivirus systems due to human error or hacking.
[0063] Packing can refer to a technique for compressing or encrypting executable files, which hackers can use to hide their code. Hackers can use packaging techniques to evade detection and can also reveal their unique characteristics.
[0064] - The Development Environment is an element that can be included when developing attack techniques, and can include development information, time stamp, region, and language.
[0065] Development information can include strings and debug paths. The debug path can contain a name preferred by the author.
[0066] Timestamps can be included in the compilation of malware. These timestamps can indicate the working hours and time zone in which the malware was developed.
[0067] Locations can reveal information about a hacker's location. Hackers often use anonymizing services to hide their activities, but this can lead to the attacker's location being leaked accidentally.
[0068] Language can refer to the font embedded in the malware. If the language is in a specific country's language, it can indicate the hacker's identity.
[0069] - Malware is an element related to the characteristics of malicious code, and may include hash value, file type, and behavior pattern.
[0070] Hash values are used to identify malware and can be calculated using a one-way algorithm to determine the data contained in a file.
[0071] File types can identify traces of malware by associating it with specific file formats.
[0072] Behavioral patterns can refer to unique patterns exhibited by malware. Malware delivered by the same hacker can exhibit similarities. Furthermore, within the same malware family, similarities in code developers or source code can be observed. These characteristics can be utilized in malware analysis.
[0073] Libraries can be used intermittently during software development. Frequently used libraries can reveal hacker traits.
[0074] - Vulnerability is an element related to actual attack methods, and may include Zero-day, N-day, Remote Code Execution (RCE), Privilege Escalation, and Shellcode.
[0075] Zero-days can represent vulnerabilities that are used in targeted attacks.
[0076] N-day may indicate an N-day vulnerability that has been patched but is still being exploited.
[0077] Remote code execution can represent a type of cyberattack in which a hacker remotely installs malicious code on a system or network.
[0078] Privilege escalation can refer to a type of cyberattack where a hacker attempts to gain elevated privileges when initially lacking system access.
[0079] Shellcode can refer to attack code used by hackers to exploit vulnerabilities and gain complete control of a system. Shellcode is typically written in hexadecimal opcode format, but hackers often create sophisticated shellcode to make detection difficult. This can be indicative of a hacker's unique characteristics.
[0080] - Social Engineering is an element related to the attack target, and can include decoy documents, phishing & pharming, SNS accounts, and attack targets.
[0081] A decoy document may be used by hackers to lure victims into installing malware. These documents can provide insight into whether a hacker is attacking, the extent of the information leak, and the hacker's intentions.
[0082] Phishing can refer to methods of fraudulently obtaining personal information, such as passwords and credit card information, using email, URLs, websites, online games, and social media. Phishing can also refer to methods of directing users to fake websites. These methods can be indicative of hacker tactics.
[0083] Social media accounts can be linked to email accounts, which can help identify hackers. For example, if an email account identified in a previous hack was used to create a social media account and then used consistently, it could be used for analysis.
[0084] If the target of the attack has a political or cultural conflict with the hacker or has political ties to the hacker, it can help identify the hacker.
[0085]
[0086] The camouflage tactic index calculation unit (140) can calculate the camouflage tactic index based on the evaluation index.
[0087] In an exemplary embodiment, the camouflage tactic index calculation unit (140) can assign preset weights to selected artifacts to set weights for each artifact. Specifically, the camouflage tactic index calculation unit (140) can assign preset weights to 33 selected artifacts based on the Analytic Hierarchy Process (AHP) and the perspectives of a hacker as an attacker and a security analyst as a defender, based on the priority and importance of the artifacts. At this time, the weights for each artifact can be set by assigning preset weights to each artifact so that the sum of the preset weights becomes 1. For example, the weights assigned to each artifact are as shown in the table below.
[0088] PriorityArtifactWeight1Zero-day0.2970288882Elevationofprivilege0.0497012413Shellcode0.0486731154Remotecodeexecution0.0458171915Attacktarget0.0438821666Behaviorpattern0.0432746657Developmentinformation0.0427812368Digitalcertificate0.0394649969N-day0.03676810110Library0.02719693211Cryptocurrencyaddress0.02466159312Language0.02402626113Serverhostinglog0.02389794714Log0.02059915315Bait Document 0.02052148816 Timestamp 0.01899781417 IP 0.01883268218 Hash value 0.01846505719 C2 Server 0.01776807520 Region 0.01705702721 Phishing & Pharming 0.01313780222 Social Media Account 0.01285496523 Encryption / Decryption Method 0.01280878924 File Format 0.01261619225 Obfuscation 0.01219638226 Hardware Info 0.01064716627 Domain 0.00839805128 URL 0.00768037829 Metadata 0.00728010730 HTTP Referrer 0.00701464631 Packing 0.00627452532 Email Address 0.00574119833 Port 0.003934171 Total 1
[0089] In addition, the camouflage tactics index calculation unit (140) can compare previously stored artifacts with selected artifacts to calculate the similarity for each artifact. Specifically, the camouflage tactics index calculation unit (140) can extract artifacts for a specific hacker from among previously stored artifacts for each hacker, compare the artifacts for the specific hacker with the selected artifacts, and calculate the similarity for each artifact for the specific hacker. In this case, the specific hacker may be a hacker who is expected to have performed a cyberattack. In other words, by calculating the artifact-by-artifact similarity with the specific hacker, the possibility of the specific hacker's camouflage tactics can be determined. The camouflage tactics index calculation unit (140) can calculate the similarity for each artifact according to a preset standard. For example, the preset standard may determine that the similarity is high when the similarity is 70% or higher, and calculate a similarity of 3. Additionally, if the similarity is 40% or greater, the similarity is considered medium, and a similarity score of 2 can be calculated. Furthermore, if the similarity is 10% or greater, the similarity is considered low, and a similarity score of 1 can be calculated. Furthermore, if the similarity is less than 10% or the corresponding artifact has not been collected, the similarity is considered non-existent, and a similarity score of 0 can be calculated.
[0090]
[0091] Additionally, the camouflage tactic index calculation unit (140) can calculate an attack index for each artifact based on the artifact-specific weight and artifact-specific similarity. Alternatively, the camouflage tactic index calculation unit (140) can calculate an attack index for each artifact by multiplying the set artifact-specific weight and the calculated artifact-specific similarity. For example, in the case of an IP, if the set weight is 0.018832682 and the similarity is calculated as 3, the IP's attack index can be 0.056498046.
[0092]
[0093] Additionally, the camouflage tactic index calculation unit (140) can calculate an attack index for each evaluation metric based on the attack index for each artifact. Specifically, the camouflage tactic index calculation unit (140) can calculate an attack index for each evaluation metric by adding up the artifact attack indices included in each evaluation metric according to the pre-classified evaluation metric. For example, if the evaluation metric is a network, the attack index of the network can be calculated by adding up the attack indices of all artifacts (IP, domain, port) included in the network.
[0094]
[0095] Additionally, the camouflage tactical index calculation unit (140) can calculate a total attack index by adding up all attack indices for each evaluation indicator. At this time, the calculated total attack index can be expressed as a percentage.
[0096]
[0097] In addition, the camouflage tactic index calculation unit (140) can set weights according to the correlation between evaluation indicators based on the similarity of each artifact. For example, the camouflage tactic index calculation unit (140) can extract an artifact with an artifact similarity of 3, and assign a weight of 1 time when the artifact is extracted, assign a weight of 2 times when the extracted artifact is included in two evaluation indicators, and assign a weight of 3 times when the extracted artifact is included in three or more evaluation indicators. In addition, the camouflage tactic index calculation unit (140) can extract an artifact with an artifact similarity of 3, and assign a weight of 3 times when the extracted artifact is included in a preset evaluation indicator. Here, the preset evaluation indicators can be malware (hash value, file type, behavior pattern, library) and infrastructure (network (IP, domain, port) and server (URL, C2 server, server hosting record)). At this time, the weighting based on the correlation between evaluation indicators can be set to the highest value among the assigned weights. Furthermore, the weighting based on the correlation between evaluation indicators can be set to one of the following values: 1x, 2x, or 3x. This is because it's difficult for hackers to maintain consistency and synchronization between various artifacts to achieve camouflage tactics. Therefore, by assigning weighting based on the correlation between multiple artifacts, the likelihood of a genuine attack can be increased.
[0098]
[0099] Additionally, the camouflage tactic index calculation unit (140) can calculate an actual attack index based on weights based on the correlation between the total attack index and the evaluation indicators. Alternatively, the camouflage tactic index calculation unit (140) can calculate an actual attack index by multiplying the total attack index by weights based on the correlation between the evaluation indicators. Here, the actual attack index can refer to a value expressing the degree of likelihood that a cyberattack intrusion trace is an actual attack.
[0100]
[0101] In addition, the camouflage tactic index calculation unit (140) can calculate the camouflage tactic index based on the actual attack index. For example, the camouflage tactic index calculation unit (140) can calculate the camouflage tactic index by subtracting the actual attack index from 100. Here, the camouflage tactic index can mean a value expressing the degree of possibility that the intrusion trace of a cyberattack is a camouflage tactic. In the present invention, the evaluation of a cyberattack can calculate the camouflage tactic index (camouflage tactic index = 100 - actual attack index) under the assumption that it is an actual attack or a camouflage tactic attack.
[0102]
[0103] The camouflage tactic judgment unit (150) can determine camouflage tactics based on the camouflage tactic index. Specifically, the camouflage tactic judgment unit (150) can determine the likelihood of collected cyber intrusion information being a camouflage tactic based on the camouflage tactic index. For example, if the camouflage tactic index is 0, the camouflage tactic judgment unit (150) can determine that there is no likelihood of camouflage tactic. In addition, if the camouflage tactic index is 1 to 40, the camouflage tactic judgment unit (150) can determine that there is a low likelihood of camouflage tactic. In addition, if the camouflage tactic index is 41 to 70, the camouflage tactic judgment unit (150) can determine that there is a medium likelihood of camouflage tactic. In addition, if the camouflage tactic index is 71 to 90, the camouflage tactic judgment unit (150) can determine that there is a high likelihood of camouflage tactic. In addition, if the camouflage tactic index is 91 to 100, the camouflage tactic judgment unit (150) can determine that there is a very high likelihood of camouflage tactic.
[0104] Additionally, the stomach tactic judgment unit (150) can provide the judgment result to the user.
[0105] For example, assuming that behavioral patterns and IP addresses similar to a specific hacker are collected from cyber breach information, the weight assigned to the behavioral pattern is 0.043274665, and the weight assigned to the IP address is 0.018832682. Since artifacts similar to a specific hacker have been collected, comparing the previously stored artifacts related to the specific hacker with the selected artifacts can yield a similarity score of 3 for both the behavioral pattern and IP address. Furthermore, since the similarity score of the behavioral pattern and IP address is 3 and is included in the pre-set evaluation indicators (malware and network), the weight based on the correlation between the evaluation indicators can be weighted 3 times. Based on this, if we calculate the actual attack index, it would be (0.043274665 * 3 + 0.018832682 * 3) * 100 * 3 = 55.90, and the camouflage tactic index could be 100 - 55.90 = 44.10. If the camouflage tactic index is 41 to 70, the probability that a specific hacker is using camouflage tactics can be determined to be medium.
[0106] For example, assuming that artifacts (behavioral patterns, C2 servers, N-days, language, attack targets, digital certificates) similar to specific hackers A and B are collected from cyber breach information, it is possible to determine the possibility that these are camouflage tactics for specific hackers A and B, as shown in Table 2 below.
[0107] Artifact Weight Similarity AB Behavior Pattern 0.04327466533 C2 Server 0.01776807530 N-day 0.03676810100 Language 0.02402626103 Target 0.04388216630 Digital Certificate 0.03946499630 Weighting by Relationship 32 Actual Attack Index 10040.3805556 Camouflage Tactics Index 059.619444
[0108] As shown in Table 2 above, when comparing a specific hacker A that has been previously stored with the selected artifacts, the similarity of the behavioral pattern, C2 server, attack target, and digital certificate can each be calculated as 3. In addition, when comparing a specific hacker B that has been previously stored with the selected artifacts, the similarity of the behavioral pattern and language can each be calculated as 3. For a specific hacker A, the similarity of the behavioral pattern and the C2 server is 3, and since it is included in the preset evaluation indices (malware and server), the weight according to the correlation between the evaluation indices can be given a weight of 3. For a specific hacker B, the similarity of the behavioral pattern and language is 3, and since it is included in two evaluation indices, the weight according to the correlation between the evaluation indices can be given a weight of 2. Based on this, if we calculate the actual attack index for a specific hacker A, (0.043274665 * 3 + 0.017768075 * 3 + 0.043882166 * 3 + 0.039464996 * 3) * 100 * 3 = 129.9509118, so the actual attack index is 100, and the camouflage tactic index is 0. Also, if we calculate the actual attack index for a specific hacker B, (0.043274665 * 3 + 0.024026261 * 3) * 100 * 2 = 40.3805556, so the actual attack index is 40.38, and the camouflage tactic index is 100 - 40.38 = 59.62. Therefore, the collected cyber-intrusion information can be judged to have a very high probability of being a real attack by a specific hacker A, and a medium probability of being a fake attack by a specific hacker B.
[0109] That is, the cyber attack camouflage tactic judgment device (100) according to one embodiment of the present invention can determine the possibility that a cyber attack trace is a camouflage tactic of a hacker who performed a cyber attack by using pre-stored cyber attack information for each hacker and collected cyber attack information.
[0110]
[0111] FIG. 2 is a flowchart illustrating a method for determining camouflage tactics for cyberattacks according to one embodiment of the present invention. The method illustrated in FIG. 2 may be performed, for example, by the aforementioned cyberattack camouflage tactics determination device. While the illustrated flowchart divides the method into multiple steps, at least some of the steps may be performed in a different order, combined with other steps and performed together, omitted, divided into substeps, or performed with one or more additional steps not illustrated.
[0112] In step 210, the computing device (12) may collect cyberattack information. Specifically, the computing device (12) may collect cyberattack information from multiple information sharing channels.
[0113] In step 220, the computing device (12) can select artifacts from the cyber breach information. Specifically, the computing device (12) can select artifacts from the cyber breach information based on preset criteria. For example, the artifact selection unit can select 33 artifacts by categorizing the cyber breach information into infrastructure-related fundamental factors and attack factors related to attack techniques.
[0114] In step 230, the computing device (12) can be classified into evaluation indices based on the attributes of the artifacts. Specifically, the computing device (12) can be classified into evaluation indices based on the attributes of 33 artifacts selected by the artifact selection unit. For example, the evaluation indices classified based on the attributes of the artifacts can include Network, Server, and Host based on infrastructure-related fundamental factors, and Anti-debugging, Development Environment, Malware, Vulnerability, and Social Engineering based on attack factors related to attack techniques.
[0115] In step 240, the computing device (12) can calculate a camouflage tactic index based on the evaluation indicators. Step 240 will be described in more detail with reference to FIG. 3 below.
[0116] In step 250, the computing device (12) can determine a camouflage tactic based on the camouflage tactic index. Specifically, the computing device (12) can determine the likelihood that the collected cyber-invasion information is a camouflage tactic based on the camouflage tactic index.
[0117]
[0118] FIG. 3 is a flowchart illustrating step 240 of a method for determining camouflage tactics of a cyber attack according to one embodiment of the present invention.
[0119] In step 241, the computing device (12) can calculate an attack index for each artifact. At this time, the computing device (12) can calculate the weight for each artifact by assigning a preset weight to the selected artifact. In addition, the computing device (12) can calculate the similarity for each artifact by comparing the previously stored artifact with the selected artifact. In addition, the computing device (12) can calculate the attack index for each artifact based on the artifact-specific weight and artifact-specific similarity. That is, the computing device (12) can calculate the attack index for each evaluation index by adding up the artifact attack indices included in each evaluation index according to the pre-classified evaluation index.
[0120] In step 242, the computing device (12) can calculate an attack index for each evaluation metric based on the attack index for each artifact. At this time, the calculated total attack index can be expressed as a percentage.
[0121] In step 243, the computing device (12) can calculate a total attack index by adding up all the attack indices for each calculated evaluation index.
[0122] In step 244, the computing device (12) can calculate an actual attack index based on weights according to the correlation between the total attack index and the evaluation indicators. At this time, the computing device (12) can set weights according to the correlation between the evaluation indicators based on the similarity of each artifact. For example, the computing device (12) can extract an artifact with an artifact similarity of 3, and assign a weight of 1 time to the extracted artifact, assign a weight of 2 times to the extracted artifact if the extracted artifact is included in two evaluation indicators, and assign a weight of 3 times to the extracted artifact if the extracted artifact is included in three or more evaluation indicators. In addition, the computing device (12) can extract an artifact with an artifact similarity of 3, and assign a weight of 3 times to the extracted artifact if the extracted artifact is included in a preset evaluation indicator. Here, the preset evaluation indicators may be malware (hash value, file type, behavior pattern, library) and infrastructure (network (IP, domain, port) and server (URL, C2 server, server hosting record)). At this time, the weight according to the correlation between the evaluation indicators may be set to the highest value among the assigned weights. In addition, the weight according to the correlation between the evaluation indicators may be set to one of 1x, 2x, and 3x. In addition, the computing device (12) may calculate the actual attack index by multiplying the total attack index and the weight according to the correlation between the evaluation indicators. Here, the actual attack index may mean a value expressing the degree of possibility that the cyberattack intrusion trace is an actual attack.
[0123] In step 245, the computing device (12) may calculate a camouflage tactic index based on the actual attack index. For example, the computing device (12) may calculate a camouflage tactic index by subtracting the actual attack index from 100. Here, the camouflage tactic index may refer to a value expressing the degree of likelihood that the cyberattack intrusion trace is a camouflage tactic. In the present invention, the evaluation of a cyberattack may calculate the camouflage tactic index (camouflage tactic index = 100 - actual attack index) under the assumption that the cyberattack is an actual attack or a camouflage tactic attack.
[0124] Therefore, a device for judging camouflage tactics of a cyber attack according to one embodiment of the present invention can use pre-stored cyber intrusion information for each hacker and collected cyber intrusion information to determine the possibility that a cyber intrusion trace is a camouflage tactic of a hacker who performed a cyber attack.
[0125]
[0126] FIG. 4 is a block diagram illustrating a computing environment (10) including a computing device suitable for use in exemplary embodiments. In the illustrated embodiment, each component may have different functions and capabilities other than those described below, and may include additional components other than those described below.
[0127] The illustrated computing environment (10) includes a computing device (12). In one embodiment, the computing device (12) may be a cyber-attack camouflage tactic judgment device (100).
[0128] A computing device (12) includes at least one processor (14), a computer-readable storage medium (16), and a communication bus (18). The processor (14) may cause the computing device (12) to operate according to the exemplary embodiments mentioned above. For example, the processor (14) may execute one or more programs stored in the computer-readable storage medium (16). The one or more programs may include one or more computer-executable instructions, which, when executed by the processor (14), may be configured to cause the computing device (12) to perform operations according to the exemplary embodiments.
[0129] A computer-readable storage medium (16) is configured to store computer-executable instructions or program code, program data, and / or other suitable forms of information. A program (20) stored in the computer-readable storage medium (16) includes a set of instructions executable by the processor (14). In one embodiment, the computer-readable storage medium (16) may be a memory (volatile memory such as random access memory, non-volatile memory, or a suitable combination thereof), one or more magnetic disk storage devices, optical disk storage devices, flash memory devices, any other form of storage medium that is accessible by the computing device (12) and capable of storing desired information, or a suitable combination thereof.
[0130] A communication bus (18) interconnects various other components of the computing device (12), including the processor (14) and computer-readable storage media (16).
[0131] The computing device (12) may also include one or more input / output interfaces (22) that provide interfaces for one or more input / output devices (24) and one or more network communication interfaces (26). The input / output interfaces (22) and the network communication interfaces (26) are connected to the communication bus (18). The input / output devices (24) may be connected to other components of the computing device (12) via the input / output interfaces (22). Exemplary input / output devices (24) may include input devices such as pointing devices (such as a mouse or a trackpad), a keyboard, a touch input device (such as a touchpad or a touchscreen), a voice or sound input device, various types of sensor devices and / or photographing devices, and / or output devices such as display devices, printers, speakers and / or network cards. The exemplary input / output devices (24) may be included within the computing device (12) as a component constituting the computing device (12), or may be connected to the computing device (12) as a separate device distinct from the computing device (12).
[0132]
[0133] While representative embodiments of the present invention have been described in detail above, those skilled in the art will appreciate that various modifications to the above-described embodiments are possible without departing from the scope of the present invention. Therefore, the scope of the present invention should not be limited to the described embodiments, but should be defined not only by the claims set forth below but also by equivalents thereof.
Claims
1. One or more processors, and A method for determining camouflage tactics of a cyber attack performed on a computing device having a memory storing one or more programs executed by one or more processors, In the computing device, a step of collecting cyber attack information from an external server; In the computing device, a step of selecting artifacts from the collected cyber attack information according to preset criteria; In the computing device, a step of classifying the selected artifacts into evaluation indicators according to their properties; and A method for determining camouflage tactics of a cyber attack, comprising the step of calculating a camouflage tactics index based on the classified evaluation indicators in the computing device.
2. In claim 1, The method for judging the camouflage tactics of the above cyber attack is as follows: In the computing device, a step of determining a camouflage tactic for the collected cyber attack information based on the calculated camouflage tactic index; and A method for judging camouflage tactics of a cyber attack, further comprising a step of providing the judgment result to a user.
3. In claim 1, The steps for collecting the above cyber breach information are: A method for determining a camouflage tactic of a cyber attack, further comprising a step of classifying the collected cyber breach information by attacker and storing the cyber breach information by attacker in the computing device.
4. In claim 1, The above artifacts are, IP (internet protocol), Domain, Port, Uniform Resource Locator (URL), Command & Control server (C2), Server hosting records, HTTP referrer, Log, Email address, Cryptocurrency address, Hardware Information, Encryption / decryption method, Obfuscation, Meta Data, Digital certificate, Packing, Development information, Time stamp, Region, Language, Hash value, File type, Behavior pattern, Library, Zero-day, N-day, Remote Code Execution (RCE), Privilege Escalation, Shellcode, Decoy document, A method for judging the camouflage tactics of cyber attacks, which include at least one of Phishing & Pharming, SNS account, and Attack target.
5. In claim 1, The above evaluation criteria are: A method for judging the camouflage tactics of cyber attacks based on fundamental factors related to infrastructure, such as network, server, host, and attack technique-related attack factors, and at least one of anti-debugging, development environment, malware, vulnerability, and social engineering.
6. In claim 1, The steps for calculating the above stomach tactical index are: In the computing device, a step of calculating an attack index for each of the selected artifacts; In the computing device, a step of calculating an attack index for each evaluation indicator based on the calculated attack index for each artifact; In the computing device, a step of calculating a total attack index by adding up all the calculated attack indices for each evaluation indicator; In the computing device, a step of calculating an actual attack index based on a weight according to the correlation between the calculated total attack index and the evaluation index; and A method for determining camouflage tactics of a cyber attack, further comprising the step of calculating the camouflage tactics index based on the calculated actual attack index in the computing device.
7. In claim 6, The step of calculating the attack index for each selected artifact is as follows: In the computing device, a step of setting weights for each artifact by assigning preset weights to each of the selected artifacts; In the computing device, a step of comparing previously stored artifacts and the selected artifacts to calculate similarity for each artifact; and A method for judging camouflage tactics of a cyber attack, further comprising the step of calculating an attack index for each artifact based on the set artifact-specific weights and the calculated artifact-specific similarity in the computing device.
8. In claim 7, The step of calculating the similarity for each artifact is as follows: In the computing device, a step of extracting an artifact for a specific attacker from among previously stored attacker-specific artifacts; and A method for determining camouflage tactics of a cyber attack, further comprising the step of comparing the extracted artifacts for the specific attacker with the selected artifacts in the computing device to calculate a similarity for each artifact for the specific attacker.
9. In claim 6, The steps for calculating the attack index for each of the above evaluation indicators are: A method for judging camouflage tactics of a cyber attack, further comprising the step of calculating an attack index for each evaluation index by adding up the artifact attack indices included in each evaluation index according to the classified evaluation index in the computing device.
10. Information collection unit that collects cyber-invasion information from external servers; An artifact selection unit that selects artifacts from the collected cyber breach information based on preset criteria; An evaluation index classification unit that classifies the selected artifacts into evaluation indexes according to their properties; and A cyber-attack camouflage tactic judgment device, comprising a camouflage tactic index calculation unit that calculates a camouflage tactic index based on the above-mentioned classified evaluation indicators.
11. In claim 10, The above cyber attack camouflage tactic judgment device is, A cyber attack camouflage tactic judgment device further comprising a camouflage tactic judgment unit that judges camouflage tactics for the collected cyber intrusion information based on the camouflage tactic index produced above and provides the judgment result to the user.
12. In claim 10, The above information collection department, A cyber attack camouflage tactic judgment device that classifies the collected cyber attack information by attacker and stores the cyber attack information by attacker.
13. In claim 10, The above artifacts are, IP (internet protocol), Domain, Port, Uniform Resource Locator (URL), Command & Control server (C2), Server hosting records, HTTP referrer, Log, Email address, Cryptocurrency address, Hardware Information, Encryption / decryption method, Obfuscation, Meta Data, Digital certificate, Packing, Development information, Time stamp, Region, Language, Hash value, File type, Behavior pattern, Library, Zero-day, N-day, Remote Code Execution (RCE), Privilege Escalation, Shellcode, Decoy document, A device for judging the camouflage tactics of cyber attacks, which are at least one of Phishing & Pharming, SNS account, and Attack target.
14. In claim 10, The above evaluation criteria are: A cyber attack camouflage tactic judgment device based on network, server, host and attack technique-related attack factors based on fundamental factors related to infrastructure, and one or more of anti-debugging, development environment, malware, vulnerability and social engineering.
15. In claim 10, The above-mentioned stomach tactical index calculation section is, A cyber attack camouflage tactic judgment device that calculates an attack index for each of the selected artifacts, calculates an attack index for each evaluation metric based on the calculated attack index for each artifact, calculates a total attack index by adding up all of the calculated attack indices for each evaluation metric, calculates an actual attack index based on a weight according to a correlation between the calculated total attack index and the evaluation metric, and calculates the camouflage tactic index based on the calculated actual attack index.
16. In claim 15, The above-mentioned stomach tactical index calculation section is, A cyber attack camouflage tactic judgment device that sets a weight for each artifact by assigning a preset weight to each of the selected artifacts, calculates a similarity for each artifact by comparing previously stored artifacts and the selected artifacts, and calculates an attack index for each artifact based on the preset artifact weights and the calculated artifact similarities.
17. In claim 16, The above-mentioned stomach tactical index calculation section is, A cyber attack camouflage tactic judgment device that extracts an artifact for a specific attacker from among previously stored artifacts for each attacker, compares the extracted artifact for the specific attacker with the selected artifact, and calculates a similarity for each artifact for the specific attacker.
18. In claim 15, The above-mentioned stomach tactical index calculation section is, A cyber attack camouflage tactic judgment device that calculates an attack index for each evaluation index by adding up the artifact attack indices included in each evaluation index according to the above-mentioned classified evaluation index.
Citation Information
Patent Citations
Method and Apparatus for Calculating Risk of Cyber Attack
KR101781450B1
Automatic generation method of Indicators of Compromise and its application for digital forensic investigation of cyber attack and System thereof
KR1020180013270A
Internet Security Cyber Threat Reporting System and Method
US20140259170A1
Inference device, inference method, and storage medium
WO2023012849A1