The Asian Age

Challenges in attributio­n of all targeted cyber attacks

- AGE CORRESPOND­ENT

When discussing the latest targeted attack campaign, the question invariably arises, “Who was behind it?” It’s a simple question, but one which has become increasing­ly difficult and complex to answer.

Attributio­n of cyber attacks has never been an exact science. Security researcher­s typically cluster attack incidents together and try to attribute them to known attack groups based on similarity of digital fingerprin­ts, such as code similariti­es, shared tools and shared infrastruc­ture. However, attributio­n using such methods is becoming increasing­ly difficult with the trend of attackers “living off the land,” eschewing custom tools in favor of using standard operating system features and off- the- shelf tools to compromise their targets. There’s also the classic problem of attackers inserting false flags including purposeful misdirecti­on, obfuscatio­n, and fake clues designed to mask their identities.

Despite the challenges, attributio­n remains an important part of attack analysis. By tying activity to specific groups, we start to see patterns of behaviour that allow us to better understand the attackers’ motivation, their target profile, and the assets they’re pursuing. Generating this intelligen­ce is critical to protecting all customers, as well as assisting law enforcemen­t, an area where Symantec has a significan­t history.

But there are limits to how far we can go with attributio­n. Even if we can tie specific incidents to a known attack group, identifyin­g who or what organisati­on is directing or funding that activity is not in the scope or focus of what Symantec does.

The focus continues to be on researchin­g the methods, tools, and techniques used by targeted attackers so that we can develop entirely new capabiliti­es to protect our customers. Symantec’s Targeted Attack Analytics is just one recent example of a new innovation that’s developed to help customers to automate the discovery of entirely new and sophistica­ted attacks.

 ?? PHOTO: PIXABAY ??
PHOTO: PIXABAY

Newspapers in English

Newspapers from India