期刊文献+

针对APT攻击中恶意USB存储设备的防护方案研究 被引量:7

Research on Protection Scheme for Malicious USB Storage Devices in APT
下载PDF
导出
摘要 文章针对APT攻击中的恶意USB存储设备设计了一套安全防护方案。该方案构造USB存储设备的白名单,只允许白名单中的USB存储设备与计算机系统进行交互,从而防止APT攻击中定制的恶意USB存储设备对主机的非授权访问;将USB存储设备与单位各级员工绑定,在特定主机对特定的USB存储设备写保护,有效阻止了APT攻击者利用社会工程学的方法诱导内部人员对系统中数据进行越权访问;通过监控向USB存储设备复制数据的进程行为,防止隐藏的恶意程序暗中窃取系统中的数据。文章方案可以很好地防止系统中的数据遭到窃取和泄露,具有良好的实用性。文章方案进行了相关的功能测试,测试结果表明该方案可行。 This paper designs a protection scheme for malicious USB storage devices in APT. The protection scheme constructs a white list of USB storage devices, and only allows the USB storage devices in white list to interact with the computer system, in order to prevent customized malicious USB storage devices in APT to get unauthorized access to the host. The scheme makes USB storage devices bind with staff at all levels and write-protects the specific USB storage device on the specific host so as to effectively prevent APT attackers utilizing social engineering to induce insiders' exceeding accesses to system data, and prevents hidden malware stealing data from the system through monitoring the process behavior that writes data to USB storage devices. As a result, the protection scheme can guard against data theft and leakage and has good practicality. This paper describes some functional tests about the protection scheme. The test results show that the scheme is feasible.
出处 《信息网络安全》 2016年第2期7-14,共8页 Netinfo Security
基金 国家高技术研究发展计划(国家863计划)[2015AA016004] 国家自然科学基金[61303213 61373169] 信息保障技术重点实验室开放基金[KJ-14-110 KJ-14-101]
关键词 APT攻击 USB存储设备 白名单 Windows过滤驱动 数据防泄露 advanced persistent threat USB storage device white list Windows filter driver data leakage prevention
  • 相关文献

参考文献18

  • 1CHEN Ping, LIEVEN D, CHtLISTOPHE H. A Study on Advance Persistent Threats[C]//IFIP. Communications and Multimedia Security, September 25-26, 2014.Aveiro, Portugal. Berlin Heidelberg: Springer, 2014: 63-72.
  • 2李凤海,李爽,张佰龙,宋衍.高等级安全网络抗APT攻击方案研究[J].信息网络安全,2014(9):109-114. 被引量:9
  • 3LANGNEtk tk. Stuxnet: Dissecting a Cyberwarfare Weapon[C]// IEEE Computer Society. Security & Privacy, IEEE, May 23-24, 2011. Claremont Resort in Oakland, California. New York: IEEE, 2011, 9(3): 49-51.
  • 4王在富.浅析APT攻击检测与防护策略[J].无线互联科技,2014,11(3):120-121. 被引量:2
  • 5NSFOCUS Information Technology Co Ltd. 2014 ICS Security Report[EB/OL]. http://vdisk,weibo.com/s/rlDAFAovsYVH, 2014-3- 11,.
  • 6李永强,谭立清,马同茂,张迪,周高磊,何旭.USB移动存储设备密级保护系统的设计与实现[J].计算机光盘软件与应用,2014,17(13):89-91. 被引量:3
  • 7陈晨,王奕钧,胡光俊,郭燕慧.针对手机的APT攻击方式的研究[J].信息网络安全,2015(3):33-37. 被引量:3
  • 8NIST. Managing Information Security kisk: Organization, Mission, and Information System View[EB/OL].http://csrc.nist.gov/publications/nistbul/itlbu12012_10.pdf, 2011-3-1.
  • 9FireEye Labs. Fireeye Advanced Threat Report[EB/OL].http://wenku. baidu.com/link?url= eHi5tUS lqp0hM4zeup0nRT31oWBMQztrkh- EbaR33z2y83dGkRt2ALoZ -70v6amVrptk71HJPQwzfzjTgdf-tstvu7Z- vzliOeFs2W8uNQ-W,2014-2-15.
  • 10DIWAN S A, PERUMAL S, FATAH AJ. Complete Security Package for USB Thumb Drive[J].Computer Engineering and Intelligent Systems, 2014, 5(8):30-37.

二级参考文献62

共引文献52

同被引文献41

引证文献7

二级引证文献27

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部