Adversaries are often able to penetrate networks and compromise systems by exploiting vulnerabilities in people and systems. The key to the success of these attacks is information that adversaries collect throughout the phases of the cyber kill chain. We summarize and analyze the methods, tactics, and tools that adversaries use to conduct reconnaissance activities throughout the attack process. First, we discuss what types of information adversaries seek, and how and when they can obtain this information. Then, we provide a taxonomy and detailed overview of adversarial reconnaissance techniques. The taxonomy introduces a categorization of reconnaissance techniques based on the source as third-party, human-, and system-based information gathering. This paper provides a comprehensive view of adversarial reconnaissance that can help in understanding and modeling this complex but vital aspect of cyber attacks as well as insights that can improve defensive strategies, such as cyber deception.
翻译:攻击成功的关键是对手在网络杀人链的各个阶段收集的信息。我们总结和分析对手在整个攻击过程中用来进行侦察活动的方法、战术和工具。首先,我们讨论对手寻求何种类型的信息,以及他们何时和如何获得这些信息。然后,我们提供对抗性侦察技术的分类学和详细概览。分类学根据来源将侦察技术分类为第三方、人类和基于系统的信息收集。本文提供了对抗性侦察的全面观点,有助于理解和模拟网络攻击这一复杂但重要的方面,以及有助于改进防御战略(如网络欺骗)的洞察力。