Advanced persistent threat (APT) is widely acknowledged to be the most sophisticated and potent class of security threat. APT refers to knowledgeable human attackers that are organized, highly sophisticated and motivated to achieve their objectives against a targeted organization(s) over a prolonged period. Strategically-motivated APTs or S-APTs are distinct in that they draw their objectives from the broader strategic agenda of third parties such as criminal syndicates, nation-states, and rival corporations. In this paper we review the use of the term - Advanced Persistent Threat - and present a formal definition. We then draw on military science, the science of organized conflict, for a theoretical basis to develop a rigorous and holistic model of the stages of an APT operation which we subsequently use to explain how S-APTs execute their strategically motivated operations using tactics, techniques and procedures. Finally, we present a general disinformation model, derived from situation awareness theory, and explain how disinformation can be used to attack the situation awareness and decision making of not only S-APT operators, but also the entities that back them.
翻译:人们普遍承认,先进的持续威胁(APT)是最为复杂和强大的安全威胁类别。APT指有知识的人类攻击者,他们有组织、高度精密,并有长期针对目标组织实现其目标的动机。具有战略动机的APT或S-APT是不同的,因为它们的目标来自诸如犯罪集团、民族国家和敌对公司等第三方更广泛的战略议程。在本文件中,我们审查了使用“高级持续威胁”这一术语的情况,并提出了一个正式的定义。然后,我们借助军事科学、有组织的冲突科学,作为理论基础,为APT行动的各个阶段制定一个严格和全面的模式,我们随后利用这一模式解释S-APT如何使用战术、技术和程序执行具有战略动机的行动。最后,我们提出了一个从形势认识理论中推导出的一般不实信息模型,并解释如何利用不实信息来攻击不仅S-APT操作者,而且支持他们的实体对局势的认识和决策。