The Whole Picture of APT Attacks Targeting Japan - What We See from STIX-based Analysis -

No ratings

Presented at codeblue 2017 by

JPCERT/CC analyzes APT attack campaigns observed in Japan by investigating C&C servers used in the attack and information collected by affected organizations. In order to capture the whole picture of APT attack campaigns targeting Japanese organizations, JPCERT/CC is now developing a system to describe incident information in STIX format and store in a database. We plan to release this system on GitHub as an open source software. This system aims to analyze attack methods and targets chronologically according to attack campaign, adversary, malware as well as method for initial intrusion and lateral movement, which is visualized as a timeline. Based on the analysis using this system, this presentation will introduce an overview of APT attack campaigns targeting Japan in order of time, as well as the relation to other campaigns by focusing on similarities in attack methods. By focusing on the targets’ characteristics in various campaigns, we will examine each adversary’s purpose behind the attack. In addition, technical features of this system will be covered, along with some observations gained through our analysis using STIX-based incident description.