Investigating cyber-attacks in a legally binding way becomes more and more difficult, especially through advanced attacks (AT) such as advanced persistent threats (APT) or multihost attacks. Current forensic models do not provide a basis for a process to analyze such attacks. This paper's objective is to find a novel forensic management approach based on agile methods to meet the challenges of ATs. When it comes to the forensic investigation of such attacks, big data problems need to be addressed due to the amount of data that needs to be analyzed. The proposed model meets this requirement by precisely defining the questions that need to be answered in an early state and collecting only the evidence that is needed to answer these questions. Additionally, the novel flower model for AT is presented that meets the different phases of an investigation process.
Both criminals and state actors are using the cyberspace to pursue their interests, including obtaining information, sabotaging networks, and disseminating disinformation. Advanced Persistent Threats (APTs) are state and non-state threat actors with high levels of expertise, target knowledge, and available financial and material resources. To effectively counter APT campaigns, it is necessary to have a deep understanding of the methods used by threat actors. Cyber Ranges provide a realistic training environment to develop and train the skills needed to respond to future attacks. However, this requires the ability to simulate APT attacks in a Cyber Range in an automated manner. This article presents an approach to implementing APT scenarios in fully virtualized Cyber Ranges. To achieve this, we extended a theoretical model to enable the formalized representation of APT attacks. Based on this model, we developed a concept for the technical implementation resulting in a framework for an automated simulation of APT attacks in Cyber Ranges. We evaluated both by formalizing two different real-world APT scenarios and implementing an abstract one.
The lack of guided exercises and practical opportunities to learn about cybersecurity in a practical way makes it difficult for security experts to improve their proficiency. Capture the Flag events and Cyber Ranges are ideal for cybersecurity training. Thereby, the participants usually compete in teams against each other, or have to defend themselves in a specific scenario. As organizers of yearly events, we present a taxonomy for interactive cyber training and education. The proposed taxonomy includes different factors of the technical setup, audience, training environment, and training setup. By the comprehensive taxonomy, different aspects of interactive training are considered. This can help trainings to improve and to be established successfully. The provided taxonomy is extendable and can be used in further application areas as research on new security technologies.
Phishing is a type of scam designed to steal users’ personal information, e.g. passwords, credit card information, or other account details. Phishing websites look similar to legitimate ones, making it difficult for users to differentiate between them. Phishing attacks are constantly being improved and the range of techniques used are continuously expanded. Signatures and encryption in emails are security mechanisms that phishers could attempt to misuse. This paper analyses the potential of these methods. Two comparative studies on the effect of Pretty Good Privacy (PGP) signatures and encryption in phishing mails were conducted. The effect was analysed in social and security-related contexts and with computer-savvy as well as regular recipients. We examined the factors computer experience, signature, encryption, signature and encryption, as well as interaction between computer experience and signatures. The results indicate a potential for misuse. Observations made during this study are stated along with future work.
The forensic investigation of cyber attacks and IT incidents is becoming increasingly difficult due to increasing complexity and intensify networking. Especially with Advanced Attacks (AT) like the increasing Advanced Persistent Threats an agile approach is indispensable. Several systems are involved in an attack (multi-host attacks). Current forensic models and procedures show considerable deficits in the process of analyzing such attacks. For this purpose, this paper presents the novel flower model, which uses agile methods and forms a new forensic management approach. In this way, the growing challenges of ATs are met. In the forensic investigation of such attacks, big data problems have to be solved due to the amount of data that needs to be analyzed. The proposed model meets this requirement by precisely defining the questions that need to be answered in an early state and collecting only the evidence usable in court proceedings that is needed to answer these questions. Additionally, the novel flower model for AT is presented that meets the different phases of an investigation process.
Cyber incidents can have a wide range of cause from a simple connection loss to an insistent attack. Once a potential cyber security incidents and system failures have been identified, deciding how to proceed is often complex. Especially, if the real cause is not directly in detail determinable. Therefore, we developed the concept of a Cyber Incident Handling Support System. The developed system is enriched with information by multiple sources such as intrusion detection systems and monitoring tools. It uses over twenty key attributes like sync-package ratio to identify potential security incidents and to classify the data into different priority categories. Afterwards, the system uses artificial intelligence to support the further decision-making process and to generate corresponding reports to brief the Board of Directors. Originating from this information, appropriate and detailed suggestions are made regarding the causes and troubleshooting measures. Feedback from users regarding the problem solutions are included into future decision-making by using labelled flow data as input for the learning process. The prototype shows that the decision making can be sustainably improved and the Cyber Incident Handling process becomes much more effective.
Posttraumatic stress disorder (PTSD) is a global public health problem. Unfortunately, many individuals with PTSD do not receive professional care due to a lack of available providers, stigma about mental illness, and other concerns. Technology-based interventions, including mobile phone applications (apps) may be a viable means of surmounting such barriers and reaching and helping those in need. Given this potential, in 2011 the U.S Veterans Affairs National Center for PTSD released PTSD Coach, a mobile app intended to provide psycho-education and self-management tools for trauma survivors with PTSD symptoms. Emerging research on PTSD Coach demonstrates high user satisfaction, feasibility, and improvement in PTSD symptoms and other psychosocial outcomes. A model of openly sharing the app's source code and content has resulted in versions being created by individuals in six other countries: Australia, Canada, The Netherlands, Germany, Sweden, and Denmark. These versions are described, highlighting their significant adaptations, enhancements, and expansions to the original PTSD Coach app as well as emerging research on them. It is clear that the sharing of app source code and content has benefited this emerging PTSD Coach community, as well as the populations they are targeting. Despite this success, challenges remain especially reaching trauma survivors in areas where few or no other mental health resources exist.