With the growing complexity and prevalence of state-sponsored Advanced Persistent Threats (APTs), exfiltration of bulk sensitive data is becoming increasingly commonplace. Furthermore, recent APTs and APT toolkits uncovered have been utilizing creative methods to communicate with Command and Control (C2) infrastructure as well as exfiltrate data, often using multiple hard-to-detect methodologies such as trusted third-party services, SMTP, or DNS. This paper proposes a scalable protocol for managing multiple secure and reliable covert channels over physical or digital means. Throughout we will show the desire for, practical applications of, and future goals for this protocol
Paper
Full text
From Bear to Vault: Designing a New Protocol to Extend the APT Communications Toolset
Semantic Scholar · Computer Science · 2018
Abstract
With the growing complexity and prevalence of state-sponsored Advanced Persistent Threats (APTs), exfiltration of bulk sensitive data is becoming increasingly commonplace. Furthermore, recent APTs and APT toolkits uncovered have been utilizing creative methods to communicate with Command and Control (C2) infrastructure as well as exfiltrate data, often using multiple hard-to-detect methodologies such as trusted third-party services, SMTP, or DNS. This paper proposes a scalable protocol for managing multiple secure and reliable covert channels over physical or digital means. Throughout we will show the desire for, practical applications of, and future goals for this protocol