Identifying cyber espionage: Towards a synthesis approach
Document Type
Conference Proceeding
Publication Date
3-17-2011
Abstract
Espionage has existed in many forms for as long as humans have kept secrets. With the skyrocketing growth of digital data storage, cyber espionage has quickly become the tool of choice for corporate and government spies. Cyber espionage typically occurs over the Internet with a consistent methodology: 1) infiltrate a targeted network, 2) install malware on the targeted victim(s), and 3) exfiltrate data at will. Detection methods exist and are well-researched for these three realms: network attack, malware, and data exfiltration. However, formal methodology does not exist for identifying cyber espionage as its own classification of cyber attack. This paper proposes a synthesis approach for identifying targeted espionage by fusing the intelligence gathered from current detection techniques. This synthesis of detection methods establishes a formal decision-making framework for determining the likelihood of cyber espionage.
Source Publication
6th International Conference on Information Warfare and Security, ICIW 2011
Recommended Citation
Merritt, D., & Mullins, B. E. (2011). Identifying cyber espionage: Towards a synthesis approach. 6th International Conference on Information Warfare and Security, ICIW 2011, 180–187.
Comments
Current AFIT students, faculty and staff may access the full conference paper through ProQuest, by clicking here.