{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,13]],"date-time":"2026-07-13T21:08:12Z","timestamp":1783976892523,"version":"3.55.0"},"publisher-location":"Cham","reference-count":54,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783030105426","type":"print"},{"value":"9783030105433","type":"electronic"}],"license":[{"start":{"date-parts":[[2019,1,1]],"date-time":"2019-01-01T00:00:00Z","timestamp":1546300800000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2019]]},"DOI":"10.1007\/978-3-030-10543-3_10","type":"book-chapter","created":{"date-parts":[[2019,3,22]],"date-time":"2019-03-22T14:03:29Z","timestamp":1553263409000},"page":"225-255","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":16,"title":["Protecting IoT and ICS Platforms Against Advanced Persistent Threat Actors: Analysis of APT1, Silent Chollima and Molerats"],"prefix":"10.1007","author":[{"given":"Samuel","family":"Grooby","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Tooska","family":"Dargahi","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ali","family":"Dehghantanha","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2019,3,23]]},"reference":[{"key":"10_CR1","doi-asserted-by":"crossref","unstructured":"H. Haughey, G. Epiphaniou, H. Al-Khateeb, and A. Dehghantanha, Adaptive traffic fingerprinting for darknet threat intelligence, vol. 70. 2018.","DOI":"10.1007\/978-3-319-73951-9_10"},{"key":"10_CR2","doi-asserted-by":"crossref","unstructured":"S. Homayoun, A. Dehghantanha, M. Ahmadzadeh, S. Hashemi, and R. Khayami, \u201cKnow Abnormal, Find Evil: Frequent Pattern Mining for Ransomware Threat Hunting and Intelligence,\u201d {IEEE} Trans. Emerg. Top. Comput., p. 1, 2017.","DOI":"10.1109\/TETC.2017.2756908"},{"key":"10_CR3","doi-asserted-by":"crossref","unstructured":"D. Kiwia, A. Dehghantanha, K.-K. R. Choo, and J. Slaughter, \u201cA cyber kill chain based taxonomy of banking Trojans for evolutionary computational intelligence,\u201d J. Comput. Sci., Nov. 2017.","DOI":"10.1016\/j.jocs.2017.10.020"},{"key":"10_CR4","unstructured":"B. E. Binde, R. McRee, and T. J. O\u2019Connor, \u201cAssessing Outbound Traffic to Uncover Advanced Persistent Threat,\u201d 2011."},{"key":"10_CR5","unstructured":"NIST, \u201cGlossary of Key Information Security Terms,\u201d 2013."},{"key":"10_CR6","unstructured":"N. Villeneuve, N. Moran, M. Scott, and T. Haq, \u201cOPERATION SAFFRON ROSE,\u201d 2013."},{"key":"10_CR7","doi-asserted-by":"crossref","unstructured":"S. E. Goodman, J. C. Kirk, and M. H. Kirk, \u201cCyberspace as a medium for terrorists,\u201d Technol. Forecast. Soc. Change, vol. 74, no. 2, pp. 193\u2013210, 2007.","DOI":"10.1016\/j.techfore.2006.07.007"},{"key":"10_CR8","unstructured":"A. Earls, \u201cAPTs New waves of advanced persistent threats are vastly improved and smarter than ever.,\u201d ebook SC Magazine, 2015."},{"key":"10_CR9","doi-asserted-by":"crossref","unstructured":"H. Haddad Pajouh, R. Javidan, R. Khayami, D. Ali, and K.-K. R. Choo, \u201cA Two-layer Dimension Reduction and Two-tier Classification Model for Anomaly-Based Intrusion Detection in IoT Backbone Networks,\u201d IEEE Trans. Emerg. Top. Comput., pp. 1\u20131, 2016.","DOI":"10.1109\/TETC.2016.2633228"},{"key":"10_CR10","unstructured":"G. M. Insights, \u201cAdvanced Persistent Threats (APT) Market Size, Industry Outlook, Regional Analysis (U.S., Canada, Germany, France, UK, Italy, Russia, China, Japan, India, Thailand, Indonesia, Malaysia, Australia, Brazil, Mexico, Saudi Arabia, UAE, South Africa), Applicat,\u201d 2017."},{"key":"10_CR11","doi-asserted-by":"crossref","unstructured":"M. Hopkins and A. Dehghantanha, \u201cExploit Kits: The production line of the Cybercrime economy?,\u201d in 2015 Second International Conference on Information Security and Cyber Forensics (InfoSec), 2015, pp. 23\u201327.","DOI":"10.1109\/InfoSec.2015.7435501"},{"key":"10_CR12","doi-asserted-by":"crossref","unstructured":"A. Azmoodeh, A. Dehghantanha, and K.-K. R. Choo, \u201cRobust Malware Detection for Internet Of (Battlefield) Things Devices Using Deep Eigenspace Learning,\u201d IEEE Trans. Sustain. Comput., pp. 1\u20131, 2018.","DOI":"10.1109\/TSUSC.2018.2809665"},{"key":"10_CR13","unstructured":"R. Brewer, \u201cAdvanced persistent threats: Minimising the damage,\u201d Netw. Secur., vol. 2014, no. 4, pp. 5\u20139, 2014."},{"key":"10_CR14","doi-asserted-by":"crossref","unstructured":"I. Friedberg, F. Skopik, G. Settanni, and R. Fiedler, \u201cCombating advanced persistent threats: From network event correlation to incident detection,\u201d Comput. Secur., vol. 48, pp. 35\u201357, 2015.","DOI":"10.1016\/j.cose.2014.09.006"},{"key":"10_CR15","doi-asserted-by":"crossref","unstructured":"H. HaddadPajouh, A. Dehghantanha, R. Khayami, and K.-K. R. Choo, \u201cA deep Recurrent Neural Network based approach for Internet of Things malware threat hunting,\u201d Futur. Gener. Comput. Syst., 2018.","DOI":"10.1016\/j.future.2018.03.007"},{"key":"10_CR16","doi-asserted-by":"crossref","unstructured":"J. Chen, C. Su, K.-H. Yeh, and M. Yung, \u201cSpecial Issue on Advanced Persistent Threat,\u201d Futur. Gener. Comput. Syst., vol. 79, pp. 243\u2013246, 2018.","DOI":"10.1016\/j.future.2017.11.005"},{"key":"10_CR17","doi-asserted-by":"crossref","unstructured":"H. H. Pajouh, A. Dehghantanha, R. Khayami, and K.-K. R. Choo, \u201cIntelligent OS X malware threat detection with code inspection,\u201d J. Comput. Virol. Hacking Tech., 2017.","DOI":"10.1007\/s11416-017-0307-5"},{"key":"10_CR18","unstructured":"C. Tankard, \u201cAdvanced Persistent threats and how to monitor and deter them,\u201d Netw. Secur., vol. 2011, no. 8, pp. 16\u201319, Aug. 2011."},{"key":"10_CR19","doi-asserted-by":"crossref","unstructured":"A. Azmoodeh, A. Dehghantanha, M. Conti, and K.-K. R. Choo, \u201cDetecting crypto-ransomware in IoT networks based on energy consumption footprint,\u201d J. Ambient Intell. Humaniz. Comput., pp. 1\u201312, Aug. 2017.","DOI":"10.1007\/s12652-017-0558-5"},{"key":"10_CR20","unstructured":"A. Greenberg, \u201cThe Zero-Day Salesmen.,\u201d Forbes, vol. 189, no. 6, pp. 40\u201344, 2012."},{"key":"10_CR21","doi-asserted-by":"crossref","unstructured":"M. Petraityte, A. Dehghantanha, and G. Epiphaniou, \u201cA Model for Android and iOS Applications Risk Calculation: CVSS Analysis and Enhancement Using Case-Control Studies,\u201d 2018, pp. 219\u2013237.","DOI":"10.1007\/978-3-319-73951-9_11"},{"key":"10_CR22","unstructured":"Mandiant, \u201cAPT1: Exposing One of China\u2019s Cyber Espionage Units,\u201d 2014."},{"key":"10_CR23","unstructured":"F. N. P. Office, \u201cUpdate on Sony Investigation,\u201d 2017."},{"key":"10_CR24","unstructured":"B. Parys, \u201cMoleRats: there\u2019s more to the naked eye,\u201d PWC Blogs, 2016."},{"key":"10_CR25","doi-asserted-by":"crossref","unstructured":"M. Conti, A. Dehghantanha, K. Franke, and S. Watson, \u201cInternet of Things Security and Forensics: Challenges and Opportunities,\u201d Futur. Gener. Comput. Syst., Jul. 2017.","DOI":"10.1016\/j.future.2017.07.060"},{"key":"10_CR26","doi-asserted-by":"crossref","unstructured":"J. Baldwin, O. M. K. Alhawi, S. Shaughnessy, A. Akinbi, and A. Dehghantanha, \u201cEmerging from the Cloud: A Bibliometric Analysis of Cloud Forensics Studies,\u201d 2018, pp. 311\u2013331.","DOI":"10.1007\/978-3-319-73951-9_16"},{"key":"10_CR27","doi-asserted-by":"crossref","unstructured":"A. Cook, H. Janicke, R. Smith, and L. Maglaras, \u201cThe industrial control system cyber defence triage process,\u201d Comput. Secur., vol. 70, pp. 467\u2013481, Sep. 2017.","DOI":"10.1016\/j.cose.2017.07.009"},{"key":"10_CR28","doi-asserted-by":"crossref","unstructured":"M. Marchetti, F. Pierazzi, M. Colajanni, and A. Guido, \u201cAnalysis of high volumes of network traffic for Advanced Persistent Threat detection,\u201d Comput. Networks, vol. 109, pp. 127\u2013141, Nov. 2016.","DOI":"10.1016\/j.comnet.2016.05.018"},{"key":"10_CR29","doi-asserted-by":"crossref","unstructured":"K. A. Ismail, M. M. Singh, N. Mustaffa, P. Keikhosrokiani, and Z. Zulkefli, \u201cSecurity Strategies for Hindering Watering Hole Cyber Crime Attack,\u201d Procedia Comput. Sci., vol. 124, pp. 656\u2013663, 2017.","DOI":"10.1016\/j.procs.2017.12.202"},{"key":"10_CR30","unstructured":"S. Caltagirone, A. Pendergast, and C. Betz, \u201cThe Diamond Model of Intrusion Analysis,\u201d Threat Connect, vol. 298, no. 0704, pp. 1\u201361, 2013."},{"key":"10_CR31","unstructured":"E. M. Hutchins, M. J. Cloppert, and R. M. Amin, \u201cIntelligence-Driven Computer Network Defense Informed by Analysis of Adversary Campaigns and Intrusion Kill Chains.\u201d"},{"key":"10_CR32","unstructured":"U.S. Department of Justice, \u201cU.S. Charges Five Chinese Military Hackers For Cyber Espionage Against U.S. Corporations And A Labor Organization For Commercial Advantage,\u201d 2014."},{"key":"10_CR33","unstructured":"S. Fagerland, \u201cSystematic cyber attacks against Israeli and Palestinian targets going on for a year,\u201d 2012."},{"key":"10_CR34","unstructured":"T. Dahms, \u201cMolerats, Here for Spring!,\u201d 2014."},{"key":"10_CR35","unstructured":"ClearSky, \u201cOperation DustySky,\u201d 2016."},{"key":"10_CR36","unstructured":"R. Sherstobitoff and I. Liba, \u201cDissecting Operation Troy: Cyberespionage in South Korea,\u201d 2013."},{"key":"10_CR37","unstructured":"D. Tarakanov, \u201cThe \u2018Kimsuky\u2019 Operation: A North Korean APT?,\u201d 2013."},{"key":"10_CR38","unstructured":"Fast Horizon, \u201cInside an APT Covert Communications Channel,\u201d 2011."},{"key":"10_CR39","unstructured":"K. Wilhoit, \u201cThe SCADA That Didn\u2019t Cry Wolf,\u201d 2013."},{"key":"10_CR40","unstructured":"S. Narang, \u201cBackdoor.Barkiofork Targets Aerospace and Defense Industry,\u201d Symantec Official Blog, 2013."},{"key":"10_CR41","unstructured":"N. M. Nart Villeneuve, Thoufique Haq, \u201cOperation Molerats: Middle East Cyber Attacks Using Poison Ivy,\u201d FireEye, 2013."},{"key":"10_CR42","unstructured":"RBS, \u201cA Breakdown and Analysis of the December, 2014 Sony Hack,\u201d RiskBasedSecurity, 2014."},{"key":"10_CR43","unstructured":"J. Bort, \u201cHow The Hackers Broke Into Sony And Why It Could Happen To Any Company,\u201d Business Insider UK, 2014."},{"key":"10_CR44","unstructured":"P. Brown, J. Sciutto, E. Perez, E. Bradner, and J. Acosta, \u201cInvestigators think hackers stole Sony passwords,\u201d CNN Poltics, 2014."},{"key":"10_CR45","unstructured":"S. Gallagher, \u201cInside the \u2018wiper\u2019 malware that brought Sony Pictures to its knees [Update],\u201d ars Technica, 2014."},{"key":"10_CR46","doi-asserted-by":"crossref","unstructured":"S. Walker-Roberts, M. Hammoudeh, and A. Dehghantanha, \u201cA Systematic Review of the Availability and Efficacy of Countermeasures to Internal Threats in Healthcare Critical Infrastructure,\u201d IEEE Access, pp. 1\u20131, 2018.","DOI":"10.1109\/ACCESS.2018.2817560"},{"key":"10_CR47","doi-asserted-by":"crossref","unstructured":"A. Shalaginov, S. Banin, A. Dehghantanha, and K. Franke, Machine learning aided static malware analysis: A survey and tutorial, vol. 70. 2018.","DOI":"10.1007\/978-3-319-73951-9_2"},{"key":"10_CR48","doi-asserted-by":"crossref","unstructured":"Y.-Y. Teing, A. Dehghantanha, K. Choo, M. T. Abdullah, and Z. Muda, \u201cGreening Cloud-Enabled Big Data Storage Forensics: Syncany as a Case Study,\u201d IEEE Trans. Sustain. Comput., pp. 1\u20131, 2017.","DOI":"10.1109\/TSUSC.2017.2687103"},{"key":"10_CR49","doi-asserted-by":"crossref","unstructured":"Y.-Y. Teing, A. Dehghantanha, and K.-K. R. Choo, \u201cCloudMe forensics: A case of big data forensic investigation,\u201d Concurr. Comput., 2017.","DOI":"10.1002\/cpe.4277"},{"key":"10_CR50","doi-asserted-by":"crossref","unstructured":"N. Milosevic, A. Dehghantanha, and K.-K. R. Choo, \u201cMachine learning aided Android malware classification,\u201d Comput. Electr. Eng., vol. 61, 2017.","DOI":"10.1016\/j.compeleceng.2017.02.013"},{"key":"10_CR51","doi-asserted-by":"crossref","unstructured":"O. M. K. Alhawi, J. Baldwin, and A. Dehghantanha, Leveraging machine learning techniques for windows ransomware network traffic detection, vol. 70. 2018.","DOI":"10.1007\/978-3-319-73951-9_5"},{"key":"10_CR52","doi-asserted-by":"crossref","unstructured":"J. Baldwin and A. Dehghantanha, Leveraging support vector machine for opcode density based detection of crypto-ransomware, vol. 70. 2018.","DOI":"10.1007\/978-3-319-73951-9_6"},{"key":"10_CR53","doi-asserted-by":"crossref","unstructured":"S. Homayoun, M. Ahmadzadeh, S. Hashemi, A. Dehghantanha, and R. Khayami, \u201cBoTShark: A Deep Learning Approach for Botnet Traffic Detection,\u201d 2018, pp. 137\u2013153.","DOI":"10.1007\/978-3-319-73951-9_7"},{"key":"10_CR54","doi-asserted-by":"crossref","unstructured":"O. Osanaiye, H. Cai, K.-K. R. Choo, A. Dehghantanha, Z. Xu, and M. Dlodlo, \u201cEnsemble-based multi-filter feature selection method for DDoS detection in cloud computing,\u201d EURASIP J. Wirel. Commun. Netw., vol. 2016, no. 1, p. 130, May 2016.","DOI":"10.1186\/s13638-016-0623-3"}],"container-title":["Handbook of Big Data and IoT Security"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-10543-3_10","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,11,21]],"date-time":"2019-11-21T22:14:44Z","timestamp":1574374484000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-030-10543-3_10"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019]]},"ISBN":["9783030105426","9783030105433"],"references-count":54,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-10543-3_10","relation":{},"subject":[],"published":{"date-parts":[[2019]]},"assertion":[{"value":"23 March 2019","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}}]}}