Cybersecurity@CSAIL Lecture: APT Cyber Attacks in Ukraine
Date and time
Location
Star Conference Room, 32-D463
Ray and Maria Stata Center 32 Vassar Street Cambridge, MA 02139Description
The team of leading cybersecurity experts from Ukraine will discuss the issues related to the series of APT cyber attacks on Ukrainian critical infrastructure, media, financial institutions and government that took place in 2015 and 2016 and resulted in power cuts, blackouts, and other serious consequences.
These attacks have been investigated by ISSP Labs - cyber forensics, threat intelligence and cyber research center of international cybersecurity company Information Systems Security Partners (ISSP Group) with headquarters in Kyiv.
Oleksii Yasynskyi, a principal researcher and Head of ISSP Labs and Oleksii Baranovskyi, researcher at ISSP Labs and Dean of Kyiv Cyber Academy will present key findings from these investigations, show how the attacks were planned and executed, and will discuss why these attacks were not detected by the most modern cybersecurity technologies like malware sandboxes, IPS, AV etc., and what we should do about it in order to enhance our cybersecurity capabilities.
Topics covered include:
- APT Attacks Common Model (KillChain)
- Actions on objectives
- Compromised components investigation
- Anomaly detection and event correlation
- Installation and exploitation phase of investigation
- Evading antiviruses method detection
- C&C center detection
- Investigation of delivery stage
- Weaponization stage analysis
- Risk of legacy-technologies in infrastructure
- Reconnaissance stage
- Attack timeline