Exploration of Mobile Device Behavior for Mitigating Advanced Persistent Threats (APT): A Systematic Literature Review and Conceptual Framework

Sensors (Basel). 2022 Jun 21;22(13):4662. doi: 10.3390/s22134662.

Abstract

During the last several years, the Internet of Things (IoT), fog computing, computer security, and cyber-attacks have all grown rapidly on a large scale. Examples of IoT include mobile devices such as tablets and smartphones. Attacks can take place that impact the confidentiality, integrity, and availability (CIA) of the information. One attack that occurs is Advanced Persistent Threat (APT). Attackers can manipulate a device's behavior, applications, and services. Such manipulations lead to signification of a deviation from a known behavioral baseline for smartphones. In this study, the authors present a Systematic Literature Review (SLR) to provide a survey of the existing literature on APT defense mechanisms, find research gaps, and recommend future directions. The scope of this SLR covers a detailed analysis of most cybersecurity defense mechanisms and cutting-edge solutions. In this research, 112 papers published from 2011 until 2022 were analyzed. This review has explored different approaches used in cybersecurity and their effectiveness in defending against APT attacks. In a conclusion, we recommended a Situational Awareness (SA) model known as Observe-Orient-Decide-Act (OODA) to provide a comprehensive solution to monitor the device's behavior for APT mitigation.

Keywords: Internet of Things (IoT); Observe–Orient–Decide–Act (OODA); Situational Awareness (SA); fingerprint; privacy; risk management; security; threat modeling; trust management; zero trust.

Publication types

  • Review
  • Systematic Review

MeSH terms

  • Computer Security*
  • Confidentiality
  • Dimaprit / analogs & derivatives
  • Internet of Things*
  • Smartphone

Substances

  • Dimaprit