Good-looking analysis from Georgia Tech.
Finally finished reading this.
This paper is so good. A lovely example of well-applied ML in cybersecurity. Also I suspect @neurovagrant will appreciate the DNS focus of this research.
Some fun findings:
Look who started eating the hosting ecosystem.
AS reuse
Actor-utilized domains are burned quickly, but also are younger than unrelated domains.
APT actors first provision infrastructure on their domain names 317 days on average before the APT attack is publicly reported. This number alone provides ample time for actors to successfully conduct their operations while negatively impacting detection systems that assign a positive reputation to longer-lived domains. Organizations need to keep their network logs for a time window of at least 19 to 25 months to be able to identify 90% of the APT infrastructure from a DNS perspective.
Lots of other gems in there. This is well worth the time to read.


