Survey and Taxonomy of Adversarial Reconnaissance Techniques
Shanto Roy, Nazia Sharmin, Jaime C. Acosta, Christopher Kiekintveld,, Aron Laszka

TL;DR
This paper provides a comprehensive survey and taxonomy of adversarial reconnaissance techniques used in cyber attacks, categorizing methods based on information sources to enhance understanding and defense strategies.
Contribution
It introduces a detailed taxonomy of adversarial reconnaissance techniques based on information sources, aiding in understanding and modeling cyber attack behaviors.
Findings
Categorizes reconnaissance techniques into third-party, human-, and system-based methods.
Provides a comprehensive overview of adversarial reconnaissance tactics.
Offers insights to improve defensive strategies like cyber deception.
Abstract
Adversaries are often able to penetrate networks and compromise systems by exploiting vulnerabilities in people and systems. The key to the success of these attacks is information that adversaries collect throughout the phases of the cyber kill chain. We summarize and analyze the methods, tactics, and tools that adversaries use to conduct reconnaissance activities throughout the attack process. First, we discuss what types of information adversaries seek, and how and when they can obtain this information. Then, we provide a taxonomy and detailed overview of adversarial reconnaissance techniques. The taxonomy introduces a categorization of reconnaissance techniques based on the source as third-party, human-, and system-based information gathering. This paper provides a comprehensive view of adversarial reconnaissance that can help in understanding and modeling this complex but vital…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsNetwork Security and Intrusion Detection · Information and Cyber Security · Advanced Malware Detection Techniques
