APT attack detection based on flow network analysis techniques using deep learning

被引:31
|
作者
Cho Do Xuan [1 ,2 ]
Mai Hoang Dao [1 ]
Hoa Dinh Nguyen [1 ]
机构
[1] Fac Informat Technol Posts & Telecommun, Inst Technol, Hanoi, Vietnam
[2] FPT Univ, Dept Informat Assurance, Hanoi, Vietnam
关键词
Advanced persistent threat; APT attack detection; network traffic; flow; bidirectional long short term memory; graph convolutional networks;
D O I
10.3233/JIFS-200694
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Advanced Persistent Threat (APT) attacks are a form of malicious, intentionally and clearly targeted attack. This attack technique is growing in both the number of recorded attacks and the extent of its dangers to organizations, businesses and governments. Therefore, the task of detecting and warning APT attacks in the real system is very necessary today. One of the most effective approaches to APT attack detection is to apply machine learning or deep learning to analyze network traffic. There have been a number of studies and recommendations to analyze network traffic into network flows and then combine with some classification or clustering methods to look for signs of APT attacks. In particular, recent studies often apply machine learning algorithms to spot the present of APT attacks based on network flow. In this paper, a new method based on deep learning to detect APT attacks using network flow is proposed. Accordingly, in our research, network traffic is analyzed into IP-based network flows, then the IP information is reconstructed from flow, and finally deep learning models are used to extract features for detecting APT attack IPs from other IPs. Additionally, a combined deep learning model using Bidirectional Long Short-Term Memory (BiLSTM) and Graph Convolutional Networks (GCN) is introduced. The new detection model is evaluated and compared with some traditional machine learning models, i.e. Multi-layer perceptron (MLP) and single GCN models, in the experiments. Experimental results show that BiLSTM-GCN model has the best performance in all evaluation scores. This not only shows that deep learning application on flow network analysis to detect APT attacks is a good decision but also suggests a new direction for network intrusion detection techniques based on deep learning.
引用
收藏
页码:4785 / 4801
页数:17
相关论文
共 50 条
  • [1] Network Flow based IoT Botnet Attack Detection using Deep Learning
    Sriram, S.
    Vinayakumar, R.
    Alazab, Mamoun
    Soman, K. P.
    [J]. IEEE INFOCOM 2020 - IEEE CONFERENCE ON COMPUTER COMMUNICATIONS WORKSHOPS (INFOCOM WKSHPS), 2020, : 189 - 194
  • [2] Classification and Analysis of Malicious Code Detection Techniques Based on the APT Attack
    Lee, Kyungroul
    Lee, Jaehyuk
    Yim, Kangbin
    [J]. APPLIED SCIENCES-BASEL, 2023, 13 (05):
  • [3] Optimization of APT attack detection based on a model combining ATTENTION and deep learning
    Cho Do Xuan
    Duc Duong
    [J]. JOURNAL OF INTELLIGENT & FUZZY SYSTEMS, 2022, 42 (04) : 4135 - 4151
  • [4] A novel approach for APT attack detection based on combined deep learning model
    Cho Do Xuan
    Mai Hoang Dao
    [J]. Neural Computing and Applications, 2021, 33 : 13251 - 13264
  • [5] A novel approach for APT attack detection based on combined deep learning model
    Cho Do Xuan
    Mai Hoang Dao
    [J]. NEURAL COMPUTING & APPLICATIONS, 2021, 33 (20): : 13251 - 13264
  • [6] A deep learning-based attack on text CAPTCHAs by using object detection techniques
    Nian, Jiawei
    Wang, Ping
    Gao, Haichang
    Guo, Xiaoyan
    [J]. IET INFORMATION SECURITY, 2022, 16 (02) : 97 - 110
  • [7] Developing a Network Attack Detection System Using Deep Learning
    Alsughayyir, Bayan
    Qamar, Ali Mustafa
    Khan, Rehanullah
    [J]. 2019 INTERNATIONAL CONFERENCE ON COMPUTER AND INFORMATION SCIENCES (ICCIS), 2019, : 232 - 236
  • [8] A new framework for APT attack detection based on network traffic
    Hoa Cuong Nguyen
    Cho Do Xuan
    Long Thanh Nguyen
    Hoa Dinh Nguyen
    [J]. JOURNAL OF INTELLIGENT & FUZZY SYSTEMS, 2023, 44 (03) : 3459 - 3474
  • [9] Network anomaly detection using deep learning techniques
    Hooshmand, Mohammad Kazim
    Hosahalli, Doreswamy
    [J]. CAAI TRANSACTIONS ON INTELLIGENCE TECHNOLOGY, 2022, 7 (02) : 228 - 243
  • [10] Optimization of Cyber-Attack Detection Using the Deep Learning Network
    Van Duong, Lai
    [J]. INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2021, 21 (07): : 159 - 163