APT attack detection based on flow network analysis techniques using deep learning

被引:31
|
作者
Cho Do Xuan [1 ,2 ]
Mai Hoang Dao [1 ]
Hoa Dinh Nguyen [1 ]
机构
[1] Fac Informat Technol Posts & Telecommun, Inst Technol, Hanoi, Vietnam
[2] FPT Univ, Dept Informat Assurance, Hanoi, Vietnam
关键词
Advanced persistent threat; APT attack detection; network traffic; flow; bidirectional long short term memory; graph convolutional networks;
D O I
10.3233/JIFS-200694
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Advanced Persistent Threat (APT) attacks are a form of malicious, intentionally and clearly targeted attack. This attack technique is growing in both the number of recorded attacks and the extent of its dangers to organizations, businesses and governments. Therefore, the task of detecting and warning APT attacks in the real system is very necessary today. One of the most effective approaches to APT attack detection is to apply machine learning or deep learning to analyze network traffic. There have been a number of studies and recommendations to analyze network traffic into network flows and then combine with some classification or clustering methods to look for signs of APT attacks. In particular, recent studies often apply machine learning algorithms to spot the present of APT attacks based on network flow. In this paper, a new method based on deep learning to detect APT attacks using network flow is proposed. Accordingly, in our research, network traffic is analyzed into IP-based network flows, then the IP information is reconstructed from flow, and finally deep learning models are used to extract features for detecting APT attack IPs from other IPs. Additionally, a combined deep learning model using Bidirectional Long Short-Term Memory (BiLSTM) and Graph Convolutional Networks (GCN) is introduced. The new detection model is evaluated and compared with some traditional machine learning models, i.e. Multi-layer perceptron (MLP) and single GCN models, in the experiments. Experimental results show that BiLSTM-GCN model has the best performance in all evaluation scores. This not only shows that deep learning application on flow network analysis to detect APT attacks is a good decision but also suggests a new direction for network intrusion detection techniques based on deep learning.
引用
收藏
页码:4785 / 4801
页数:17
相关论文
共 50 条
  • [31] A New Approach for Network Steganography Detection based on Deep Learning Techniques
    Cho Do Xuan
    Lai Van Duong
    [J]. INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2021, 12 (07) : 37 - 42
  • [32] Detection of epileptic seizure using EEG signals analysis based on deep learning techniques
    Abdulwahhab, Ali H.
    Abdulaal, Alaa Hussein
    Al-Ghrairi, Assad H. Thary
    Mohammed, Ali Abdulwahhab
    Valizadeh, Morteza
    [J]. CHAOS SOLITONS & FRACTALS, 2024, 181
  • [33] Unsupervised Learning for Network Flow based Anomaly Detection in the Era of Deep Learning
    Kabir, Md Ahsanul
    Luo, Xiao
    [J]. 2020 IEEE SIXTH INTERNATIONAL CONFERENCE ON BIG DATA COMPUTING SERVICE AND APPLICATIONS (BIGDATASERVICE 2020), 2020, : 166 - 169
  • [34] A Novel Deep Learning Stack for APT Detection
    Bodstrom, Tero
    Hamalainen, Timo
    [J]. APPLIED SCIENCES-BASEL, 2019, 9 (06):
  • [35] Understanding the Influence of Graph Kernels on Deep Learning Architecture: A Case Study of Flow-based Network Attack Detection
    Su, Liya
    Yao, Yepeng
    Lu, Zhigang
    Liu, Baoxu
    [J]. 2019 18TH IEEE INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS/13TH IEEE INTERNATIONAL CONFERENCE ON BIG DATA SCIENCE AND ENGINEERING (TRUSTCOM/BIGDATASE 2019), 2019, : 312 - 318
  • [36] Distributed Denial of Service Attack Detection in Network Traffic Using Deep Learning Algorithm
    Ramzan, Mahrukh
    Shoaib, Muhammad
    Altaf, Ayesha
    Arshad, Shazia
    Iqbal, Faiza
    Castilla, Angel Kuc
    Ashraf, Imran
    [J]. SENSORS, 2023, 23 (20)
  • [37] Soter: Deep Learning Enhanced In-Network Attack Detection Based on Programmable Switches
    Xie, Guorui
    Li, Qing
    Cui, Chupeng
    Zhu, Peican
    Zhao, Dan
    Shi, Wanxin
    Qi, Zhuyun
    Jiang, Yong
    Xiao, Xi
    [J]. 2022 41ST INTERNATIONAL SYMPOSIUM ON RELIABLE DISTRIBUTED SYSTEMS (SRDS 2022), 2022, : 225 - 236
  • [38] Payload-Based Web Attack Detection Using Deep Neural Network
    Jin, Xiaohui
    Cui, Baojiang
    Yang, Jun
    Cheng, Zishuai
    [J]. ADVANCES ON BROAD-BAND WIRELESS COMPUTING, COMMUNICATION AND APPLICATIONS, BWCCA-2017, 2018, 12 : 482 - 488
  • [39] A novel approach for APT attack detection based on feature intelligent extraction and representation learning
    Do Xuan, Cho
    Cuong, Nguyen Hoa
    [J]. PLOS ONE, 2024, 19 (06):
  • [40] Wireless Intrusion and Attack Detection for 5G Networks using Deep Learning Techniques
    Alenazi, Bayana
    Idris, Hala Eldaw
    [J]. INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2021, 12 (07) : 851 - 856