A novel approach for APT attack detection based on combined deep learning model

被引:34
|
作者
Cho Do Xuan [1 ,2 ]
Mai Hoang Dao [1 ]
机构
[1] Posts & Telecommun Inst Technol, Fac Informat Technol, Hanoi, Vietnam
[2] FPT Univ, Informat Assurance Dept, Hanoi, Vietnam
来源
NEURAL COMPUTING & APPLICATIONS | 2021年 / 33卷 / 20期
关键词
Advanced persistent threat; APT attack detection; Network traffic; Abnormal behavior; Combined deep learning model; ADVANCED PERSISTENT THREATS;
D O I
10.1007/s00521-021-05952-5
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Advanced persistent threat (APT) attack is a malicious attack type which has intentional and clear targets. This attack technique has become a challenge for information security systems of organizations, governments, and businesses. The approaches of using machine learning or deep learning algorithms to analyze signs and abnormal behaviors of network traffic for detecting and preventing APT attacks have become popular in recent years. However, the APT attack detection approach that uses behavior analysis and evaluation techniques is facing many difficulties due to the lack of typical data of attack campaigns. To handle this situation, recent studies have selected and extracted the APT attack behaviors which based on datasets are built from experimental tools. Consequently, these properties are few and difficult to obtain in practical monitoring systems. Therefore, although the experimental results show good detection, it does not bring high efficiency in practice. For above reasons, in this paper, a new method based on network traffic analysis using a combined deep learning model to detect APT attacks will be proposed. Specifically, individual deep learning networks such as multilayer perceptron (MLP), convolutional neural network (CNN), and long short-term memory (LSTM) will also be sought, built and linked into combined deep learning networks to analyze and detect signs of APT attacks in network traffic. To detect APT attack signals, the combined deep learning models are performed in two main stages including (i) extracting IP features based on flow: In this phase, we will analyze network traffic into networking flows by IP address and then use the combined deep learning models to extract IP features by network flow; (ii) classifying APT attack IPs: Based on IP features extracted in a task (i), the APT attack IPs and normal IPs will be identified and classified. The proposal of a combined deep learning model to detect APT attacks based on network traffic is a new approach, and there is no research proposed and applied yet. In the experimental section, combined deep learning models proved their superior abilities to ensure accuracy on all measurements from 93 to 98%. This is a very good result for APT attack detection based on network traffic.
引用
收藏
页码:13251 / 13264
页数:14
相关论文
共 50 条
  • [21] Deep Learning Approach for Attack Detection in Controller Area Networks
    Lee, Jungyeong
    Kim, Woocheol
    Cho, Jin-Hee
    Kim, Dong Seong
    Moore, Terrence J.
    Nelson, Frederica F.
    Lim, Hyuk
    [J]. ARTIFICIAL INTELLIGENCE AND MACHINE LEARNING FOR MULTI-DOMAIN OPERATIONS APPLICATIONS III, 2021, 11746
  • [22] Detection of attack behaviour of pig based on deep learning
    Li, Yanwen
    Li, Juxia
    Na, Tengxiao
    Yang, Hua
    [J]. SYSTEMS SCIENCE & CONTROL ENGINEERING, 2023, 11 (01)
  • [23] The APT Detection Method based on Attack Tree for SDN
    Jia Shan-Shan
    Xu Ya-Bin
    [J]. ICCSP 2018: PROCEEDINGS OF THE 2ND INTERNATIONAL CONFERENCE ON CRYPTOGRAPHY, SECURITY AND PRIVACY, 2018, : 116 - 121
  • [24] An APT Attack Detection Method Based on eBPF and Transformer
    Qiu, Rixuan
    Luo, Hao
    Jing, Sitong
    Li, Xinxiu
    Li, Yuancheng
    [J]. International Journal of Network Security, 2024, 26 (06) : 964 - 972
  • [25] The Optimized Attribute Attack Graph Based on APT Attack Stage Model
    Li, Meicong
    Huang, Wei
    Wang, Yongbin
    Fan, Wenqing
    [J]. 2016 2ND IEEE INTERNATIONAL CONFERENCE ON COMPUTER AND COMMUNICATIONS (ICCC), 2016, : 2781 - 2785
  • [26] A Novel Approach for Marine Small Target Detection Based on Deep Learning
    Pan, Meiyan
    Chen, Jianjun
    Wang, Shengli
    Dong, Ziwei
    [J]. 2019 IEEE 4TH INTERNATIONAL CONFERENCE ON SIGNAL AND IMAGE PROCESSING (ICSIP 2019), 2019, : 395 - 399
  • [27] Hybrid deep learning model for attack detection in internet of things
    Rekha, H.
    Siddappa, M.
    [J]. SERVICE ORIENTED COMPUTING AND APPLICATIONS, 2022, 16 (04) : 293 - 312
  • [28] An Explainable Deep Learning Model for Fingerprint Presentation Attack Detection
    Rai, Anuj
    Dey, Somnath
    [J]. COMPUTER VISION AND IMAGE PROCESSING, CVIP 2023, PT III, 2024, 2011 : 309 - 321
  • [29] Hybrid deep learning model for attack detection in internet of things
    H. Rekha
    M. Siddappa
    [J]. Service Oriented Computing and Applications, 2022, 16 : 293 - 312
  • [30] A novel combined approach based on deep Autoencoder and deep classifiers for credit card fraud detection
    Fanai, Hosein
    Abbasimehr, Hossein
    [J]. EXPERT SYSTEMS WITH APPLICATIONS, 2023, 217