A novel approach for APT attack detection based on combined deep learning model

被引:2
|
作者
Cho Do Xuan
Mai Hoang Dao
机构
[1] Posts and Telecommunications Institute of Technology,Faculty of Information Technology
[2] FPT University,Information Assurance Dept
来源
关键词
Advanced persistent threat; APT attack detection; Network traffic; Abnormal behavior; Combined deep learning model;
D O I
暂无
中图分类号
学科分类号
摘要
Advanced persistent threat (APT) attack is a malicious attack type which has intentional and clear targets. This attack technique has become a challenge for information security systems of organizations, governments, and businesses. The approaches of using machine learning or deep learning algorithms to analyze signs and abnormal behaviors of network traffic for detecting and preventing APT attacks have become popular in recent years. However, the APT attack detection approach that uses behavior analysis and evaluation techniques is facing many difficulties due to the lack of typical data of attack campaigns. To handle this situation, recent studies have selected and extracted the APT attack behaviors which based on datasets are built from experimental tools. Consequently, these properties are few and difficult to obtain in practical monitoring systems. Therefore, although the experimental results show good detection, it does not bring high efficiency in practice. For above reasons, in this paper, a new method based on network traffic analysis using a combined deep learning model to detect APT attacks will be proposed. Specifically, individual deep learning networks such as multilayer perceptron (MLP), convolutional neural network (CNN), and long short-term memory (LSTM) will also be sought, built and linked into combined deep learning networks to analyze and detect signs of APT attacks in network traffic. To detect APT attack signals, the combined deep learning models are performed in two main stages including (i) extracting IP features based on flow: In this phase, we will analyze network traffic into networking flows by IP address and then use the combined deep learning models to extract IP features by network flow; (ii) classifying APT attack IPs: Based on IP features extracted in a task (i), the APT attack IPs and normal IPs will be identified and classified. The proposal of a combined deep learning model to detect APT attacks based on network traffic is a new approach, and there is no research proposed and applied yet. In the experimental section, combined deep learning models proved their superior abilities to ensure accuracy on all measurements from 93 to 98%. This is a very good result for APT attack detection based on network traffic.
引用
下载
收藏
页码:13251 / 13264
页数:13
相关论文
共 50 条
  • [31] An Explainable Deep Learning Model for Fingerprint Presentation Attack Detection
    Rai, Anuj
    Dey, Somnath
    COMPUTER VISION AND IMAGE PROCESSING, CVIP 2023, PT III, 2024, 2011 : 309 - 321
  • [32] Hybrid deep learning model for attack detection in internet of things
    H. Rekha
    M. Siddappa
    Service Oriented Computing and Applications, 2022, 16 : 293 - 312
  • [33] A novel combined approach based on deep Autoencoder and deep classifiers for credit card fraud detection
    Fanai, Hosein
    Abbasimehr, Hossein
    EXPERT SYSTEMS WITH APPLICATIONS, 2023, 217
  • [34] PulmoNet: a novel deep learning based pulmonary diseases detection model
    AbdulRahman Tosho Abdulahi
    Roseline Oluwaseun Ogundokun
    Ajiboye Raimot Adenike
    Mohd Asif Shah
    Yusuf Kola Ahmed
    BMC Medical Imaging, 24
  • [35] PulmoNet: a novel deep learning based pulmonary diseases detection model
    Abdulahi, AbdulRahman Tosho
    Ogundokun, Roseline Oluwaseun
    Adenike, Ajiboye Raimot
    Shah, Mohd Asif
    Ahmed, Yusuf Kola
    BMC MEDICAL IMAGING, 2024, 24 (01)
  • [36] A novel model based on deep learning for Pedestrian detection and Trajectory prediction
    Shi, Keke
    Zhu, Yaping
    Pan, Hong
    PROCEEDINGS OF 2019 IEEE 8TH JOINT INTERNATIONAL INFORMATION TECHNOLOGY AND ARTIFICIAL INTELLIGENCE CONFERENCE (ITAIC 2019), 2019, : 592 - 598
  • [37] A Novel Lung Nodule Detection and Recognition Model Based on Deep Learning
    Lu, Zhaolin
    Liu, Fei
    Wang, Lvting
    Xu, Liyu
    Liu, Xiangqun
    IEEE Access, 2024, 12 : 155990 - 156002
  • [38] Reinforcement Learning Based Approach for Flip Attack Detection
    Liu, Hanxiao
    Li, Yuchao
    Martensson, Jonas
    Xie, Lihua
    Johansson, Karl Henrik
    2020 59TH IEEE CONFERENCE ON DECISION AND CONTROL (CDC), 2020, : 3212 - 3217
  • [39] Data integrity attack detection in smart grid: A deep learning approach
    Basodi S.
    Tan S.
    Song W.
    Pan Y.
    International Journal of Security and Networks, 2020, 15 (01) : 15 - 24
  • [40] A Deep Learning Based Framework for Cloud Masquerade Attack Detection
    Xu, Shuting
    Lai, Shuhua
    Li, Yongjian
    2018 IEEE 37TH INTERNATIONAL PERFORMANCE COMPUTING AND COMMUNICATIONS CONFERENCE (IPCCC), 2018,