A novel approach for APT attack detection based on combined deep learning model

被引:2
|
作者
Cho Do Xuan
Mai Hoang Dao
机构
[1] Posts and Telecommunications Institute of Technology,Faculty of Information Technology
[2] FPT University,Information Assurance Dept
来源
关键词
Advanced persistent threat; APT attack detection; Network traffic; Abnormal behavior; Combined deep learning model;
D O I
暂无
中图分类号
学科分类号
摘要
Advanced persistent threat (APT) attack is a malicious attack type which has intentional and clear targets. This attack technique has become a challenge for information security systems of organizations, governments, and businesses. The approaches of using machine learning or deep learning algorithms to analyze signs and abnormal behaviors of network traffic for detecting and preventing APT attacks have become popular in recent years. However, the APT attack detection approach that uses behavior analysis and evaluation techniques is facing many difficulties due to the lack of typical data of attack campaigns. To handle this situation, recent studies have selected and extracted the APT attack behaviors which based on datasets are built from experimental tools. Consequently, these properties are few and difficult to obtain in practical monitoring systems. Therefore, although the experimental results show good detection, it does not bring high efficiency in practice. For above reasons, in this paper, a new method based on network traffic analysis using a combined deep learning model to detect APT attacks will be proposed. Specifically, individual deep learning networks such as multilayer perceptron (MLP), convolutional neural network (CNN), and long short-term memory (LSTM) will also be sought, built and linked into combined deep learning networks to analyze and detect signs of APT attacks in network traffic. To detect APT attack signals, the combined deep learning models are performed in two main stages including (i) extracting IP features based on flow: In this phase, we will analyze network traffic into networking flows by IP address and then use the combined deep learning models to extract IP features by network flow; (ii) classifying APT attack IPs: Based on IP features extracted in a task (i), the APT attack IPs and normal IPs will be identified and classified. The proposal of a combined deep learning model to detect APT attacks based on network traffic is a new approach, and there is no research proposed and applied yet. In the experimental section, combined deep learning models proved their superior abilities to ensure accuracy on all measurements from 93 to 98%. This is a very good result for APT attack detection based on network traffic.
引用
下载
收藏
页码:13251 / 13264
页数:13
相关论文
共 50 条
  • [41] Unconstrained face detection: a Deep learning and Machine learning combined approach
    Dattatray D. Sawat
    Ravindra S. Hegadi
    CSI Transactions on ICT, 2017, 5 (2) : 195 - 199
  • [42] Detection Mechanism of FDI attack feature based on Deep Learning
    Pu, Qiang
    Qin, Hao
    Han, Hu
    Xia, Yuanyi
    Li, Zhihao
    Xie, Kejun
    Wang, Wenqing
    2018 IEEE SMARTWORLD, UBIQUITOUS INTELLIGENCE & COMPUTING, ADVANCED & TRUSTED COMPUTING, SCALABLE COMPUTING & COMMUNICATIONS, CLOUD & BIG DATA COMPUTING, INTERNET OF PEOPLE AND SMART CITY INNOVATION (SMARTWORLD/SCALCOM/UIC/ATC/CBDCOM/IOP/SCI), 2018, : 1761 - 1765
  • [43] DDoS ATTACK DETECTION METHODS BASED ON DEEP LEARNING IN HEALTHCARE
    Wang, Chaoying
    Zhu, Ting
    JOURNAL OF MECHANICS IN MEDICINE AND BIOLOGY, 2023, 23 (04)
  • [44] APT Attack Detection Based on Graph Convolutional Neural Networks
    Ren, Weiwu
    Song, Xintong
    Hong, Yu
    Lei, Ying
    Yao, Jinyu
    Du, Yazhou
    Li, Wenjuan
    INTERNATIONAL JOURNAL OF COMPUTATIONAL INTELLIGENCE SYSTEMS, 2023, 16 (01)
  • [45] A new framework for APT attack detection based on network traffic
    Hoa Cuong Nguyen
    Cho Do Xuan
    Long Thanh Nguyen
    Hoa Dinh Nguyen
    JOURNAL OF INTELLIGENT & FUZZY SYSTEMS, 2023, 44 (03) : 3459 - 3474
  • [46] APT Attack Detection Based on Graph Convolutional Neural Networks
    Weiwu Ren
    Xintong Song
    Yu Hong
    Ying Lei
    Jinyu Yao
    Yazhou Du
    Wenjuan Li
    International Journal of Computational Intelligence Systems, 16
  • [47] Survey of attack and detection based on the full life cycle of APT
    Wang, Zhiwei
    He, Xijie
    Yi, Xin
    Li, Ziyang
    Cao, Xudong
    Yin, Tao
    Li, Shuhao
    Fu, Anmin
    Zhang, Yuqing
    Tongxin Xuebao/Journal on Communications, 2024, 45 (09): : 206 - 228
  • [48] RP-NBSR: A Novel Network Attack Detection Model Based on Machine Learning
    Shen, Zihao
    Wang, Hui
    Liu, Kun
    Liu, Peiqian
    Ba, Menglong
    Zhao, MengYao
    COMPUTER SYSTEMS SCIENCE AND ENGINEERING, 2021, 37 (01): : 121 - 133
  • [49] Model- Based Deep Learning for Cyber-Attack Detection in Electric Drive Systems
    Abou Jawdeh, Shaya
    Choi, Seungdeog
    Liu, Chung-Hung
    2022 IEEE APPLIED POWER ELECTRONICS CONFERENCE AND EXPOSITION, APEC, 2022, : 567 - 573
  • [50] DeepTaskAPT: Insider APT detection using Task-tree based Deep Learning
    Mamun, Mohammad
    Shi, Kevin
    2021 IEEE 20TH INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (TRUSTCOM 2021), 2021, : 693 - 700