A novel approach for APT attack detection based on an advanced computing

被引:2
|
作者
Xuan, Cho Do [1 ]
Nguyen, Tung Thanh [2 ]
机构
[1] Posts & Telecommun Inst Technol, Fac Informat Secur, Hanoi, Vietnam
[2] Minist Informat & Commun, Natl Inst Digital Technol & Digital Transformat, Hanoi, Vietnam
来源
SCIENTIFIC REPORTS | 2024年 / 14卷 / 01期
关键词
BiLSTM; Attention; Dynamic graph convolutional neural network; APT attack detection; ADVANCED PERSISTENT THREATS; NETWORK;
D O I
10.1038/s41598-024-72957-0
中图分类号
O [数理科学和化学]; P [天文学、地球科学]; Q [生物科学]; N [自然科学总论];
学科分类号
07 ; 0710 ; 09 ;
摘要
To enhance the effectiveness of the Advanced Persistent Threat (APT) detection process, this research proposes a new approach to build and analyze the behavior profiles of APT attacks in network traffic. To achieve this goal, this study carries out two main objectives, including (i) building the behavior profile of APT IP in network traffic using a new intelligent computation method; (ii) analyzing and evaluating the behavior profile of APT IP based on a deep graph network. Specifically, to build the behavior profile of APT IP, this article describes using a combination of two different data mining methods: Bidirectional Long Short-Term Memory (Bi) and Attention (A). Based on the obtained behavior profile, the Dynamic Graph Convolutional Neural Network (DGCNN) is proposed to extract the characteristics of APT IP and classify them. With the flexible combination of different components in the model, the important information and behavior of APT attacks are demonstrated, not only enhancing the accuracy of detecting attack campaigns but also reducing false predictions. The experimental results in the paper show that the method proposed in this study has brought better results than other approaches on all measurements. In particular, the accuracy of APT attack prediction results (Precision) reached from 84 to 91%, higher than other studies of over 7%. These experimental results have proven that the proposed BiADG model for detecting APT attacks in this study is proper and reasonable. In addition, those experimental results have not only proven the effectiveness and superiority of the proposed method in detecting APT attacks but have also opened up a new approach for other cyber-attack detections such as distributed denial of service, botnets, malware, phishing, etc.
引用
收藏
页数:19
相关论文
共 50 条
  • [1] A novel approach for APT attack detection based on combined deep learning model
    Cho Do Xuan
    Mai Hoang Dao
    NEURAL COMPUTING & APPLICATIONS, 2021, 33 (20): : 13251 - 13264
  • [2] A novel approach for APT attack detection based on combined deep learning model
    Cho Do Xuan
    Mai Hoang Dao
    Neural Computing and Applications, 2021, 33 : 13251 - 13264
  • [3] A novel approach for APT attack detection based on feature intelligent extraction and representation learning
    Do Xuan, Cho
    Cuong, Nguyen Hoa
    PLOS ONE, 2024, 19 (06):
  • [4] A novel approach for software vulnerability detection based on advanced computing
    Cho Do Xuan
    Huynh Nhat Anh
    Neural Computing and Applications, 2025, 37 (6) : 5121 - 5139
  • [5] Ontology based APT Attack Behavior Analysis in Cloud Computing
    Choi, Junho
    Choi, Chang
    Lynn, Htet Myet
    Kim, Pankoo
    2015 10TH INTERNATIONAL CONFERENCE ON BROADBAND AND WIRELESS COMPUTING, COMMUNICATION AND APPLICATIONS (BWCCA 2015), 2015, : 375 - 379
  • [6] A Novel Approach for APT Detection Based on Ensemble Learning Model
    Cuong, Nguyen Hoa
    Xuan, Cho Do
    Long, Vu Thanh
    Dat, Nguyen Duy
    Anh, Tran Quang
    STATISTICAL ANALYSIS AND DATA MINING, 2025, 18 (01)
  • [7] The APT Detection Method based on Attack Tree for SDN
    Jia Shan-Shan
    Xu Ya-Bin
    ICCSP 2018: PROCEEDINGS OF THE 2ND INTERNATIONAL CONFERENCE ON CRYPTOGRAPHY, SECURITY AND PRIVACY, 2018, : 116 - 121
  • [8] An APT Attack Detection Method Based on eBPF and Transformer
    Qiu, Rixuan
    Luo, Hao
    Jing, Sitong
    Li, Xinxiu
    Li, Yuancheng
    International Journal of Network Security, 2024, 26 (06) : 964 - 972
  • [9] A novel intelligent cognitive computing-based APT malware detection for Endpoint systems
    Do Xuan, Cho
    Huong, D. T.
    Nguyen, Toan
    JOURNAL OF INTELLIGENT & FUZZY SYSTEMS, 2022, 43 (03) : 3527 - 3547
  • [10] APT Attack Detection Based on Graph Convolutional Neural Networks
    Ren, Weiwu
    Song, Xintong
    Hong, Yu
    Lei, Ying
    Yao, Jinyu
    Du, Yazhou
    Li, Wenjuan
    INTERNATIONAL JOURNAL OF COMPUTATIONAL INTELLIGENCE SYSTEMS, 2023, 16 (01)