• Home
  • Search
  • A novel approach for APT attack detection based on combined deep learning model
  • Cite Icon76
  • https://doi.org/10.1007/s00521-021-05952-5Copy DOI Icon

A novel approach for APT attack detection based on combined deep learning model

Show More
  • Abstract
  • Literature Map
  • References
  • Citations
  • Similar Papers
Abstract

Advanced persistent threat (APT) attack is a malicious attack type which has intentional and clear targets. This attack technique has become a challenge for information security systems of organizations, governments, and businesses. The approaches of using machine learning or deep learning algorithms to analyze signs and abnormal behaviors of network traffic for detecting and preventing APT attacks have become popular in recent years. However, the APT attack detection approach that uses behavior analysis and evaluation techniques is facing many difficulties due to the lack of typical data of attack campaigns. To handle this situation, recent studies have selected and extracted the APT attack behaviors which based on datasets are built from experimental tools. Consequently, these properties are few and difficult to obtain in practical monitoring systems. Therefore, although the experimental results show good detection, it does not bring high efficiency in practice. For above reasons, in this paper, a new method based on network traffic analysis using a combined deep learning model to detect APT attacks will be proposed. Specifically, individual deep learning networks such as multilayer perceptron (MLP), convolutional neural network (CNN), and long short-term memory (LSTM) will also be sought, built and linked into combined deep learning networks to analyze and detect signs of APT attacks in network traffic. To detect APT attack signals, the combined deep learning models are performed in two main stages including (i) extracting IP features based on flow: In this phase, we will analyze network traffic into networking flows by IP address and then use the combined deep learning models to extract IP features by network flow; (ii) classifying APT attack IPs: Based on IP features extracted in a task (i), the APT attack IPs and normal IPs will be identified and classified. The proposal of a combined deep learning model to detect APT attacks based on network traffic is a new approach, and there is no research proposed and applied yet. In the experimental section, combined deep learning models proved their superior abilities to ensure accuracy on all measurements from 93 to 98%. This is a very good result for APT attack detection based on network traffic.

Similar Papers
  • Research Article
  • Citations55

APT attack detection based on flow network analysis techniques using deep learning

  • Jul 07, 2020
  • Journal of Intelligent & Fuzzy Systems
  • Cho Do Xuan +2
  • Conference Article
  • Citations6

Research on Prevention Solution of Advanced Persistent Threat

  • Jan 01, 2014
  • Xiaomei Liu
  • Research Article
  • Citations18

A new framework for APT attack detection based on network traffic

  • Mar 09, 2023
  • Journal of Intelligent & Fuzzy Systems
  • Hoa Cuong Nguyen +3
  • Book Chapter
  • Citations5

Evolution of Advanced Persistent Threat (APT) Attacks and Actors

  • Jan 01, 2019
  • Chia-Mei Chen +2
  • Research Article
  • Citations9

A Hybrid Intelligent Approach to Attribute Advanced Persistent Threat Organization Using PSO-MSVM Algorithm

  • Dec 01, 2022
  • IEEE Transactions on Network and Service Management
  • Yangyang Mei +4
  • Conference Article
  • Citations5

APT Attack Detection Method Based on Traffic Log Features

  • Sep 23, 2022
  • Xingjie Huang +5
  • Research Article
  • Citations1

APT Attack Detection Method Based on Traceability Graph

  • Jun 01, 2024
  • Journal of Intelligence and Knowledge Engineering
  • Yihan Yin +2
  • Conference Article
  • Citations14

Functions-based CFG Embedding for Malware Homology Analysis

  • Apr 01, 2019
  • Jieran Liu +2
  • Research Article
  • Citations128

Conan: A Practical Real-Time APT Detection System With High Accuracy and Efficiency

  • Feb 04, 2020
  • IEEE Transactions on Dependable and Secure Computing
  • Chunlin Xiong +8
  • Book Chapter
  • Citations31

Proposed Approach for Targeted Attacks Detection

  • Dec 29, 2015
  • Ibrahim Ghafir +1
  • Book Chapter
  • Citations1

Attacks on Android-Based Smartphones and Impact of Vendor Customization on Android OS Security

  • Jan 01, 2020
  • Sudesh Kumar +2
  • Conference Article
  • Citations20

Ctracer: Uncover C&C in Advanced Persistent Threats Based on Scalable Framework for Enterprise Log Data

  • Jun 01, 2015
  • Kai-Fong Hong +3
  • Research Article
  • Citations8

Fuzzy inference based feature selection and optimized deep learning for Advanced Persistent Threat attack detection

  • Dec 25, 2023
  • International Journal of Adaptive Control and Signal Processing
  • Anil Kumar +2
  • Conference Article
  • Citations18

Host in Danger? Detecting Network Intrusions from Authentication Logs

  • Oct 01, 2019
  • Haibo Bian +5
  • Research Article
  • Citations20

Detecting mobile advanced persistent threats based on large-scale DNS logs

  • Jun 12, 2020
  • Computers & Security
  • Zongyuan Xiang +2
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.