A hybrid ensemble machine learning model for detecting APT attacks based on network behavior anomaly detection

Author:

Saini Neeraj1,Bhat Kasaragod Vivekananda2,Prakasha Krishna3,Das Ashok Kumar4ORCID

Affiliation:

1. Department of Computer Science & Engineering Manipal Institute of Technology, Manipal Academy of Higher Education Manipal Karnataka India

2. Department of Computer Science & Engineering and Centre for Cryptography Manipal Institute of Technology, Manipal Academy of Higher Education Manipal Karnataka India

3. Department of Information & Communication Technology Manipal Institute of Technology, Manipal Academy of Higher Education Manipal Karnataka India

4. Center for Security, Theory and Algorithmic Research International Institute of Information Technology Hyderabad India

Abstract

SummaryA persistent, targeted cyber attack is called an advanced persistent threat (APT) attack. The attack is mainly launched to gain sensitive information, take over the system, and for financial gain, which creates nowadays more hurdles and challenges for the organization in preventing, detecting, and recovering from such attacks. Due to the nature of APT attacks, it is difficult to detect them quickly. Therefore machine learning techniques come into these research areas. This study uses deep and machine learning models such as random forest, decision tree, convolutional neural network, multilayer perceptron and so forth to categorize and effectively detect APT attacks by utilizing publicly accessible datasets. The datasets used in this study are CSE‐CIC‐IDS2018, CIC‐IDS2017, NSL‐KDD, and UNSW‐NB15. This study proposes the hybrid ensemble machine learning model, a mixed approach of random forest and XGBoost classifiers. It has obtained the maximum prediction accuracy of 98.92%, 99.91%, 99.24%, and 97.11% for datasets CSE‐CIC‐IDS2018, CIC‐IDS2017, NSL‐KDD, and UNSW‐NB15, with a false positive rate of 0.52%, 0.12%, 0.62%, and 5.29% respectively. These results are compared to other closely related recent studies in the literature. Our experiment's findings show that our model has performed significantly better for all datasets.

Publisher

Wiley

Subject

Computational Theory and Mathematics,Computer Networks and Communications,Computer Science Applications,Theoretical Computer Science,Software

Reference56 articles.

1. Advanced persistent threat (APT) attacks.https://www.cynet.com/advanced‐persistent‐threat‐apt‐attacks/

2. Special Issue on Advanced Persistent Threat

3. A Survey on Advanced Persistent Threats: Techniques, Solutions, Challenges, and Research Opportunities

4. BurtJ.McAfee finds years‐long attack by Chinese‐linked APT groups.https://www.esecurityplanet.com/threats/mcafee‐finds‐years‐long‐attack‐by‐chinese‐apt‐groups

5. Advanced Persistent Threat Detection: A Survey

Cited by 1 articles. 订阅此论文施引文献 订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3