Detection of Advanced Persistent Threat based on Kill Chain Node Mapping and LSTM

Juefu Li · Proceedings of the 2021 5th International Conference on Electronic Information Technology and Computer Engineering · 2021

The advanced persistent threat (APT) has caused serious damage to the core information infrastructure of many governments and organizations. How to correlatively analyze the massive logs generated by various security devices become a key point to effectively detect such new type of attack. This paper analyzes features of the APT attack and proposes a new APT detection method based on the extended cyber kill chain and the long and short-term memory network which can extensively correlate network behaviors. Furtherly, the idea of the proposed method provides a new direction for the application and practice of detecting complex cyber attacks.

Read the paper · More papers on PaperTik