APT Attack Detection Method Based on Traffic Log Features
Xingjie Huang, Beibei Su, Ru Zhang, Feiyu Chen, Jinmeng Zhao, Yating Gao · 2022
APT (Advanced Persistent Threat) attack can generally hide the attack process by evading the detection of the IDS system. This paper proposes a detection model for C2 stage network behavior in APT attacks using anonymized datasets. For C2 domain name access records, a number of features based on DNS behavior rules are proposed, and these features are fused with traffic features. Experiments are carried out by combining the data collected in a large-scale organization with the simulation data. The experiments result shows that the method in this paper has the ability to detect APT attacks under large data, and can detect suspected infected hosts.