APT Detector: Detect and Identify APT Malware Based on Deep Learning Framework

Binhui Tang, Jialin Yang, Xin Li, Yang Cao, Jie Wang · 2023

Advanced persistent threat (APT) attacks use sophisticated attack techniques and covert command and control (C&C) channels to conduct long-term sustained cyber attacks on specific targets as unobtrusively as possible. Over the past ten years, APT attacks have become increasingly frequent, gradually taking on a highly organized, nationalized, and militarized nature. Because APT malware is highly covert, has a long latency period, and presents characteristics such as diversification, high frequency, and sophistication. In the face of existing detection methods, it is easy for attackers to bypass detection by customizing malware and adapting and configuring tools to the target network. The continuous improvement of network technologies and tools and the complex and diverse attack process make it very difficult to detect unknown APT malware. To address the problems, this paper takes APT malware as the detection object and collects 6777 malware from 20 types of APT attack actors. Through the improved Convolutional Neural network (CNN) model combined with an attention mechanism to complete automatic extraction and weighting of static malware features, which can detect and discover APT malware. Meanwhile, the recognition effect for APT malware is better than other existing methods, which realize the attribution of APT attack groups.

Read the paper · More papers on PaperTik