APT Detection Based on RSDN Framework

Mahmoud Basi, Tao Shang, Jiayu Liu, Yatong Jiang, Weiwei Wang · 2024

Advanced Persistent Threats (APTs) represent sophisticated cyberattacks orchestrated by highly skilled groups, often with support from nation-states or criminal entities. These attacks are meticulously planned and executed against strategic objectives, exhibiting prolonged duration. Identifying and forecasting APTs accurately remains challenging. In this paper, we propose an integrated framework of machine learning models on a big data, referred to as the Random Forest, Support Vector Machine, and Deep Neural Network (RSDN) System. The scheme collects network traffic data and uploading files. Subsequently, the data undergo processing using Resilient Distributed Datasets, employing one-hot encoding techniques, and splitting the datasets into training and testing sets within the spark big data platform. Moreover, we evaluate three different models within the RSDN system and integrate them into scenarios to identify the most effective scheme for detecting APTs. The experimental evaluation demonstrates the effectiveness of our approach in combating APTs, providing valuable insights for cybersecurity practitioners and achieving remarkable accuracy rates of 95% to 98% in their initial phase.

Read the paper · More papers on PaperTik