APT Attack Detection Using Packet Flow and Optimized Ensemble Machine Learning with Low Time Complexity

Kalaivani Selvaraj, Manmeet Mahinderjit Singh · 2024

Advanced Persistent Threat (APT) attacks steal sensitive data from targeted organizations and remain undetected by the Security Operation Center (SOC). Researchers develop automated detection of APT attacks. For efficient detection of APT attacks need, extensive data and high resources. Moreover, Deep Learning algorithms need huge labelled variables for APT attack detection. This paper uses data flow parameters such as Flow Packets, Flow IAT (Inter Arrival Time) Mean and Fwd IAT Total for APT attack detection. The Machine learning (ML) algorithms such as SVM, LR, BNN, and Bayesian Optimized Ensemble learning model are Bayesian optimized and used for APT attack detection. This study examines each ML algorithm's performance using accuracy, precision, recall, and F1-score metrics. The Bayesian Optimized Ensemble learning model performs better than traditional methods and has a high accuracy of about 97.24%, F1-score of 0.9845, and precision and recall of 0.985 and 0.9845, respectively.

Read the paper · More papers on PaperTik