Limitations of Advanced Persistent Threat Datasets: Insights for Cybersecurity Research

Abdullah Al Mamun, Harith Al-Sahaf, Ian S. Welch, Marinho Pilla Barcellos, Seyit Ahmet Camtepe · 2024

Advanced Persistent Threats (APTs) pose a significant and ever-evolving challenge to cybersecurity, necessitating the development of robust and effective detection mechanisms. Central to this endeavor is the availability of high-quality datasets that accurately capture the complexities and nuances of APT activities. This paper presents a comprehensive analysis of four publicly available APT datasets, focusing on their strengths, limitations, and implications for cybersecurity research. A meticulous examination shows that none of these datasets can be used directly without extensive preprocessing. The strengths and limitations of each dataset are explained, enabling researchers to make informed decisions regarding their selection and application. Additionally, common challenges encountered in APT dataset analysis are identified, and data preprocessing techniques tailored to effectively apply machine learning algorithms are proposed. Leveraging these datasets, initial results demonstrating balanced accuracy across various standard machine learning classifiers are provided. We have made our code publicly available to promote reproducibility and further research. By shedding light on the intricacies of APT dataset management and utilization, this study contributes to the broader discourse on enhancing the detection and mitigation of these sophisticated threats.

Read the paper · More papers on PaperTik