An Ensemble Stacked Boosting Framework for Advanced Persistent Threat (APT) Detection in the Industrial Internet of Things(IIoT)
G. Kirubavathi, C Guruakshya. · 2024
The IIoT has changed the face of different industries through better connectivity, fast data generation, and efficiency in operation. However, these connected systems become more prone to Advanced Persistent Threats-silent, long-term cyberattacks that can compromise security without any form of detection. As such, this study introduces a new ensemble stacking boosting framework tailored toward APT detection in IIoT environments. The proposed system exploits Linear Discriminant Analysis as a metaclassifier, combining various machine learning models including Gradient Boost, XGBoost, LightGBM, and Random Forest in order to boost the detection accuracy. Tested on the CICAPT-IIoT dataset with both malicious and benign network traffic, our approach produced superior performance with an accuracy and precision of 0.94, a recall of 0.91 and an F-measure of 0.92. These results show that the model significantly outperforms existing methods, offering a scalable and high-accuracy solution to APT detection in IIoT systems and thereby contributes toward a more secure IIoT landscape.