Detecting Lateral Movement in Advanced Persistent Threats Based on Remote Desktop Protocol

Zainab Obaid Aljadani, Khalid Alsubhi · 2024

Advanced Persistent Threats (APTs) are one of the most perilous forms of cyberattacks, partly because they concentrate on certain, high-value targets. A pivotal stage in these assaults is lateral movement, wherein attackers traverse compromised systems to acquire additional control and access sensitive information. This study concentrates on identifying lateral movement in Advanced Persistent Threats (APTs), particularly via the Remote Desktop Protocol (RDP) as a principal attack vector, especially in 2019 with Corona pandemic increasing the work online It has become necessary to protect the network, its accessories, and the devices connected to it to ensure protected access and prevent hacking. Deep learning models were utilized to detect malicious behavior with event logs LANL dataset, and the model's efficacy was assessed using conventional metrics like F1-score, precision, recall, and accuracy. We have attained a performance level of 99.98% with CNN and RNN.

Read the paper · More papers on PaperTik