An Improved Predictive Model for Early Detection of Advanced Persistent Threat Attacks on High Value Networks
Open AccessHackers have stolen enormous amounts of intellectual property data from high value networks, resulting in $300 billion of intellectual property stolen each year. Cyberattacks have increased significantly in the past several years with the exponential growth in internet usage and cloud-based storage. Of these attacks, the most impactful is the Advanced Persistent Threat (APT).. The praxis proposes a 2-stage classification/detection model to improve the detection of APT attacks on high value networks using K Nearest Neighbor (KNN) —a supervised matching learning (ML) algorithm for the first stage classification, followed by an unsupervised ML model—the isolation forest for the second stage detection. This praxis uses a more realistic dataset representing actual network traffic with both benign and threat information—CICIDS2017 in Packet Capture (PCAP) files which contain packet data including various protocols, attack vectors, IP addresses of source and destination, and port numbers. In addition, the CICIDS2017 is augmented with Contagio’s real-time APT datasets to create a near real-time true APT embedded network traffic dataset. Contagio is a collection of historic malware samples, observations, threats and analysis that’s downloadable on the contagion website. The semi-synthetic dataset enables more realistic performance measurements from the various ML / Deep Learning (DL) algorithms. The performance metrics collected from the model show improved detection of anomalies and APT attacks. The improvement in accuracy and precision for the anomaly detection range from 5% up to 40%.
- All rights reserved
Notice to Authors
If you are the author of this work and you have any questions about the information on this page, please use the Contact form to get in touch with us.