Detection of advanced persistent threat: A genetic programming approach

被引:0
作者
Al Mamun, Abdullah [1 ]
Al-Sahaf, Harith [1 ,2 ]
Welch, Ian [1 ]
Mansoori, Masood [1 ]
Camtepe, Seyit [3 ]
机构
[1] Victoria Univ Wellington, Sch Engn & Comp Sci, Wellington, New Zealand
[2] Al Zahraa Univ Women, Coll Informat Technol Engn, Karbala, Iraq
[3] CSIRO, Data61, Eveleigh, Australia
关键词
APT; Advanced Persistent Threat; Evolutionary computation; Genetic Programming; Machine Learning; CKC; INTRUSION DETECTION; ANOMALY DETECTION; NETWORKS; SYSTEM;
D O I
10.1016/j.asoc.2024.112447
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Advanced Persistent Threats (APTs) are an intimidating class of cyberattacks known for their persistence, sophistication, and targeted nature. These attacks, coordinated by highly motivated adversaries, pose a grave risk to organizations and individuals, often operating stealthily and evading detection. While existing research primarily focuses on applying Machine Learning (ML) methods to analyze network traffic data for APT detection, this article introduces a novel approach that utilizes Genetic Programming (GP). The proposed method not only detects APT attacks but also identifies their specific life cycle stages through the evolutionary capabilities of GP. Its effectiveness lies in its ability to excel in detecting intricate patterns, even within classes with a limited number of instances, a feat that is often challenging for traditional ML techniques. The method involves evolving and optimizing its models to effectively learn and adapt to complex APT behaviors. Experimentation with a publicly available dataset showcases the efficacy of the proposed method across diverse APT stages. The results demonstrate that the proposed method, GPC, achieves a 3.71% improvement in balanced accuracy compared to the best-performing model from related works. Moreover, a thorough analysis of the best-evolved GP model uncovers valuable insights about identified features and significant patterns. This research advances the APT detection paradigm by leveraging GP's capabilities, providing afresh and effective perspective on countering these persistent threats.
引用
收藏
页数:14
相关论文
共 72 条
  • [21] Crosbie M., 1995, P WORK NOT AAAI S GE, P1
  • [22] Systems for Detecting Advanced Persistent Threats a Development Roadmap using Intelligent Data Analysis
    de Vries, Johannes
    Hoogstraaten, Hans
    van den Berg, Jan
    Daskapan, Semir
    [J]. 2012 ASE INTERNATIONAL CONFERENCE ON CYBER SECURITY (CYBERSECURITY), 2012, : 54 - 61
  • [23] Debatty T, 2018, 2018 INTERNATIONAL CONFERENCE ON MILITARY COMMUNICATIONS AND INFORMATION SYSTEMS (ICMCIS)
  • [24] A Method of Monitoring and Detecting APT Attacks Based on Unknown Domains
    Do Xuan Cho
    Ha Hai Nam
    [J]. PROCEEDINGS OF THE 13TH INTERNATIONAL SYMPOSIUM INTELLIGENT SYSTEMS 2018 (INTELS'18), 2019, 150 : 316 - 323
  • [25] Detecting zero-day attacks using context-aware anomaly detection at the application-layer
    Duessel, Patrick
    Gehl, Christian
    Flegel, Ulrich
    Dietrich, Sven
    Meier, Michael
    [J]. INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2017, 16 (05) : 475 - 490
  • [26] Evolutionary Deep Learning: A Genetic Programming Approach to Image Classification
    Evans, Benjamin
    Al-Sahaf, Harith
    Xue, Bing
    Zhang, Mengjie
    [J]. 2018 IEEE CONGRESS ON EVOLUTIONARY COMPUTATION (CEC), 2018, : 1538 - 1545
  • [27] Fraley JB, 2017, IEEE SOUTHEASTCON
  • [28] Combating advanced persistent threats: From network event correlation to incident detection
    Friedberg, Ivo
    Skopik, Florian
    Settanni, Giuseppe
    Fiedler, Roman
    [J]. COMPUTERS & SECURITY, 2015, 48 : 35 - 57
  • [29] Stochastic Semantic-Based Multi-objective Genetic Programming Optimisation for Classification of Imbalanced Data
    Galvan-Lopez, Edgar
    Vazquez-Mendoza, Lucia
    Trujillo, Leonardo
    [J]. ADVANCES IN SOFT COMPUTING, MICAI 2016, PT II, 2017, 10062 : 261 - 272
  • [30] Detection of advanced persistent threat using machine-learning correlation analysis
    Ghafir, Ibrahim
    Hammoudeh, Mohammad
    Prenosil, Vaclav
    Han, Liangxiu
    Hegarty, Robert
    Rabie, Khaled
    Aparicio-Navarro, Francisco J.
    [J]. FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2018, 89 : 349 - 359