conference-paper

APT Detection Based on RSDN Framework

Research footprint

At a glance

Citations
3
References
18
Comments
0
Paper overview

Öz

Advanced Persistent Threats (APTs) represent sophisticated cyberattacks orchestrated by highly skilled groups, often with support from nation-states or criminal entities. These attacks are meticulously planned and executed against strategic objectives, exhibiting prolonged duration. Identifying and forecasting APTs accurately remains challenging. In this paper, we propose an integrated framework of machine learning models on a big data, referred to as the Random Forest, Support Vector Machine, and Deep Neural Network (RSDN) System. The scheme collects network traffic data and uploading files. Subsequently, the data undergo processing using Resilient Distributed Datasets, employing one-hot encoding techniques, and splitting the datasets into training and testing sets within the spark big data platform. Moreover, we evaluate three different models within the RSDN system and integrate them into scenarios to identify the most effective scheme for detecting APTs. The experimental evaluation demonstrates the effectiveness of our approach in combating APTs, providing valuable insights for cybersecurity practitioners and achieving remarkable accuracy rates of 95% to 98% in their initial phase.

Record transparency

Publication details

DOI
10.1109/iceiec61773.2024.10561650
OpenAlex
W4399852516
Document type
conference-paper
Language
EN
Last metadata update
Community

Comments

Oturum Açın to join the discussion.

  1. No comments yet. Start the discussion.