Advanced persistent threat detection based on characteristics of communications

Zhen DAI,Guang CHENG
DOI: https://doi.org/10.3778/j.issn.1002-8331.1703-0552
2017-01-01
Abstract:Advanced Persistent Threat(APT)is a serious threat to the world, APT detection has become the key point of network security protection. Due to the complexity of APT, the traditional detection technology cannot perform well. An APT detection method is proposed by using APT communication features extracted from international security company reports. In order to improve the detection effect of this method, an algorithm for double feature matching is put forward. The initial feature matching method uses bloom filter to filter out some messages quickly, and then the exact matching method is set up to determine whether it is APT malicious traffic. The experimental results show that the method has higher detection rate and fewer false positives.
What problem does this paper attempt to address?