Detecting Apt Attacks Using an Extended Sequence-Based Learning Approach

Hao Yue,Tong Li,Di Wu,Runzi Zhang,Zhen Yang
DOI: https://doi.org/10.2139/ssrn.4238362
2022-01-01
SSRN Electronic Journal
Abstract:Advanced persistent threat (APT) disintegrates the security fortress of enterprises and becomes a significant threat to network security. Studies in recent years have focused on detecting APT attacks by matching typical tactics, techniques, and procedures (TTPs) that are associated with APT attacks. However, the high-level intention of APT attacks has not been taken into account yet, which we believe is essential for precisely detecting APT attacks. In this study, we propose a sequence-based learning approach (SLAII) for attack detection, which systematically integrates heterogeneous security relevant data and identifies attack intent. Specifically, we first investigate various data sources of attack detection and establish a dedicated network event ontology. A provenance graph is constructed from heterogeneous data integrated by the ontology to ensure data homogeneity. Secondly, we incorporate security knowledge from industrial domain experts to analyze attack intention, based on which we identify and leverage features that are strongly correlated with APT attacks. We evaluate SLAII through 10 APT attacks in realistic environments. It detects attacks with an average of 93.05% precision, 98.12% recall, and 95.36% F1-score. The results show that we provide an effective attack detection method for cybersecurity analysts.
What problem does this paper attempt to address?