A Novel Approach for APT Detection Based on Ensemble Learning Model
Nguyen Hoa Cuong, Cho Do Xuan, Vu Thanh Long, Nguyen Duy Dat, Tran Quang Anh ABSTRACT
In recent years, the number and complexity of advanced persistent threat (APT) attacks have significantly increased, posing major challenges for organizations in effectively detecting and mitigating these threats. Although various APT detection methods have been developed, current approaches still face limitations, such as poor generalization leading to high false alarm rates. To address these challenges, this article proposes a novel ensemble learning model called MCG, based on the combination of three main components: multilayer perceptron (MLP), correlated recursion (CR) layer, and graph attention network (GAT). The MLP component extracts flow features from network traffic, the CR layer constructs the IP information network by grouping and linking network behaviors, and finally, the GAT layer analyzes relationships between IPs through an attention mechanism. The MCG model proposed in this article has demonstrated superior performance in APT detection by effectively leveraging the strengths of each component, enabling more accurate identification of abnormal behaviors and reducing false alarms. The experimental results, presented in Section 4.4, show that the MCG model significantly improves accuracy and outperforms traditional methods. This demonstrates that the proposed model not only makes significant theoretical contributions but also offers practical value, providing a more reliable and effective solution for early detection and warning of APT attacks.