arrow
Return

Two statistical traffic features for certain APT group identification

delete2022-06-01
delete4
PRE
AI
J
Jianyi Liu
刘莹 cover
刘莹 (Ying Liu)
J
Jingwen Li
W
Wenxin Sun
J
Jie Cheng
R
Ru Zhang *
X
Xingjie Huang
P
Pang Jin
DOI:10.1016/j.jisa.2022.103207delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Advanced Persistent Threat (APT) attack, which refers to the continuous and effective attack activities carried out by a group on a specific object, has become the major threats of highly protected networks. The attack traffics generated by a certain APT group, have a high similar distribution, especially in the command and control (C&C) stage. This paper analyzes the DNS and TCP traffic of a certain APT group's attack, and constructs two new features, C2Load_fluct (response packet load fluctuation) and Bad_rate (bad packet rate), which can be used to identify APT group. Experimental results show that the F1-score can reach above 0.98 and 0.94 respectively on the two datasets, which proves that the two new features are effective for APT group identification.
Keywords:
APT attack
Bad_rate
C2Load_fluct
APT group identification

Journal

Journal of Information Security and Applications cover
Journal of Information Security and Applications
IF:
3.7
Papers:
1.9K
Citations:
4.9K

Organization

B
beijing university of posts & telecommunications
Scholars:
1.4W
Papers: 1.2W
Citations: 9
S
State Grid Corporation of China
Scholars:
6.5K
Papers: 5.2K
Citations: 1.7K