Return
Two statistical traffic features for certain APT group identification
DOI:10.1016/j.jisa.2022.103207.png)
Abstract
En 中文
Advanced Persistent Threat (APT) attack, which refers to the continuous and effective attack activities carried out by a group on a specific object, has become the major threats of highly protected networks. The attack traffics generated by a certain APT group, have a high similar distribution, especially in the command and control (C&C) stage. This paper analyzes the DNS and TCP traffic of a certain APT group's attack, and constructs two new features, C2Load_fluct (response packet load fluctuation) and Bad_rate (bad packet rate), which can be used to identify APT group. Experimental results show that the F1-score can reach above 0.98 and 0.94 respectively on the two datasets, which proves that the two new features are effective for APT group identification.
Keywords:
APT attack
Bad_rate
C2Load_fluct
APT group identification
Journal
IF:
3.7
Papers:
1.9K
Citations:
4.9K

