Detection and classification of advanced persistent threats and attacks using the support vector machine

43Citations
Citations of this article
95Readers
Mendeley users who have this article in their library.

Abstract

Traditional network attack and hacking models are constantly evolving to keep pace with the rapid development of network technology. Advanced persistent threat (APT), usually organized by a hacker group, is a complex and targeted attack method. A long period of strategic planning and information search usually precedes an attack on a specific goal. Focus is on a targeted object and customized specific methods are used to launch the attack and obtain confidential information. This study offers an attack detection system that enables early discovery of the APT attack. The system uses the NSL-KDD database for attack detection and verification. The main method uses principal component analysis (PCA) for feature sampling and the enhancement of detection eciency. The advantages and disadvantages of using the classifiers are then compared to detect the dataset, the classifier supports the vector machine, naive Bayes classification, the decision tree and neural networks. Results of the experiments show the support vector machine (SVM) to have the highest recognition rate, reaching 97.22% (for the trained subdata A). The purpose of this study was to establish an APT early warning model mechanism, that could be used to reduce the impact and influence of APT attacks.

References Powered by Scopus

Induction of Decision Trees

15540Citations
N/AReaders
Get full text

Classification and regression trees

8020Citations
N/AReaders
Get full text

Top 10 algorithms in data mining

4419Citations
N/AReaders
Get full text

Cited by Powered by Scopus

CNN-based network intrusion detection against denial-of-service attacks

280Citations
N/AReaders
Get full text

IoT Intrusion Detection Using Machine Learning with a Novel High Performing Feature Selection Method

129Citations
N/AReaders
Get full text

Intrusion Detection System Based on Fast Hierarchical Deep Convolutional Neural Network

97Citations
N/AReaders
Get full text

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Cite

CITATION STYLE

APA

Chu, W. L., Lin, C. J., & Chang, K. N. (2019). Detection and classification of advanced persistent threats and attacks using the support vector machine. Applied Sciences (Switzerland), 9(21). https://doi.org/10.3390/app9214579

Readers' Seniority

Tooltip

PhD / Post grad / Masters / Doc 30

75%

Researcher 6

15%

Lecturer / Post doc 3

8%

Professor / Associate Prof. 1

3%

Readers' Discipline

Tooltip

Computer Science 40

83%

Engineering 6

13%

Decision Sciences 1

2%

Social Sciences 1

2%

Save time finding and organizing research with Mendeley

Sign up for free