<p>Advanced Persistent Threats (APTs) represent a sophisticated and persistent cybersecurity challenge, characterized by stealthy, multi-phase, and targeted attacks aimed at compromising information systems over an extended period. Developing an effective Intrusion Detection System (IDS) capable of detecting APTs at different phases relies on selecting network traffic features. However, not all of these features are directly related to the phases of APTs. Some network traffic features may be unrelated or have limited relevance to identifying malicious activity. Therefore, it is important to carefully select and analyze the most relevant features to improve the IDS performance. This work proposes a feature selection and classification model that integrates two prominent machine learning algorithms: SHapley Additive exPlanations (SHAP) and Extreme Gradient Boosting (XGBoost). The aim is to develop lightweight IDS based on a selected minimum number of influential features for detecting APTs at various phases. The proposed method also specifies the relevant features for each phase of APTs independently. Extensive experimental results on the SCVIC-APT-2021 dataset indicated that our proposed approach has improved performance compared to other standard techniques. Specifically, both the macro-average F1-score and recall reached 94% and 93%, respectively, while reducing the complexity of the detection model by selecting only 12 features out of 77.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Explainable AI for enhancing IDS against advanced persistent kill chain

  • Bassam Noori Shaker,
  • Bahaa Al-Musawi,
  • Mohammed Falih Hassan

摘要

Advanced Persistent Threats (APTs) represent a sophisticated and persistent cybersecurity challenge, characterized by stealthy, multi-phase, and targeted attacks aimed at compromising information systems over an extended period. Developing an effective Intrusion Detection System (IDS) capable of detecting APTs at different phases relies on selecting network traffic features. However, not all of these features are directly related to the phases of APTs. Some network traffic features may be unrelated or have limited relevance to identifying malicious activity. Therefore, it is important to carefully select and analyze the most relevant features to improve the IDS performance. This work proposes a feature selection and classification model that integrates two prominent machine learning algorithms: SHapley Additive exPlanations (SHAP) and Extreme Gradient Boosting (XGBoost). The aim is to develop lightweight IDS based on a selected minimum number of influential features for detecting APTs at various phases. The proposed method also specifies the relevant features for each phase of APTs independently. Extensive experimental results on the SCVIC-APT-2021 dataset indicated that our proposed approach has improved performance compared to other standard techniques. Specifically, both the macro-average F1-score and recall reached 94% and 93%, respectively, while reducing the complexity of the detection model by selecting only 12 features out of 77.