Advanced Persistent Threats (APTs) present an ever-evolving challenge to computer systems and networks due to their stealthy and persistent nature. Traditional APT detection methods, like signature-based and anomaly-based approaches, struggle against these sophisticated threats, aggravated by the rapid evolution of APT techniques and the emergence of adversarial attacks. This study explores the application of Federated Learning (FL) to enhance APT detection. FL, a decentralized machine learning approach, enables collaborative model training across multiple devices or organizations while preserving data privacy and security. Leveraging diverse data sources enhances detection model accuracy and robustness. FL also adapts effectively to the evolving APT landscape, offering a promising tool for real-time detection. Using the DAPT 2020 dataset, this research compares Support Vector Machine (SVM) and Stacked Autoencoder with Long Short-Term Memory (LSTM) models to FL models, including investigating adversarial attacks. Results show FL significantly improves APT detection, with precision, recall, and accuracy exceeding 99%, highlighting its potential in addressing APT challenges and emphasizing privacy-preserving approaches in cybersecurity.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Privacy Preserving Advanced Persistent Threat Detection Using Fed-Adv-LSTM

  • Lokmane Heraguemi,
  • Abdelaziz Amara Korba,
  • Nacira Ghoualmi-Zine

摘要

Advanced Persistent Threats (APTs) present an ever-evolving challenge to computer systems and networks due to their stealthy and persistent nature. Traditional APT detection methods, like signature-based and anomaly-based approaches, struggle against these sophisticated threats, aggravated by the rapid evolution of APT techniques and the emergence of adversarial attacks. This study explores the application of Federated Learning (FL) to enhance APT detection. FL, a decentralized machine learning approach, enables collaborative model training across multiple devices or organizations while preserving data privacy and security. Leveraging diverse data sources enhances detection model accuracy and robustness. FL also adapts effectively to the evolving APT landscape, offering a promising tool for real-time detection. Using the DAPT 2020 dataset, this research compares Support Vector Machine (SVM) and Stacked Autoencoder with Long Short-Term Memory (LSTM) models to FL models, including investigating adversarial attacks. Results show FL significantly improves APT detection, with precision, recall, and accuracy exceeding 99%, highlighting its potential in addressing APT challenges and emphasizing privacy-preserving approaches in cybersecurity.