This is a sel -a chi ed e sion o an o iginal a icle. This e sion
may di e om he o iginal in pagina ion and ypog aphic de ails.
Au ho (s):
Ti le:
Yea :
Ve sion:
Copy igh :
Righ s:
Righ s u l:
Please ci e he o iginal e sion:
CC BY 4.0
h ps://c ea i ecommons.o g/licenses/by/4.0/
A No el Deep Lea ning S ack o APT De ec ion
© 2019 by The Au ho s. Licensee MDPI, Basel, Swi ze land.
Published e sion
Bods öm, Te o; Hämäläinen, Timo
Bods öm, T., & Hämäläinen, T. (2019). A No el Deep Lea ning S ack o APT De ec ion. Applied
Sciences, 9(6), A icle 1055. h ps://doi.o g/10.3390/app9061055
2019
applied
sciences
A icle
A No el Deep Lea ning S ack o APT De ec ion
Te o Bods öm * and Timo Hämäläinen
Facul y o In o ma ion Technology, Uni e si y o Jy äskylä, 40014 Jy äskylä, Finland; [email p o ec ed]
*Co espondence: e [email p o ec ed]
Recei ed: 11 Feb ua y 2019; Accep ed: 8 Ma ch 2019; Published: 13 Ma ch 2019
Abs ac :
We p esen a no el Deep Lea ning (DL) s ack o de ec ing Ad anced Pe sis en h ea
(APT) a acks. This model is based on a heo e ical app oach whe e an APT is obse ed as a
mul i- ec o mul i-s age a ack wi h a con inuous s a egic campaign. To cap u e hese a acks,
he en i e ne wo k low and pa icula ly aw da a mus be used as an inpu o he de ec ion p ocess.
By combining di e en ypes o ailo ed DL-me hods, i is possible o cap u e ce ain ypes o
anomalies and beha iou . Ou me hod essen ially b eaks down a bigge p oblem in o smalle asks,
ies o sol e hese sequen ially and inally e u ns a conclusi e esul . This concep pape ou lines,
o example, he p oblems and possible solu ions o he asks. Addi ionally, we desc ibe how we
will be de eloping, implemen ing and es ing he me hod in he nea u u e.
Keywo ds: Ad anced Pe sis en Th ead (APT); Deep Lea ning (DL); ne wo k anomaly de ec ion
1. In oduc ion
Due o he complexi y and dynamical beha iou o APT a acks, we p opose a sys em a chi ec u e
o a no el p o o ype ha akes in o accoun he beha iou o hese sophis ica ed a acks while
de ec ing anomalies. Thus, we need o conside ollowing issues: (i) ou lie s; (ii) da a dimensions;
(iii) non-linea his o ical e en s; (i ) unde lying hidden in e connec ions; and ( ) p e iously unknown
a acks. To cap u e ou lie s caused by APT, he sys em mus deal wi h he abo e-men ioned issues
e ec i ely. The e o e, we need o de elop a s ack o Deep Lea ning (DL) me hods whe e each laye
has i s own pu pose ins ead o ha ing one single me hod. Finally, he sys em equi es a da a usion
unc ion whe e all de ec ed hos ile ou lie s a e collec ed and combined. The sys em a chi ec u e mus
be ca e ully planned, empi ically es ed and op imised as well as he co ec da a ep esen a ion o
he inpu mus be selec ed.
APT a ack is a sophis ica ed ne wo k a ack, wi h he pu pose o long- e m espionage o maximal
des uc ion o a ge sys ems and ne wo ks. I has mul iple unc ionali ies, which a e de eloped o
a oid de ec ion o as long as possible. Some o hose unc ionali ies include mul iple simul aneous
a ack ec o s wi h di e en phases, masque ading as communica ion da a, andom changes in
execu ion ime in e als, ho izon al and e ical connec ions and mimicking legi ima e a ic [
1
].
A common way o execu e APT is ia spea - ishing email spoo ing a ack bu , i he e exis s an inside
h ea , i can be execu ed e en inside he a ge ne wo k [2,3].
To he bes o ou knowledge, his ype o sys em a chi ec u e has no been p esen ed ye in
academic esea ch, e en hough APT a ack de ec ion me hods ha e been p oposed.
Nex , in Sec ion 2, cu en de ec ion p oblems a e b ie ly discussed. Then, in Sec ion 3, da a
p ope ies and how hey ela e o de ec ion p ocess a e p esen ed. Sec ion 4desc ibes he DL de ec ion
s ack wi h de ails and p elimina y complexi y e alua ion is included in Sec ion 5. The pape concludes
wi h Sec ions 6and 7is ese ed o sugges ions o u u e wo ks.
Appl. Sci. 2019,9, 1055; doi:10.3390/app9061055 www.mdpi.com/jou nal/applsci
Appl. Sci. 2019,9, 1055 2 o 10
2. Cu en De ec ion P oblems
In ou p e ious pape [
1
], we p oposed a no el me hod o de ec ing (APT) a acks by using
OODA loop and Black Swan heo y. The pu pose o he me hod is o ake in o accoun cu en de ec ion
p oblems and imp o e de ec ion a e o ea lie unknown a acks, which is cu en ly qui e low. In
ou me hod, he in en ion is no o manipula e ne wo k da a low be o e i is passed o he de ec ion
p ocess. Tha is, ins ead o , o example, educing dimensions o s anda dising inpu da a, we pass he
da a di ec ly o he de ec ion p ocess. This way, one does no educe o e all complexi y o andomness
o he da a.
Cu en anomaly de ec ion esea ch [
4
,
5
] elies on simila me hods, whe e ou da ed and hea ily
manipula ed da ase s, such as KDD98, KDDCUP99 and NSLKDD [
6
], a e used o benchma king
p oposed me hods. Ano he issue is ha complex p oblems a e sol ed in a simple manne , ha is,
one ype o me hod is used o handling he en i e p oblem, such as one ype o Machine Lea ning
(ML) o Deep Lea ning (DL) algo i hm. Addi ionally, Albanese [
7
] e al. poin ed ou in hei esea ch
ha cu en in usion de ec ion sys ems ely hea ily on a ack inge p in s, which a e da a sequences
o iden i y an a ack, o a ack p o iles, which a e beha iou models o an a ack. Bo h men ioned
me hods equi e p io knowledge o an a ack, hus canno be used o de ec ing ea lie unknown
a acks. The au ho s p oposed a amewo k ha iden i ies sequence o e en s, sepa a es unexplained
cases based on p io models and es ima es he p obabili y o an a ack. Mo eo e , Au [
8
] e al. s a ed
ha he numbe o sma phones is inc easing and hey a e somewha ulne able, which inc eases
he p obabili y o being a ic im o an APT. These de ices a e connec ed o cloud se ices all he
ime, inc easing pe sonal da a ansmission, as well as he p obabili y o espionage. Conside ing
men ioned issues, we can s a e ha he o e all complexi y in a ne wo k inc eases due o g owing
numbe o de ices and da a ansmissions, which also adds mo e andomness o da a.
Nicho [
9
] e al. s a ed in hei s udy ha he academic communi y has neglec ed esea ch ela ed
o APT a acks, and, while esea ch exis s, i is oo ocused on de ec ing a acks a e wa ds. The e o e,
hei app oach ocused on p e en ing human e o , which commonly is he eason ha a campaign
ge s s a ed in he i s place. In addi ion, human e o canno be elimina ed comple ely, hus mo e
esea ch on sophis ica ed de ec ion me hods a e also equi ed. As men ioned abo e, “...[APT a ack]
eal- ime de ec ion migh no be possible no necessa y. Ins ead, he ocus is o d op he de ec ion ime om yea s
o mon hs o an accep able one, ha is, days” [1].
3. Da a P ope ies
This sec ion desc ibes b ie ly di e en p ope ies ha da a ha e as well as he pu pose o he
p oposed anomaly de ec ion p ocess. In his pape , he da a a e conside ed a combina ion o ne wo k
packe heade s and payload.
3.1. Ou lie s
Ou lie de ec ion has some se ious p oblems. One can hink ha a iny ou lie is no signi ican
o he de ec ion p ocess. Howe e , in he case o APT and due o i s le el o sophis ica ion, i migh
be he only way o de ec such an a ack. Fo men ioned issues, one has o selec a da a p ocessing
me hod such ha he p ocessing does no modi y he da a s uc u e.
Fo hese easons, in ou p oposed app oach, he ne wo k da a a e no manipula ed in any way.
The de ec ion sys em inpu is aw bina y da a.
3.2. Da a Dimensions
In many p oposed de ec ion me hods, da a dimensions a e educed o gaining speed and mo e
compu a ional powe . This ype o app oach howe e can cause impo an ou lie s o anish, hus
educing de ec ion a e.
Appl. Sci. 2019,9, 1055 3 o 10
In ou p oposed me hod, da a dimensions a e le as hey a e. Fo example, TCP/IP packe
heade and da a ields ha e a maximum leng h o 1500 by es in E he ne ne wo k and sp ead o e 27
dimensions. As was s a ed in ou ea lie pape [
1
], we implemen ed he DL s ack in a way ha i akes
he da a inpu in bina y o m. Dimensionali y is high, as 1500 by es ep esen 12,000 dimensions in
bina y, howe e each dimension has he alue o 0 o 1, hus da a s anda disa ion is no needed in
inpu laye . An al e na i e op ion is o p esen da a ield alues as in ege s and use da a ame ields as
a dimensionali y, o example 27 dimensions in TCP/IP packe . Wi h he la e app oach, da a alues
a e highe , bu , as minimum and maximum alues a e known, s anda disa ion migh no be needed. I
is wo h es ing bo h app oaches and compa ing which pe o ms be e , i any di e ence exis s. Wi h
his app oach, he o iginal dimensionali y is kep in da a.
3.3. Non-Linea His o ical E en s
Fo non-linea his o ical e en s, he e exis s wo known p oblems: (i) “du a ion blindness”; and
(ii) “cu se o lea ning”. These issues may be sol ed wi h mul iple sequen ial neu al ne wo ks. Tha is,
neu al ne wo ks a e ained in a ce ain pe iod o ime, o example e e y 24 h, and a s ack is buil wi h
hese neu al ne wo ks. In his manne , de ec ed ou lie s a e passed h ough a ious neu al ne wo ks
and a e checked o ea lie exis ence o a oid he du a ion blindness. This also educes he cu se o
lea ning as neu al ne wo ks a e ained wi h ewe da a, hus educing he possibili y o o e i ing.
Lu e al. s a ed ha e en he ansmission ime in e al du ing he APT communica ion is no
egula . The da a low may also consis o mo e han one da a packe . Mo eo e , e en hough he low
du a ion can be sho e han 5 s [
10
], we can s a e ha communica ion pa e ns can be de ec ed om
his o ical ou lie s.
3.4. Unde lying Hidden In e connec ions
A e he execu ion, an APT ends o seek ano he ulne able hos s and sp ead i sel h ough a
local ne wo k, hus c ea ing hidden in e connec ions. By iden i ying hese unusual in e nal hos - o-hos
connec ions, i is possible o de ec unexpec ed anomalies. Le us assume ha PCs in a local ne wo k
should no communica e wi h each o he , excep o example wi h ins an messaging applica ion.
Howe e , sys em de ec s Remo e Desk op P o ocol (RDP) communica ing wi hin se e al PCs, which
should aise a wa ning. On he o he hand, RDP can also be used o legi asks, hus, by using i , an
a ack can communica e unde ec ed o a long ime, in he case he de ec ion sys em alsely iden i ies i
as alse nega i e.
3.5. P e iously Unknown A acks
P e iously unknown a acks a e a common p oblem o adi ional de ec o s, such as in usion
de ec ion sys ems (IDS), which a e based on a ack signa u es [
11
]. In he case o an APT, he p oblem
is e en wo se, as he a ack uses sophis ica ed s eal h me hods and mimics no mal a ic and hus can
hide unde ec ed o a long pe iods o ime [1,9].
Deep lea ning me hods ha e shown signi ican po en ial o de ec his ype o
anomalies [5,11–22]. Albei s udied me hods a y om image p ocessing o signal p ocessing and so
o h, basic unc ionali ies can be con e ed o ano he ype o de ec ion p ocess.
4. Deep Lea ning De ec ion S ack
Fo esol ing he abo e-men ioned p oblems, we p opose a Deep Lea ning s ack ha uses
sequen ial neu al ne wo ks o de ec ion and classi ica ion. Ou app oach also akes in o accoun
de ec ion di e ences be ween algo i hms, ins ead o using a single algo i hm. Wi h his me hod,
he s ack ex ac s p e iously known da a, de ec s anomalies, classi ies and does compa isons wi h
his o ical ou lie s as well as seeks hei in e connec ions om ne wo k a ic low.
Appl. Sci. 2019,9, 1055 4 o 10
4.1. Known A acks
The pu pose o he i s laye is o de ec known a acks om da a low, sa e hem o da abase
wi h imes amp and inally emo e he de ec ed da a om he low. The es o he da a low is pushed
o he second de ec ion laye , acco ding o Figu e 1. The de ec ion accu acy is no 100 pe cen , hus
e en when he known a acks a e emo ed, he e is a possibili y o exis ing aces o known a acks in
he es o he da a.
The i s laye includes mul iple neu al ne wo ks, which a e ained egula ly. Tha is, ins ead o
using one neu al ne wo k ha is e- ained and upda ed, we add new neu al ne wo ks o he s ack,
which a e ained wi h new ou lie de ec ions. This me hod is used o a oid o e i ing.
Fo es ing and op imisa ion pu poses, we execu e es s wi h semi-supe ised (SDL) and
unsupe ised (UDL) Deep Lea ning me hods in his laye . Neu al ne wo ks a e ained wi h da a om
known a acks and, in he case he DL de ec s a known a ack, i d ops da a om low. Fo example, an
Au oencode (AE) ha consis s o deep laye s can be ained only wi h known a acks, hus, when i
de ec s a known a ack, i econs uc s he obse a ion co ec ly. In o he wo ds, all da a ha cause
enough econs uc ion e o a e passed o he nex laye .
He e is a mo e de ailed example how he i s and second de ec ion laye s a e e- ained and
kep up o da e. We use he ollowing syn ax: xNy, whe e x ep esen s he assigned AE (1 o known
a acks and 2 o no mal a ic) and y is he in e al numbe ha inc eases om 1 o
n
. To cla i y, when
conside ing he i s and second laye s, he e a e coun o y unique AEs wi h hei own inpu and
ou pu laye s. Tha is, he i s and second de ec ion laye s, as desc ibed in Figu e 1, do no include
only one AE.
Fi s , he aining in e al is se , 24 h in his example. Tha is, a new neu al ne wo k is ained
e e y 24 h. The neu al ne wo k in he i s laye 1N1 is ained wi h a ailable da a o known a acks
and he second laye ’s neu al ne wo k 2N1 wi h a ailable no mal a ic da a. The da a inpu om
he i s day is es ed wi h 1N1 and 2N1 o anomalies. The i s and second laye ne wo ks o he
second day a e ained wi h he da a p ocessed on he i s day, including he iden i ied a acks and
upda ed no mal a ic. The da a inpu om he second day is p ocessed by 1N1 and 1N2 o known
a acks as well as 2N1 and 2N2 o no mal a ic. The ne wo ks o he hi d day a e cons uc ed in
he same ashion esul ing in h ee ne wo ks in he i s laye and h ee ne wo ks in he second laye
o de ec ing known a acks and no mal a ic, espec i ely. In o he wo ds, each laye a e he i s
one is ained wi h he de ec ions only om he p e ious laye .
Wi h his a chi ec u e, he numbe o neu al ne wo ks inc eases depending on he aining in e al.
I can be se o a day, week, mon h o some sui able alue. Fo example, when limi ing he maximum
ime o ope a ion o he whole sys em o one yea and he aining in e al is one day, he numbe
o neu al ne wo ks would be 365 in he i s and second laye s. Fo ime complexi y, his means ha
he e would be 365 s anda d ime ope a ions in each laye , which could exclude eal- ime de ec ion.
Howe e , i can be assumed ha de ec ion p ocess would no ake oo long ime. Wi h he desc ibed
a chi ec u e, we can minimise he possibili y o o e i ing, which is impo an o neu al ne wo ks o
be able o de ec anomalies.
4.2. No mal T a ic
The second laye de ec s no mal ne wo k a ic and emo es i om he low. As he known
a acks and no mal ne wo k a ic a e disca ded om he da a low, he e can s ill exis aces o
p e iously unknown obse a ions in he es o he da a, which can be malicious.
The second laye also con ains mul iple neu al ne wo ks. Howe e , when a new se ice o
applica ion is ins alled o a ne wo k, he second laye should be upda ed acco dingly. These highly
dynamical unc ionali ies in a ne wo k cause new ypes o da a, which inc eases he numbe o
legi ou lie s.
As in he ea lie laye , bo h SDL and UDL me hods a e es ed o op imal pe o mance. While he
de ec ion p ocess s ays he same, he neu al ne wo ks a e ained only wi h no mal a ic da a. When
Appl. Sci. 2019,9, 1055 5 o 10
conside ing he AE, he ou lie s ha a e causing econs uc ion e o a e passed o he nex laye and
he da a ha a e success ully econs uc ed a e d opped om he low.
4.3. His o ical Appea ance
The pu pose o he hi d laye is o de ec i an ou lie has appea ed ea lie in he ne wo k.
Since APT can s ay in ine ia-s a e o a long pe iod o ime o a oid de ec ion, his o ical appea ance
e i ica ion is impo an o he p ocess. The hi d laye is kep up o da e by e- aining he neu al
ne wo k wi h he ou lie s ha ha e passed h ough he de ec ion p ocess.
The hi d laye de ec s using Recu en Neu al Ne wo k—Long Sho -Te m Memo y (RNN-LSTM)
uni s whe he an ou lie has appea ed be o e. While RNN can lea n empo al pa e ns and alues ha
a e es ima ed om cu en and pas alues, i s memo y unc ion is sho . RNN-LSTM adds a cell o
RNN enabling longe memo y ha has he abili y o lea n hese pa e ns om longe sequences o
da a, hus imp o ing pe o mance and allowing be e ime-se ies es ima ion [20].
IP/TCP packe is cons uc ed om 27 unique ields, hus each ield is ea ed as a unique ea u e
and all 27 ea u es a e passed h ough neu al ne wo k, while compa ing o ea lie ea u es. The neu al
ne wo k is ained wi h ea lie ou lie s, which allows he neu al ne wo k o compa e 27 ea u es
simul aneously and p edic ea lie appea ance.
We can hink ea u es as signal agmen s, ha is p e iously ound ou lie s c ea e some ype
o con inuous signals and hese signals can be isualised a e wa ds. One app oach o iden i y new
ou lie s in signals is o de ec change poin s in signals [
13
]. Howe e , we canno assume ha a new
ou lie , in any o he 27 signals, c ea es a de ec able change poin , as signals do no necessa ily beha e
egula ly in ou case.
Vinayakuma e al. s a ed ha anomalous e en s do no ha e pa e ns and hey occu equen ly
in a ne wo k in en ionally o unin en ionally [
20
]. F om his pe spec i e, we can conside known
ou lie s as no mal and new ou lie s as anomalies, while seeking hose om ou lie da a low. Qin e al.
es ed RNN-LSTM o anomaly de ec ion in IP bea e ne wo k by ga he ing da a om 31,000 po s
wi h highe han 1Gb/s a ic. A e aining he sys em o one week, hey managed o ge good
anomaly de ec ion a es in a es en i onmen o 824 po s. They conside ed h ee ypes o anomalies:
(i) wa ning, one anomaly do ; (ii) issue, wo con inuous anomaly do s; and (iii) ala m, mo e con inuous
anomaly do s. Howe e , hey s a ed ha ixed he one-week moni o ing pe iod caused many alse
posi i es, as a ic in po le el is no so pe iodical. Ano he conce n was compu ing usage while
using RNN-LSTM in each po o es en i onmen , as i uses a lo o compu ing powe [
16
], hus we
ha e o conside one o mo e sequen ial RNN-LSTMs, no pa allel.
4.4. Ou lie Classi ica ion
The ou h laye classi ies ou lie s o di e en ca ego ies, which include a leas he ollowing:
(i) known a acks; (ii) p edic ed a acks; (iii) unknown ou lie s; and (i ) no mal a ic. A e he
classi ica ion p ocess, unnecessa y ou lie s can be emo ed om da a, ha is Ca ago ies (i) and (i ).
The e a e di e en me hods o classi ying ou lie s. Zolo ukhin e al. p oposed [
11
] a me hod
u ilising G owing Hie a chical Sel -O ganising Map (GHSOM) o de ec ing anomalies in dynamical
web eques s o web-se e . The pu pose is o iden i y anomalies caused by misuse ha do no ha e
signa u es. Tes esul s show high de ec ion a e wi h e y low alse posi i e a e, hus a simila
app oach is used as a pa o ou me hod. Unsupe ised GHSOM allows he sel -o ganising map o
g ow ho izon ally and e ically by using mul iple laye s. This way i c ea es highe a iance and
de ec s smalle di e ences among ou lie s. To suppo he usage o GHSOM in ou me hod, Chiu e
al. s a ed ha 2D Sel -O ganising Map (SOM) has wo disad an ages: (i) map size has o be de ined
be o e aining p ocess; and (ii) he e a e no hie a chical ela ions be ween clus e s. Thei es esul s
also show low alse posi i e and nega i e a es [
12
]. The e o e, we do no limi he clus e expansions
o he GHSOM size, as he e does no exis any in o ma ion on how many clus e s should be chosen o
how high o wide he GHSOM should g ow. Howe e , Shi e al. s a ed ha “ he hie a chical g owing
Appl. Sci. 2019,9, 1055 6 o 10
mechanism o GHSOM is aul y” and p oposed sGHSOM wi h mino addi ional unc ionali y o sol e
his issue. They added a new pa ame e o calcula e simila i y o classes by using a dis ance me ic
be ween laye s, which is missing om GHSOM. Thei benchma king es s show inc eased classi ica ion
accu acy compa ed o GHSOM [19], hus sGHSOM has o be e alua ed as well.
4.5. Anomaly Mapping
The inal phase o he de ec ion p ocess is mapping anomalies, whe e hei in e connec ions a e
analysed wi h a g aph algo i hm. The pu pose o his laye is o map ou lie s and e eal hei hidden
connec ions, which may emain in isible o he wise. The e a e wo possible solu ions o his phase,
ei he using G aph Da abase (GDB) o G aph-based Neu al Ne wo k (GNN) implemen a ion ha
inds spa ial, empo al and seman ic ela ionships be ween da a poin s.
Zhang [
22
] p oposed GDB o knowledge managemen in his esea ch. GDB is used o e eal
connec ions among use c ea ed documen s and how hey a e used. Da a om ela ional da abase
a e easily con e ed o GDB and connec ions made isible. The au ho s a ed h ee bene i s o using
GDB: (i) hey a e ideal o modelling scena ios in a ne wo k; (ii) many- o-many ela ionships a e easy
o implemen ; and (iii) quick access o da a wi h simple que ies. Hu lbu [
14
] s a ed ha , as GDBs
deals wi h p ope ies and connec ions, hey ep esen a lo o in o ma ion, which s ays hidden wi hou
esea ch. I is also poin ed ou ha GDB suppo s desc ibing all kinds o complex mode n ne wo ks.
Mo eo e , Yisong [
21
] e al. s a ed ha da a in eg a ed ia GDB can s o e ne wo k opology di ec ly,
hus i suppo s highly complex ne wo k p esen a ions.
GNN, as p esen ed by Sca selli e al., is a gene al class neu al ne wo k o g aphs, which is
p oposed o seek unde lying ela ionships among da a [
18
]. Qi e al. s a ed ha GNN “is a dynamic
model whe e he hidden ep esen a ion o all nodes e ol e o e ime” [
15
]. Quek e al. used GNN o s udy
s uc u al image p esen a ion and classi ica ion. They s a ed ha GNN is capable o p ocessing bo h
posi ional and non-posi ional g aphs. Thei expe imen al es s show ha GNN has g ea po en ial
o classi ying da a [
17
]. In GNNs, edges ep esen ela ionships, while nodes ep esen objec s o
concep s [
15
,
17
,
18
]. Thus, we can s a e ha , o ou pu poses, nodes ep esen de ices and hei
p ope ies in a ne wo k and edges connec ions be ween he nodes.
5. De ec ion Engine
The pu pose o he p oposed me hod is o p ocess ou lie s as well as o de ec and iden i y APT
a acks. Fo his pu pose, we de ine da a low as ollows:
F=da a low
K=known a acks
N=no mal a ic
O1=unknown legi ima e ou lie s
O2=unknown a ack ou lie s
KT= aces o known a acks
NT= aces o no mal a ic
F={K,N,O1,O2}
The i s and second laye s emo e known da a. Howe e , as men ioned he Sec ions 4.1 and 4.2,
ou lie da a can s ill con ain aces o known a acks and no mal a ic.
A e he i s laye , he da a low is:
F1={KT,N,O1,O2}
Appl. Sci. 2019,9, 1055 7 o 10
A e he second laye , i is:
F2={KT,NT,O1,O2}
His o ical e en s a e es ed wi h RNN-LSTM whe e ou lie ea u es low h ough i . I he e is
no ea lie de ec ion, i is a new ou lie . When an ou lie is de ec ed in his phase, i is added o he
da abase. Then, his in o ma ion becomes a ailable o he classi ie .
The classi ie o ganises ou lie s o he clus e s in GHSOM, based on da a packe s. As GHSOM
does no limi he g ow h, wecan de ec sligh di e ences in ou lie s. I can iden i y new ypes o
clus e s i hey appea in da a, since i is an unsupe ised me hod.
A e wa ds, ou lie s a e mapped wi h a g aph me hod, which e eals hei hidden
in e connec ions. These hidden connec ions can e eal how widely he APT has sp ead and which a e
he communica ion p o ocols and po s. In he case an a ack uses in e nal ou ing communica ion
channel, i can also be acked.
The las phase is da a usion, whe e ou lie da a a e mapped in such ha hey can be isualised
o in es iga ion and analysis pu poses.
Fo he inal es s, he e a e ou di e en s ack models as desc ibed in Table 1.
Table 1. S ack models o inal es s.
1s laye SDL SDL UDL UDL
2nd laye SDL UDL SDL UDL
3 d laye RNN-LSTM RNN-LSTM RNN-LSTM RNN-LSTM
4 h laye GHSOM GHSOM GHSOM GHSOM
5 h laye GNN/GDB GNN/GDB GNN/GDB GNN/GDB
6. Complexi y E alua ion
The me hod’s complexi y is discussed in his sec ion. I is necessa y o e alua e he complexi y
om wo poin s o iew, sys em and ime complexi ies. As hese complexi ies ha e signi ican impac
on compu a ional equi emen s, hey ha e o be e alua ed in o de o assess whe he he sys em
pe o ms in easonable ime. By e alua ions, we can es ima e minimum ha dwa e equi emen s and
expec ed maximum ime o da a packe o pass en i e de ec ion p ocess.
The sys em has a main unc ion, which is anomaly de ec ion and suppo ing unc ions, such
as egula upda es, isualisa ion, w i ing o da abase and so o h. To keep in mind he pu pose
o he esea ch, we ocus on anomaly de ec ion complexi y. Suppo ing unc ions can be execu ed
in sepa a ed co es, hus hey do no in e e e wi h he de ec ion p ocess. Figu e 1shows da a low
h ough he DL de ec ion s ack in a gene al le el.
6.1. Sys em Complexi y
F om he low cha in Figu e 1, we can iden i y ha he complexi y o he sys em is inc easing
owa ds he end o he s ack. The i s wo laye s a e simple and linea while emo ing known da a
om a low; e en hough he e can exis 1–nneu al ne wo ks, he ope a ion emains simila in e e y
neu al ne wo k. The inal laye s inc ease he complexi y as ou lie s a e pushed o h ee di e en ypes
o neu al ne wo ks, each ha ing a special pu pose, as desc ibed abo e. A e ou lie s a e p ocessed in
each neu al ne wo k, da a usion is execu ed o a ange da a in such manne ha hey can be p esen ed
o isualised.
The sou ce code is equi ed o de ailed Cycloma ic complexi y e alua ion, hus i can be execu ed
when he comple e p o o ype is de eloped.
Appl. Sci. 2019,9, 1055 8 o 10
Figu e 1. Da a low h ough he de ec ion p ocess.