scieee Open visual document viewer

A Novel Deep Learning Stack for APT Detection

Bodström, Tero,Hämäläinen, Timo

Full text

This is a sel -a chi ed e sion o an o iginal a icle. This e sion may di e om he o iginal in pagina ion and ypog aphic de ails. Au ho (s): Ti le: Yea : Ve sion: Copy igh : Righ s: Righ s u l: Please ci e he o iginal e sion: CC BY 4.0 h ps://c ea i ecommons.o g/licenses/by/4.0/ A No el Deep Lea ning S ack o APT De ec ion © 2019 by The Au ho s. Licensee MDPI, Basel, Swi ze land. Published e sion Bods öm, Te o; Hämäläinen, Timo Bods öm, T., & Hämäläinen, T. (2019). A No el Deep Lea ning S ack o APT De ec ion. Applied Sciences, 9(6), A icle 1055. h ps://doi.o g/10.3390/app9061055 2019 applied sciences A icle A No el Deep Lea ning S ack o APT De ec ion Te o Bods öm * and Timo Hämäläinen Facul y o In o ma ion Technology, Uni e si y o Jy äskylä, 40014 Jy äskylä, Finland; [email p o ec ed] *Co espondence: e [email p o ec ed] Recei ed: 11 Feb ua y 2019; Accep ed: 8 Ma ch 2019; Published: 13 Ma ch 2019   Abs ac : We p esen a no el Deep Lea ning (DL) s ack o de ec ing Ad anced Pe sis en h ea (APT) a acks. This model is based on a heo e ical app oach whe e an APT is obse ed as a mul i- ec o mul i-s age a ack wi h a con inuous s a egic campaign. To cap u e hese a acks, he en i e ne wo k low and pa icula ly aw da a mus be used as an inpu o he de ec ion p ocess. By combining di e en ypes o ailo ed DL-me hods, i is possible o cap u e ce ain ypes o anomalies and beha iou . Ou me hod essen ially b eaks down a bigge p oblem in o smalle asks, ies o sol e hese sequen ially and inally e u ns a conclusi e esul . This concep pape ou lines, o example, he p oblems and possible solu ions o he asks. Addi ionally, we desc ibe how we will be de eloping, implemen ing and es ing he me hod in he nea u u e. Keywo ds: Ad anced Pe sis en Th ead (APT); Deep Lea ning (DL); ne wo k anomaly de ec ion 1. In oduc ion Due o he complexi y and dynamical beha iou o APT a acks, we p opose a sys em a chi ec u e o a no el p o o ype ha akes in o accoun he beha iou o hese sophis ica ed a acks while de ec ing anomalies. Thus, we need o conside ollowing issues: (i) ou lie s; (ii) da a dimensions; (iii) non-linea his o ical e en s; (i ) unde lying hidden in e connec ions; and ( ) p e iously unknown a acks. To cap u e ou lie s caused by APT, he sys em mus deal wi h he abo e-men ioned issues e ec i ely. The e o e, we need o de elop a s ack o Deep Lea ning (DL) me hods whe e each laye has i s own pu pose ins ead o ha ing one single me hod. Finally, he sys em equi es a da a usion unc ion whe e all de ec ed hos ile ou lie s a e collec ed and combined. The sys em a chi ec u e mus be ca e ully planned, empi ically es ed and op imised as well as he co ec da a ep esen a ion o he inpu mus be selec ed. APT a ack is a sophis ica ed ne wo k a ack, wi h he pu pose o long- e m espionage o maximal des uc ion o a ge sys ems and ne wo ks. I has mul iple unc ionali ies, which a e de eloped o a oid de ec ion o as long as possible. Some o hose unc ionali ies include mul iple simul aneous a ack ec o s wi h di e en phases, masque ading as communica ion da a, andom changes in execu ion ime in e als, ho izon al and e ical connec ions and mimicking legi ima e a ic [ 1 ]. A common way o execu e APT is ia spea - ishing email spoo ing a ack bu , i he e exis s an inside h ea , i can be execu ed e en inside he a ge ne wo k [2,3]. To he bes o ou knowledge, his ype o sys em a chi ec u e has no been p esen ed ye in academic esea ch, e en hough APT a ack de ec ion me hods ha e been p oposed. Nex , in Sec ion 2, cu en de ec ion p oblems a e b ie ly discussed. Then, in Sec ion 3, da a p ope ies and how hey ela e o de ec ion p ocess a e p esen ed. Sec ion 4desc ibes he DL de ec ion s ack wi h de ails and p elimina y complexi y e alua ion is included in Sec ion 5. The pape concludes wi h Sec ions 6and 7is ese ed o sugges ions o u u e wo ks. Appl. Sci. 2019,9, 1055; doi:10.3390/app9061055 www.mdpi.com/jou nal/applsci Appl. Sci. 2019,9, 1055 2 o 10 2. Cu en De ec ion P oblems In ou p e ious pape [ 1 ], we p oposed a no el me hod o de ec ing (APT) a acks by using OODA loop and Black Swan heo y. The pu pose o he me hod is o ake in o accoun cu en de ec ion p oblems and imp o e de ec ion a e o ea lie unknown a acks, which is cu en ly qui e low. In ou me hod, he in en ion is no o manipula e ne wo k da a low be o e i is passed o he de ec ion p ocess. Tha is, ins ead o , o example, educing dimensions o s anda dising inpu da a, we pass he da a di ec ly o he de ec ion p ocess. This way, one does no educe o e all complexi y o andomness o he da a. Cu en anomaly de ec ion esea ch [ 4 , 5 ] elies on simila me hods, whe e ou da ed and hea ily manipula ed da ase s, such as KDD98, KDDCUP99 and NSLKDD [ 6 ], a e used o benchma king p oposed me hods. Ano he issue is ha complex p oblems a e sol ed in a simple manne , ha is, one ype o me hod is used o handling he en i e p oblem, such as one ype o Machine Lea ning (ML) o Deep Lea ning (DL) algo i hm. Addi ionally, Albanese [ 7 ] e al. poin ed ou in hei esea ch ha cu en in usion de ec ion sys ems ely hea ily on a ack inge p in s, which a e da a sequences o iden i y an a ack, o a ack p o iles, which a e beha iou models o an a ack. Bo h men ioned me hods equi e p io knowledge o an a ack, hus canno be used o de ec ing ea lie unknown a acks. The au ho s p oposed a amewo k ha iden i ies sequence o e en s, sepa a es unexplained cases based on p io models and es ima es he p obabili y o an a ack. Mo eo e , Au [ 8 ] e al. s a ed ha he numbe o sma phones is inc easing and hey a e somewha ulne able, which inc eases he p obabili y o being a ic im o an APT. These de ices a e connec ed o cloud se ices all he ime, inc easing pe sonal da a ansmission, as well as he p obabili y o espionage. Conside ing men ioned issues, we can s a e ha he o e all complexi y in a ne wo k inc eases due o g owing numbe o de ices and da a ansmissions, which also adds mo e andomness o da a. Nicho [ 9 ] e al. s a ed in hei s udy ha he academic communi y has neglec ed esea ch ela ed o APT a acks, and, while esea ch exis s, i is oo ocused on de ec ing a acks a e wa ds. The e o e, hei app oach ocused on p e en ing human e o , which commonly is he eason ha a campaign ge s s a ed in he i s place. In addi ion, human e o canno be elimina ed comple ely, hus mo e esea ch on sophis ica ed de ec ion me hods a e also equi ed. As men ioned abo e, “...[APT a ack] eal- ime de ec ion migh no be possible no necessa y. Ins ead, he ocus is o d op he de ec ion ime om yea s o mon hs o an accep able one, ha is, days” [1]. 3. Da a P ope ies This sec ion desc ibes b ie ly di e en p ope ies ha da a ha e as well as he pu pose o he p oposed anomaly de ec ion p ocess. In his pape , he da a a e conside ed a combina ion o ne wo k packe heade s and payload. 3.1. Ou lie s Ou lie de ec ion has some se ious p oblems. One can hink ha a iny ou lie is no signi ican o he de ec ion p ocess. Howe e , in he case o APT and due o i s le el o sophis ica ion, i migh be he only way o de ec such an a ack. Fo men ioned issues, one has o selec a da a p ocessing me hod such ha he p ocessing does no modi y he da a s uc u e. Fo hese easons, in ou p oposed app oach, he ne wo k da a a e no manipula ed in any way. The de ec ion sys em inpu is aw bina y da a. 3.2. Da a Dimensions In many p oposed de ec ion me hods, da a dimensions a e educed o gaining speed and mo e compu a ional powe . This ype o app oach howe e can cause impo an ou lie s o anish, hus educing de ec ion a e. Appl. Sci. 2019,9, 1055 3 o 10 In ou p oposed me hod, da a dimensions a e le as hey a e. Fo example, TCP/IP packe heade and da a ields ha e a maximum leng h o 1500 by es in E he ne ne wo k and sp ead o e 27 dimensions. As was s a ed in ou ea lie pape [ 1 ], we implemen ed he DL s ack in a way ha i akes he da a inpu in bina y o m. Dimensionali y is high, as 1500 by es ep esen 12,000 dimensions in bina y, howe e each dimension has he alue o 0 o 1, hus da a s anda disa ion is no needed in inpu laye . An al e na i e op ion is o p esen da a ield alues as in ege s and use da a ame ields as a dimensionali y, o example 27 dimensions in TCP/IP packe . Wi h he la e app oach, da a alues a e highe , bu , as minimum and maximum alues a e known, s anda disa ion migh no be needed. I is wo h es ing bo h app oaches and compa ing which pe o ms be e , i any di e ence exis s. Wi h his app oach, he o iginal dimensionali y is kep in da a. 3.3. Non-Linea His o ical E en s Fo non-linea his o ical e en s, he e exis s wo known p oblems: (i) “du a ion blindness”; and (ii) “cu se o lea ning”. These issues may be sol ed wi h mul iple sequen ial neu al ne wo ks. Tha is, neu al ne wo ks a e ained in a ce ain pe iod o ime, o example e e y 24 h, and a s ack is buil wi h hese neu al ne wo ks. In his manne , de ec ed ou lie s a e passed h ough a ious neu al ne wo ks and a e checked o ea lie exis ence o a oid he du a ion blindness. This also educes he cu se o lea ning as neu al ne wo ks a e ained wi h ewe da a, hus educing he possibili y o o e i ing. Lu e al. s a ed ha e en he ansmission ime in e al du ing he APT communica ion is no egula . The da a low may also consis o mo e han one da a packe . Mo eo e , e en hough he low du a ion can be sho e han 5 s [ 10 ], we can s a e ha communica ion pa e ns can be de ec ed om his o ical ou lie s. 3.4. Unde lying Hidden In e connec ions A e he execu ion, an APT ends o seek ano he ulne able hos s and sp ead i sel h ough a local ne wo k, hus c ea ing hidden in e connec ions. By iden i ying hese unusual in e nal hos - o-hos connec ions, i is possible o de ec unexpec ed anomalies. Le us assume ha PCs in a local ne wo k should no communica e wi h each o he , excep o example wi h ins an messaging applica ion. Howe e , sys em de ec s Remo e Desk op P o ocol (RDP) communica ing wi hin se e al PCs, which should aise a wa ning. On he o he hand, RDP can also be used o legi asks, hus, by using i , an a ack can communica e unde ec ed o a long ime, in he case he de ec ion sys em alsely iden i ies i as alse nega i e. 3.5. P e iously Unknown A acks P e iously unknown a acks a e a common p oblem o adi ional de ec o s, such as in usion de ec ion sys ems (IDS), which a e based on a ack signa u es [ 11 ]. In he case o an APT, he p oblem is e en wo se, as he a ack uses sophis ica ed s eal h me hods and mimics no mal a ic and hus can hide unde ec ed o a long pe iods o ime [1,9]. Deep lea ning me hods ha e shown signi ican po en ial o de ec his ype o anomalies [5,11–22]. Albei s udied me hods a y om image p ocessing o signal p ocessing and so o h, basic unc ionali ies can be con e ed o ano he ype o de ec ion p ocess. 4. Deep Lea ning De ec ion S ack Fo esol ing he abo e-men ioned p oblems, we p opose a Deep Lea ning s ack ha uses sequen ial neu al ne wo ks o de ec ion and classi ica ion. Ou app oach also akes in o accoun de ec ion di e ences be ween algo i hms, ins ead o using a single algo i hm. Wi h his me hod, he s ack ex ac s p e iously known da a, de ec s anomalies, classi ies and does compa isons wi h his o ical ou lie s as well as seeks hei in e connec ions om ne wo k a ic low. Appl. Sci. 2019,9, 1055 4 o 10 4.1. Known A acks The pu pose o he i s laye is o de ec known a acks om da a low, sa e hem o da abase wi h imes amp and inally emo e he de ec ed da a om he low. The es o he da a low is pushed o he second de ec ion laye , acco ding o Figu e 1. The de ec ion accu acy is no 100 pe cen , hus e en when he known a acks a e emo ed, he e is a possibili y o exis ing aces o known a acks in he es o he da a. The i s laye includes mul iple neu al ne wo ks, which a e ained egula ly. Tha is, ins ead o using one neu al ne wo k ha is e- ained and upda ed, we add new neu al ne wo ks o he s ack, which a e ained wi h new ou lie de ec ions. This me hod is used o a oid o e i ing. Fo es ing and op imisa ion pu poses, we execu e es s wi h semi-supe ised (SDL) and unsupe ised (UDL) Deep Lea ning me hods in his laye . Neu al ne wo ks a e ained wi h da a om known a acks and, in he case he DL de ec s a known a ack, i d ops da a om low. Fo example, an Au oencode (AE) ha consis s o deep laye s can be ained only wi h known a acks, hus, when i de ec s a known a ack, i econs uc s he obse a ion co ec ly. In o he wo ds, all da a ha cause enough econs uc ion e o a e passed o he nex laye . He e is a mo e de ailed example how he i s and second de ec ion laye s a e e- ained and kep up o da e. We use he ollowing syn ax: xNy, whe e x ep esen s he assigned AE (1 o known a acks and 2 o no mal a ic) and y is he in e al numbe ha inc eases om 1 o n . To cla i y, when conside ing he i s and second laye s, he e a e coun o y unique AEs wi h hei own inpu and ou pu laye s. Tha is, he i s and second de ec ion laye s, as desc ibed in Figu e 1, do no include only one AE. Fi s , he aining in e al is se , 24 h in his example. Tha is, a new neu al ne wo k is ained e e y 24 h. The neu al ne wo k in he i s laye 1N1 is ained wi h a ailable da a o known a acks and he second laye ’s neu al ne wo k 2N1 wi h a ailable no mal a ic da a. The da a inpu om he i s day is es ed wi h 1N1 and 2N1 o anomalies. The i s and second laye ne wo ks o he second day a e ained wi h he da a p ocessed on he i s day, including he iden i ied a acks and upda ed no mal a ic. The da a inpu om he second day is p ocessed by 1N1 and 1N2 o known a acks as well as 2N1 and 2N2 o no mal a ic. The ne wo ks o he hi d day a e cons uc ed in he same ashion esul ing in h ee ne wo ks in he i s laye and h ee ne wo ks in he second laye o de ec ing known a acks and no mal a ic, espec i ely. In o he wo ds, each laye a e he i s one is ained wi h he de ec ions only om he p e ious laye . Wi h his a chi ec u e, he numbe o neu al ne wo ks inc eases depending on he aining in e al. I can be se o a day, week, mon h o some sui able alue. Fo example, when limi ing he maximum ime o ope a ion o he whole sys em o one yea and he aining in e al is one day, he numbe o neu al ne wo ks would be 365 in he i s and second laye s. Fo ime complexi y, his means ha he e would be 365 s anda d ime ope a ions in each laye , which could exclude eal- ime de ec ion. Howe e , i can be assumed ha de ec ion p ocess would no ake oo long ime. Wi h he desc ibed a chi ec u e, we can minimise he possibili y o o e i ing, which is impo an o neu al ne wo ks o be able o de ec anomalies. 4.2. No mal T a ic The second laye de ec s no mal ne wo k a ic and emo es i om he low. As he known a acks and no mal ne wo k a ic a e disca ded om he da a low, he e can s ill exis aces o p e iously unknown obse a ions in he es o he da a, which can be malicious. The second laye also con ains mul iple neu al ne wo ks. Howe e , when a new se ice o applica ion is ins alled o a ne wo k, he second laye should be upda ed acco dingly. These highly dynamical unc ionali ies in a ne wo k cause new ypes o da a, which inc eases he numbe o legi ou lie s. As in he ea lie laye , bo h SDL and UDL me hods a e es ed o op imal pe o mance. While he de ec ion p ocess s ays he same, he neu al ne wo ks a e ained only wi h no mal a ic da a. When Appl. Sci. 2019,9, 1055 5 o 10 conside ing he AE, he ou lie s ha a e causing econs uc ion e o a e passed o he nex laye and he da a ha a e success ully econs uc ed a e d opped om he low. 4.3. His o ical Appea ance The pu pose o he hi d laye is o de ec i an ou lie has appea ed ea lie in he ne wo k. Since APT can s ay in ine ia-s a e o a long pe iod o ime o a oid de ec ion, his o ical appea ance e i ica ion is impo an o he p ocess. The hi d laye is kep up o da e by e- aining he neu al ne wo k wi h he ou lie s ha ha e passed h ough he de ec ion p ocess. The hi d laye de ec s using Recu en Neu al Ne wo k—Long Sho -Te m Memo y (RNN-LSTM) uni s whe he an ou lie has appea ed be o e. While RNN can lea n empo al pa e ns and alues ha a e es ima ed om cu en and pas alues, i s memo y unc ion is sho . RNN-LSTM adds a cell o RNN enabling longe memo y ha has he abili y o lea n hese pa e ns om longe sequences o da a, hus imp o ing pe o mance and allowing be e ime-se ies es ima ion [20]. IP/TCP packe is cons uc ed om 27 unique ields, hus each ield is ea ed as a unique ea u e and all 27 ea u es a e passed h ough neu al ne wo k, while compa ing o ea lie ea u es. The neu al ne wo k is ained wi h ea lie ou lie s, which allows he neu al ne wo k o compa e 27 ea u es simul aneously and p edic ea lie appea ance. We can hink ea u es as signal agmen s, ha is p e iously ound ou lie s c ea e some ype o con inuous signals and hese signals can be isualised a e wa ds. One app oach o iden i y new ou lie s in signals is o de ec change poin s in signals [ 13 ]. Howe e , we canno assume ha a new ou lie , in any o he 27 signals, c ea es a de ec able change poin , as signals do no necessa ily beha e egula ly in ou case. Vinayakuma e al. s a ed ha anomalous e en s do no ha e pa e ns and hey occu equen ly in a ne wo k in en ionally o unin en ionally [ 20 ]. F om his pe spec i e, we can conside known ou lie s as no mal and new ou lie s as anomalies, while seeking hose om ou lie da a low. Qin e al. es ed RNN-LSTM o anomaly de ec ion in IP bea e ne wo k by ga he ing da a om 31,000 po s wi h highe han 1Gb/s a ic. A e aining he sys em o one week, hey managed o ge good anomaly de ec ion a es in a es en i onmen o 824 po s. They conside ed h ee ypes o anomalies: (i) wa ning, one anomaly do ; (ii) issue, wo con inuous anomaly do s; and (iii) ala m, mo e con inuous anomaly do s. Howe e , hey s a ed ha ixed he one-week moni o ing pe iod caused many alse posi i es, as a ic in po le el is no so pe iodical. Ano he conce n was compu ing usage while using RNN-LSTM in each po o es en i onmen , as i uses a lo o compu ing powe [ 16 ], hus we ha e o conside one o mo e sequen ial RNN-LSTMs, no pa allel. 4.4. Ou lie Classi ica ion The ou h laye classi ies ou lie s o di e en ca ego ies, which include a leas he ollowing: (i) known a acks; (ii) p edic ed a acks; (iii) unknown ou lie s; and (i ) no mal a ic. A e he classi ica ion p ocess, unnecessa y ou lie s can be emo ed om da a, ha is Ca ago ies (i) and (i ). The e a e di e en me hods o classi ying ou lie s. Zolo ukhin e al. p oposed [ 11 ] a me hod u ilising G owing Hie a chical Sel -O ganising Map (GHSOM) o de ec ing anomalies in dynamical web eques s o web-se e . The pu pose is o iden i y anomalies caused by misuse ha do no ha e signa u es. Tes esul s show high de ec ion a e wi h e y low alse posi i e a e, hus a simila app oach is used as a pa o ou me hod. Unsupe ised GHSOM allows he sel -o ganising map o g ow ho izon ally and e ically by using mul iple laye s. This way i c ea es highe a iance and de ec s smalle di e ences among ou lie s. To suppo he usage o GHSOM in ou me hod, Chiu e al. s a ed ha 2D Sel -O ganising Map (SOM) has wo disad an ages: (i) map size has o be de ined be o e aining p ocess; and (ii) he e a e no hie a chical ela ions be ween clus e s. Thei es esul s also show low alse posi i e and nega i e a es [ 12 ]. The e o e, we do no limi he clus e expansions o he GHSOM size, as he e does no exis any in o ma ion on how many clus e s should be chosen o how high o wide he GHSOM should g ow. Howe e , Shi e al. s a ed ha “ he hie a chical g owing Appl. Sci. 2019,9, 1055 6 o 10 mechanism o GHSOM is aul y” and p oposed sGHSOM wi h mino addi ional unc ionali y o sol e his issue. They added a new pa ame e o calcula e simila i y o classes by using a dis ance me ic be ween laye s, which is missing om GHSOM. Thei benchma king es s show inc eased classi ica ion accu acy compa ed o GHSOM [19], hus sGHSOM has o be e alua ed as well. 4.5. Anomaly Mapping The inal phase o he de ec ion p ocess is mapping anomalies, whe e hei in e connec ions a e analysed wi h a g aph algo i hm. The pu pose o his laye is o map ou lie s and e eal hei hidden connec ions, which may emain in isible o he wise. The e a e wo possible solu ions o his phase, ei he using G aph Da abase (GDB) o G aph-based Neu al Ne wo k (GNN) implemen a ion ha inds spa ial, empo al and seman ic ela ionships be ween da a poin s. Zhang [ 22 ] p oposed GDB o knowledge managemen in his esea ch. GDB is used o e eal connec ions among use c ea ed documen s and how hey a e used. Da a om ela ional da abase a e easily con e ed o GDB and connec ions made isible. The au ho s a ed h ee bene i s o using GDB: (i) hey a e ideal o modelling scena ios in a ne wo k; (ii) many- o-many ela ionships a e easy o implemen ; and (iii) quick access o da a wi h simple que ies. Hu lbu [ 14 ] s a ed ha , as GDBs deals wi h p ope ies and connec ions, hey ep esen a lo o in o ma ion, which s ays hidden wi hou esea ch. I is also poin ed ou ha GDB suppo s desc ibing all kinds o complex mode n ne wo ks. Mo eo e , Yisong [ 21 ] e al. s a ed ha da a in eg a ed ia GDB can s o e ne wo k opology di ec ly, hus i suppo s highly complex ne wo k p esen a ions. GNN, as p esen ed by Sca selli e al., is a gene al class neu al ne wo k o g aphs, which is p oposed o seek unde lying ela ionships among da a [ 18 ]. Qi e al. s a ed ha GNN “is a dynamic model whe e he hidden ep esen a ion o all nodes e ol e o e ime” [ 15 ]. Quek e al. used GNN o s udy s uc u al image p esen a ion and classi ica ion. They s a ed ha GNN is capable o p ocessing bo h posi ional and non-posi ional g aphs. Thei expe imen al es s show ha GNN has g ea po en ial o classi ying da a [ 17 ]. In GNNs, edges ep esen ela ionships, while nodes ep esen objec s o concep s [ 15 , 17 , 18 ]. Thus, we can s a e ha , o ou pu poses, nodes ep esen de ices and hei p ope ies in a ne wo k and edges connec ions be ween he nodes. 5. De ec ion Engine The pu pose o he p oposed me hod is o p ocess ou lie s as well as o de ec and iden i y APT a acks. Fo his pu pose, we de ine da a low as ollows: F=da a low K=known a acks N=no mal a ic O1=unknown legi ima e ou lie s O2=unknown a ack ou lie s KT= aces o known a acks NT= aces o no mal a ic F={K,N,O1,O2} The i s and second laye s emo e known da a. Howe e , as men ioned he Sec ions 4.1 and 4.2, ou lie da a can s ill con ain aces o known a acks and no mal a ic. A e he i s laye , he da a low is: F1={KT,N,O1,O2} Appl. Sci. 2019,9, 1055 7 o 10 A e he second laye , i is: F2={KT,NT,O1,O2} His o ical e en s a e es ed wi h RNN-LSTM whe e ou lie ea u es low h ough i . I he e is no ea lie de ec ion, i is a new ou lie . When an ou lie is de ec ed in his phase, i is added o he da abase. Then, his in o ma ion becomes a ailable o he classi ie . The classi ie o ganises ou lie s o he clus e s in GHSOM, based on da a packe s. As GHSOM does no limi he g ow h, wecan de ec sligh di e ences in ou lie s. I can iden i y new ypes o clus e s i hey appea in da a, since i is an unsupe ised me hod. A e wa ds, ou lie s a e mapped wi h a g aph me hod, which e eals hei hidden in e connec ions. These hidden connec ions can e eal how widely he APT has sp ead and which a e he communica ion p o ocols and po s. In he case an a ack uses in e nal ou ing communica ion channel, i can also be acked. The las phase is da a usion, whe e ou lie da a a e mapped in such ha hey can be isualised o in es iga ion and analysis pu poses. Fo he inal es s, he e a e ou di e en s ack models as desc ibed in Table 1. Table 1. S ack models o inal es s. 1s laye SDL SDL UDL UDL 2nd laye SDL UDL SDL UDL 3 d laye RNN-LSTM RNN-LSTM RNN-LSTM RNN-LSTM 4 h laye GHSOM GHSOM GHSOM GHSOM 5 h laye GNN/GDB GNN/GDB GNN/GDB GNN/GDB 6. Complexi y E alua ion The me hod’s complexi y is discussed in his sec ion. I is necessa y o e alua e he complexi y om wo poin s o iew, sys em and ime complexi ies. As hese complexi ies ha e signi ican impac on compu a ional equi emen s, hey ha e o be e alua ed in o de o assess whe he he sys em pe o ms in easonable ime. By e alua ions, we can es ima e minimum ha dwa e equi emen s and expec ed maximum ime o da a packe o pass en i e de ec ion p ocess. The sys em has a main unc ion, which is anomaly de ec ion and suppo ing unc ions, such as egula upda es, isualisa ion, w i ing o da abase and so o h. To keep in mind he pu pose o he esea ch, we ocus on anomaly de ec ion complexi y. Suppo ing unc ions can be execu ed in sepa a ed co es, hus hey do no in e e e wi h he de ec ion p ocess. Figu e 1shows da a low h ough he DL de ec ion s ack in a gene al le el. 6.1. Sys em Complexi y F om he low cha in Figu e 1, we can iden i y ha he complexi y o he sys em is inc easing owa ds he end o he s ack. The i s wo laye s a e simple and linea while emo ing known da a om a low; e en hough he e can exis 1–nneu al ne wo ks, he ope a ion emains simila in e e y neu al ne wo k. The inal laye s inc ease he complexi y as ou lie s a e pushed o h ee di e en ypes o neu al ne wo ks, each ha ing a special pu pose, as desc ibed abo e. A e ou lie s a e p ocessed in each neu al ne wo k, da a usion is execu ed o a ange da a in such manne ha hey can be p esen ed o isualised. The sou ce code is equi ed o de ailed Cycloma ic complexi y e alua ion, hus i can be execu ed when he comple e p o o ype is de eloped. Appl. Sci. 2019,9, 1055 8 o 10 Figu e 1. Da a low h ough he de ec ion p ocess.