Advanced Persistent Threat Identification with Boosting and Explainable AI
TL;DR: In this article , a boosting-based machine learning method was used to detect Advanced persistent threat (APT) and explainable artificial intelligence (XAI) was coupled with the predictions to provide actionable insights to the domain stakeholders as well as practitioners in this domain.
read more
Abstract: Abstract Advanced persistent threat (APT) is a serious concern in cyber-security that has matured and grown over the years with the advent of technology. The main aim of this study is to establish an effective identification model for APT attacks to prevent and reduce their influence. Machine learning has the potential as well as substantial background to detect and predict cyber-security threats including APT. This study utilized several boosting-based machine learning methods to predict various types of APTs that are consistent in cyber-security domain. Furthermore, Explainable Artificial Intelligence (XAI) was coupled with the predictions to provide actionable insights to the domain stakeholders as well as practitioners in this domain. The results, particularly XGBoost with weighted F1 score of 0.97 and SHapley Additive exPlanations (SHAP)-based explanation, prove that boosting methods as well as machine learning models paired with XAI are indeed promising in handling cyber-security-related dataset problems which can be extrapolated towards new avenues of challenging research by effectively deploying boosting-based XAI models.
read more
Chat with Paper
AI Agents for this Paper
Find similar papers on Google Scholar, PubMed and Arxiv
Write a critical review of this paper
Analyze citations of this paper to find unaddressed research gaps
Citations
Airport security: the impact of AI on safety, efficiency, and the passenger experience
Eugene Pik
TL;DR: This literature review article explores how artificial intelligence is revolutionizing airport security by automating threat analysis and identification processes, with the suggestion for further research on optimizing real-time authentication systems, studying various AI strategies, and enhancing AI-based intrusion detection systems to prepare for future threats.
4
From Fine-Grained to Refined: APT Malware Knowledge Graph Construction and Attribution Analysis Driven by Multi-stage Graph Computation
Rongqi Jing,Zhengwei Jiang,Qiuyun Wang,Shuwei Wang,Hao Li,Xiao Chen +5 more
Hybridizing Base-Line 2D-CNN Model with Cat Swarm Optimization for Enhanced Advanced Persistent Threat Detection
Ali Bakhiet,Salah A. Aly +1 more
- 22 Jul 2024
TL;DR: This research enhances APT detection using a 2D-CNN model hybridized with Cat Swarm Optimization, achieving 98.4% accuracy, significantly improving detection efficiency and accuracy across various attack stages in cyber-security.
A Novel Neural Networks-based Framework for APT Detection in Networked Autonomous Systems
Hassan El Alami,Danda B. Rawat +1 more
- 29 Jul 2024
TL;DR: This paper proposes a neural network-based framework for Advanced Persistent Threat (APT) detection in Networked Autonomous Systems, leveraging generative adversarial networks and Deep Learning to accurately identify malicious activities, achieving significant improvement over existing DL techniques.
References
Greedy function approximation: A gradient boosting machine.
TL;DR: A general gradient descent boosting paradigm is developed for additive expansions based on any fitting criterion, and specific algorithms are presented for least-squares, least absolute deviation, and Huber-M loss functions for regression, and multiclass logistic likelihood for classification.
•Proceedings Article
A unified approach to interpreting model predictions
Scott M. Lundberg,Su-In Lee +1 more
- 04 Dec 2017
TL;DR: In this article, a unified framework for interpreting predictions, SHAP (SHapley Additive exPlanations), is presented, which assigns each feature an importance value for a particular prediction.
The advantages of the Matthews correlation coefficient (MCC) over F1 score and accuracy in binary classification evaluation
Davide Chicco,Giuseppe Jurman +1 more
TL;DR: This article shows how MCC produces a more informative and truthful score in evaluating binary classifications than accuracy and F1 score, by first explaining the mathematical properties, and then the asset of MCC in six synthetic use cases and in a real genomics scenario.
A Survey of Data Mining and Machine Learning Methods for Cyber Security Intrusion Detection
Anna L. Buczak,Erhan Guven +1 more
TL;DR: The complexity of ML/DM algorithms is addressed, discussion of challenges for using ML/ DM for cyber security is presented, and some recommendations on when to use a given method are provided.
2.5K
Multi-class AdaBoost ∗
TL;DR: A new algorithm is proposed that naturally extends the original AdaBoost algorithm to the multiclass case without reducing it to multiple two-class problems and is extremely easy to implement and is highly competitive with the best currently available multi-class classification methods.
2K