Advanced Persistent Threat Detection using Anomaly Score Calibration and Multi-class Classification
| dc.contributor.author | Soh, Ornella Lucresse | |
| dc.contributor.supervisor | Traoré, Issa | |
| dc.date.accessioned | 2023-04-27T22:50:22Z | |
| dc.date.available | 2023-04-27T22:50:22Z | |
| dc.date.copyright | 2023 | en_US |
| dc.date.issued | 2023-04-27 | |
| dc.degree.department | Department of Electrical and Computer Engineering | |
| dc.degree.level | Master of Applied Science M.A.Sc. | en_US |
| dc.description.abstract | Organisations worldwide continue to face a diverse range of attacks. Traditionally, these have been attacks of opportunity that quickly act upon weaker targets whenever possible. However, in the past decade, advanced persistent threats (APTs) have emerged that consist of targeted and long-term campaigns perpetrated by skilled and determined hackers who have clearly defined objectives and relentlessly work towards achieving their aims. APT breaches can go undetected for long periods because of the hackers’ ability to adapt to and escape defensive methods. In this paper, we present a new approach to establishing whether a security event is part of an APT attack by predicting the corresponding kill chain stage. For monitored security activity and events, our approach derives a probabilistic anomaly score using an approach based on principal component analysis (PCA) and score calibration and classifying the event with a multi-class type of Bayesian Network (BN). We evaluate the proposed model using two different public APT datasets, which yielded very encouraging performance in accurately detecting APT event occurrences and stages. | en_US |
| dc.description.scholarlevel | Graduate | en_US |
| dc.identifier.uri | http://hdl.handle.net/1828/15036 | |
| dc.language | English | eng |
| dc.language.iso | en | en_US |
| dc.rights | Available to the World Wide Web | en_US |
| dc.subject | Score | en_US |
| dc.subject | Calibration | en_US |
| dc.subject | Multi-class Classification | en_US |
| dc.subject | Bayesian network | en_US |
| dc.subject | PCA | en_US |
| dc.subject | APTs | en_US |
| dc.title | Advanced Persistent Threat Detection using Anomaly Score Calibration and Multi-class Classification | en_US |
| dc.type | Thesis | en_US |
Files
Original bundle
1 - 1 of 1
Loading...
- Name:
- Soh_Ornella_MASc_2023.pdf
- Size:
- 477.01 KB
- Format:
- Adobe Portable Document Format
- Description:
- APTs detection using Machine Learning algorithms.
License bundle
1 - 1 of 1
No Thumbnail Available
- Name:
- license.txt
- Size:
- 2 KB
- Format:
- Item-specific license agreed upon to submission
- Description: