NUST Institutional Repository

Machine Learning based Advanced Persistent Threats (APT) detection in Windows

Show simple item record

dc.contributor.author Hassan, Madiha
dc.date.accessioned 2024-07-22T06:21:40Z
dc.date.available 2024-07-22T06:21:40Z
dc.date.issued 2024-07-22
dc.identifier.other 00000400918
dc.identifier.uri http://10.250.8.41:8080/xmlui/handle/123456789/44845
dc.description Supervised by Associate Prof Dr. Mian Muhammad Waseem Iqbal en_US
dc.description.abstract Advanced Persistent Threats (APTs) turns into significant and ongoing concern of cyber security as the smart threat actors use advance ways to infiltrate and persist within targeted systems for a longer period of time. Every APT attack goes through various stages before its completion making it difficult for conventional signature-based techniques and rule-based intrusion detection systems to recognize these elusive threats. Machine learning (ML) techniques are utilized in recent past for the detection of the APTs in Windows environment using Network based detection. Due to the limited information extracted from network data, less known features are used by ML algorithms for detection therefore evading security systems. Therefore, this research focus on finding sophisticated new features that can aid in identifying the latest APTs in Windows environment. ML models like Random forest (RF), Convolution Neural Network(CNN), Naïve Bayes (NB), Multi-Layer Perceptron (MLP) and Long short-term Memory (LSTM) with different encoding techniques (Frequency, Label, and Hot) are utilized for detection of the Windows APTs. Results show that MLP model using Label encoding, accomplished the highest accuracy i.e., (95.45%) and F1 score (95.267%), highlighting the potential of neural network in APT detection. These result validate the proposed model’s efficiency, feature selection, and data pre-processing in building effective Windows based security solutions. en_US
dc.language.iso en en_US
dc.publisher MCS en_US
dc.title Machine Learning based Advanced Persistent Threats (APT) detection in Windows en_US
dc.type Thesis en_US


Files in this item

This item appears in the following Collection(s)

Show simple item record

Search DSpace


Advanced Search

Browse

My Account