Feasibility Approach Based on SecMonet Framework to Protect Networks from Advanced Persistent Threat Attacks

2Citations
Citations of this article
4Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Advanced Persistent Threat (APT) principally steal data once the attacker gains unauthorized access to network resources. In this paper, we propose a detection and defense technique based on SecMonet framework to avoid this sophisticated attack. SecMonet is a security framework that can gather events and flows, normalize them, create a valuable dataset, train a classifier based neural networks, and detect and defend against APT attacks. In this regard, log data from logging servers or Firewall has been considered by SecMonet. In addition, a ranking criterion for detected suspicious activities has been also considered by the classifier to detect APT attack. The proposed method has been evaluated by a local simulated network and by a real network scenario. The result shows that the proposed technique can significantly detected APT attacks.

Cite

CITATION STYLE

APA

Salem, M., & Mohammed, M. (2019). Feasibility Approach Based on SecMonet Framework to Protect Networks from Advanced Persistent Threat Attacks. In Lecture Notes on Data Engineering and Communications Technologies (Vol. 29, pp. 333–343). Springer Science and Business Media Deutschland GmbH. https://doi.org/10.1007/978-3-030-12839-5_30

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free