Advanced Persistent Threat Identification with Boosting and Explainable AI

10Citations
Citations of this article
46Readers
Mendeley users who have this article in their library.

This article is free to access.

Abstract

Advanced persistent threat (APT) is a serious concern in cyber-security that has matured and grown over the years with the advent of technology. The main aim of this study is to establish an effective identification model for APT attacks to prevent and reduce their influence. Machine learning has the potential as well as substantial background to detect and predict cyber-security threats including APT. This study utilized several boosting-based machine learning methods to predict various types of APTs that are consistent in cyber-security domain. Furthermore, Explainable Artificial Intelligence (XAI) was coupled with the predictions to provide actionable insights to the domain stakeholders as well as practitioners in this domain. The results, particularly XGBoost with weighted F1 score of 0.97 and SHapley Additive exPlanations (SHAP)-based explanation, prove that boosting methods as well as machine learning models paired with XAI are indeed promising in handling cyber-security-related dataset problems which can be extrapolated towards new avenues of challenging research by effectively deploying boosting-based XAI models.

Cite

CITATION STYLE

APA

Hasan, M. M., Islam, M. U., & Uddin, J. (2023). Advanced Persistent Threat Identification with Boosting and Explainable AI. SN Computer Science, 4(3). https://doi.org/10.1007/s42979-023-01744-x

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free