{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,27]],"date-time":"2026-06-27T19:01:14Z","timestamp":1782586874786,"version":"3.54.5"},"reference-count":55,"publisher":"SAGE Publications","issue":"3","license":[{"start":{"date-parts":[[2020,7,7]],"date-time":"2020-07-07T00:00:00Z","timestamp":1594080000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/journals.sagepub.com\/page\/policies\/text-and-data-mining-license"}],"content-domain":{"domain":["journals.sagepub.com"],"crossmark-restriction":true},"short-container-title":["Journal of Intelligent &amp; Fuzzy Systems"],"published-print":{"date-parts":[[2020,10,7]]},"abstract":"<jats:p>Advanced Persistent Threat (APT) attacks are a form of malicious, intentionally and clearly targeted attack. This attack technique is growing in both the number of recorded attacks and the extent of its dangers to organizations, businesses and governments. Therefore, the task of detecting and warning APT attacks in the real system is very necessary today. One of the most effective approaches to APT attack detection is to apply machine learning or deep learning to analyze network traffic. There have been a number of studies and recommendations to analyze network traffic into network flows and then combine with some classification or clustering methods to look for signs of APT attacks. In particular, recent studies often apply machine learning algorithms to spot the present of APT attacks based on network flow. In this paper, a new method based on deep learning to detect APT attacks using network flow is proposed. Accordingly, in our research, network traffic is analyzed into IP-based network flows, then the IP information is reconstructed from flow, and finally deep learning models are used to extract features for detecting APT attack IPs from other IPs. Additionally, a combined deep learning model using Bidirectional Long Short-Term Memory (BiLSTM) and Graph Convolutional Networks (GCN) is introduced. The new detection model is evaluated and compared with some traditional machine learning models, i.e. Multi-layer perceptron (MLP) and single GCN models, in the experiments. Experimental results show that BiLSTM-GCN model has the best performance in all evaluation scores. This not only shows that deep learning application on flow network analysis to detect APT attacks is a good decision but also suggests a new direction for network intrusion detection techniques based on deep learning.<\/jats:p>","DOI":"10.3233\/jifs-200694","type":"journal-article","created":{"date-parts":[[2020,7,7]],"date-time":"2020-07-07T11:10:33Z","timestamp":1594120233000},"page":"4785-4801","update-policy":"https:\/\/doi.org\/10.1177\/sage-journals-update-policy","source":"Crossref","is-referenced-by-count":40,"title":["APT attack detection based on flow network analysis techniques using deep learning"],"prefix":"10.1177","volume":"39","author":[{"given":"Cho","family":"Do Xuan","sequence":"first","affiliation":[{"name":"Faculty of Information Technology, Posts and Telecommunications Institute of Technology, Hanoi, Vietnam"},{"name":"Department of Information Assurance, FPT University, Hanoi, Vietnam"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mai Hoang","family":"Dao","sequence":"additional","affiliation":[{"name":"Faculty of Information Technology, Posts and Telecommunications Institute of Technology, Hanoi, Vietnam"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Hoa Dinh","family":"Nguyen","sequence":"additional","affiliation":[{"name":"Faculty of Information Technology, Posts and Telecommunications Institute of Technology, Hanoi, Vietnam"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"179","published-online":{"date-parts":[[2020,7,7]]},"reference":[{"key":"e_1_3_1_2_2","first-page":"1","article-title":"A Survey on Advanced Persistent Threats: Techniques, Solutions, Challenges, and Research Opportunities","volume":"1","author":"Alshamrani A.","year":"2019","unstructured":"AlshamraniA., ChowdharyA., MyneniS. and HuangD., A Survey on Advanced Persistent Threats: Techniques, Solutions, Challenges, and Research Opportunities, IEEE Communications Surveys & Tutorials 1 (2019), 1\u201329.","journal-title":"IEEE Communications Surveys & Tutorials"},{"key":"e_1_3_1_3_2","unstructured":"CodeE. Advanced Persistent Threat Understanding the Danger and How to Protect Your Organization 1rd ed.; Elsevier Amsterdam (2012)."},{"key":"e_1_3_1_4_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2016.05.018"},{"key":"e_1_3_1_5_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.procs.2019.02.058"},{"key":"e_1_3_1_6_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2014.09.006"},{"key":"e_1_3_1_7_2","doi-asserted-by":"publisher","DOI":"10.1155\/2017\/4916953"},{"key":"e_1_3_1_8_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2015.2458581"},{"key":"e_1_3_1_9_2","first-page":"519","article-title":"\u015e. Bahtiyar, A Flow Based Approach to Detect Advanced Persistent Threats in Communication Systems","volume":"22","year":"2018","unstructured":"\u015e. Bahtiyar, A Flow Based Approach to Detect Advanced Persistent Threats in Communication Systems, Journal of Natural & Applied Sciences 22 (2018), 519\u2013528.","journal-title":"Journal of Natural & Applied Sciences"},{"key":"e_1_3_1_10_2","doi-asserted-by":"crossref","unstructured":"MilajerdiS.M. GjomemoR. EsheteB. and SekarR. HOLMES: Real-time APT Detection through Correlation of Suspicious Information Flows In Proceedings Of The 2019 Ieee Symposium On Security And Privacy (Sp) San Francisco CA USA USA 19\u201323 (2019) 1137\u20131152.","DOI":"10.1109\/SP.2019.00026"},{"key":"e_1_3_1_11_2","first-page":"45","article-title":"Detection and Classification of Advanced Persistent Threats and Attacks Using the Support Vector Machine","volume":"21","author":"Chu W.-L.","year":"2019","unstructured":"ChuW.-L., LinC.-J. and ChangK.-N., Detection and Classification of Advanced Persistent Threats and Attacks Using the Support Vector Machine, Applied Sciences 21 (2019), 45\u201379.","journal-title":"Applied Sciences"},{"key":"e_1_3_1_12_2","doi-asserted-by":"publisher","DOI":"10.3390\/app9061055"},{"key":"e_1_3_1_13_2","doi-asserted-by":"publisher","DOI":"10.1002\/nem.2039"},{"key":"e_1_3_1_14_2","unstructured":"Office of National science and technology research programs - News detail. Available online: http:\/\/www.vpct.gov.vn\/NewsDetail.html?newsId=392 (accessed on 28 December 2019)."},{"key":"e_1_3_1_15_2","doi-asserted-by":"crossref","unstructured":"BeigiE.B. JaziH.H. NataliaS. and AliA. Towards Effective Feature Selection in Machine Learning-Based Botnet Detection Approaches In Proceedings of the 2014 IEEE Conference on Communications and Network Security San Francisco CA USA 29\u201331 October (2014) 247\u2013255.","DOI":"10.1109\/CNS.2014.6997492"},{"key":"e_1_3_1_16_2","unstructured":"CIC Flow Meter. Available online: http:\/\/www.netflowmeter.ca\/netflowmeter.html (accessed on 1 December 2019)."},{"key":"e_1_3_1_17_2","unstructured":"LashkariA.H. Draper-GilG. MamunM.S.I. and GhorbaniA.A. Characterization of Tor Traffic Using Time Based Features In Proceedings of the 3rd International Conference on Information System Security and Privacy Porto Portugal January (2017) 253\u2013262."},{"key":"e_1_3_1_18_2","unstructured":"GilG.D. LashkariA.H. MamunM. and GhorbaniA.A. Characterization of Encrypted and VPN Traffic Using Time-Related Features In Proceedings of the 2nd International Conference on Information Systems Security and Privacy (ICISSP 2016) Rome Italy 20 February (2016) 407\u2013414."},{"key":"e_1_3_1_19_2","doi-asserted-by":"publisher","DOI":"10.1561\/2000000039"},{"key":"e_1_3_1_20_2","doi-asserted-by":"publisher","DOI":"10.9781\/ijimai.2016.415"},{"key":"e_1_3_1_21_2","unstructured":"AgarapA.F. Deep Learning using Rectified Linear Units (ReLU) arXiv (2018) arXiv:1803.08375."},{"key":"e_1_3_1_22_2","doi-asserted-by":"crossref","unstructured":"Duan;K. KeerthiS. ChuW. ShevadeS.K. and PooA.N. Multi-category Classification by Soft-Max Combination of Binary Classifiers In Proceedings of the 4th International Workshop MCS 2003 Guildford UK 11\u201313 (2003) 125\u2013134.","DOI":"10.1007\/3-540-44938-8_13"},{"key":"e_1_3_1_23_2","unstructured":"ThomasN.K. and WellingM. Semi-Supervised Classification with Graph Convolutional Networks arXiv (2017) arXiv:1609.02907."},{"key":"e_1_3_1_24_2","doi-asserted-by":"crossref","unstructured":"MarcheggianiD. and TitovI. Encoding Sentences with Graph Convolutional Networks for Semantic Role Labeling In Proceedings of the 2017 Conference on Empirical Methods in Natural Language Processing Copenhagen Denmark 7\u201311 (2017) 1506\u20131515.","DOI":"10.18653\/v1\/D17-1159"},{"key":"e_1_3_1_25_2","doi-asserted-by":"publisher","DOI":"10.1162\/neco.1997.9.8.1735"},{"key":"e_1_3_1_26_2","doi-asserted-by":"crossref","unstructured":"GravesA. MohamedA. and HintonG. Speech Recognition with Deep Recurrent Neural Networks. In Proceedings of the 2013 IEEE International Conference on Acoustics Speech and Signal Processing Vancouver BC Canada 26\u201331 (2013) 6645\u20136649.","DOI":"10.1109\/ICASSP.2013.6638947"},{"key":"e_1_3_1_27_2","doi-asserted-by":"crossref","unstructured":"CornegrutaS. BakewellR. WitheyS. and MontanaG. Modelling Radiological Language with Bidirectional Long Short-Term Memory Networks arXiv (2017) arXiv: 1609.08409.","DOI":"10.18653\/v1\/W16-6103"},{"key":"e_1_3_1_28_2","unstructured":"Malware Capture Facility Project. Available online: https:\/\/www.stratosphereips.org\/datasets-malware. (accessed on 11 December 2019)."},{"key":"e_1_3_1_29_2","unstructured":"Quang Nam Portal. Available online: http:\/\/english.quangnam.gov.vn\/default.aspx (accessed on 30 December 2019)."},{"key":"e_1_3_1_30_2","article-title":"Early Detection of Cyber Security Threats using Structured Behavior Modeling","volume":"5","author":"Yan X.","year":"2013","unstructured":"YanX. and ZhangJ.Y., Early Detection of Cyber Security Threats using Structured Behavior Modeling, ACM Transactions on Information and System Security 5 (2013), Article A.","journal-title":"ACM Transactions on Information and System Security"},{"key":"e_1_3_1_31_2","doi-asserted-by":"crossref","unstructured":"JohnsonJ.R. and HoganE.A. A graph analytic metric for mitigating advanced persistent threat In Proceedings of the 2013 IEEE International Conference on Intelligence and Security Informatics Seattle WA USA 4\u20137 (2013) 129\u2013133.","DOI":"10.1109\/ISI.2013.6578801"},{"key":"e_1_3_1_32_2","doi-asserted-by":"crossref","unstructured":"IngolsK. LippmannR. and PiwowarskiK. Practical attack graph generation for network defense In Proceedings of the 2006 22nd Annual Computer Security Applications Conference (ACSAC\u201906) Miami Beach FL USA 26 December (2006) 121\u2013130.","DOI":"10.1109\/ACSAC.2006.39"},{"key":"e_1_3_1_33_2","doi-asserted-by":"crossref","unstructured":"AlbaneseM. JajodiaS. and NoelS. Time-efficient and cost-effective network hardening using attack graphs In Proceedings of the IEEE\/IFIP International Conference on Dependable Systems and Networks (DSN 2012). Boston MA USA 25\u201328 (2012) 1\u201312.","DOI":"10.1109\/DSN.2012.6263942"},{"key":"e_1_3_1_34_2","doi-asserted-by":"crossref","unstructured":"OuX. BoyerW.F. and McQueenM.A. Ascalable approach to attack graph generation In Proceedings of the 13th ACM conference on Computer and communications security. Alexandria Virginia USA (2006) pp. 336\u2013345.","DOI":"10.1145\/1180405.1180446"},{"key":"e_1_3_1_35_2","unstructured":"Jehyun LeeJ. LeeH. and H.P. In Scalable attack graph for risk assessment In Proceedings of the 2009 International Conference on Information Networking Chiang Mai India 21\u201324 (2009) 1\u20135."},{"key":"e_1_3_1_36_2","unstructured":"JhaS. SheynerO. and WingJ. Two formal analyses of attack graphs In Proceedings of the 15th IEEE Computer Security Foundations Workshop Cape Breton NS Canada Canada 24\u201326 (2002) 49\u201363"},{"key":"e_1_3_1_37_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-88313-5_2"},{"key":"e_1_3_1_38_2","doi-asserted-by":"crossref","unstructured":"DewanP. KashyapA. and KumaraguruP. Analyzing social and stylometric features to identify spear phishing emails In Proceedings of the 2014 APWG Symposiumon Electronic Crime Research (eCrime) Birmingham AL USA 23\u201325 (2014) 1\u201313.","DOI":"10.1109\/ECRIME.2014.6963160"},{"key":"e_1_3_1_39_2","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2019.2957750"},{"key":"e_1_3_1_40_2","doi-asserted-by":"crossref","unstructured":"JainA.K. and GuptaB.B. Phishing Detection: Analysis of Visual Similarity Based Approaches Security and Communication Networks (2017) Article ID 5421046 20 pages.","DOI":"10.1155\/2017\/5421046"},{"key":"e_1_3_1_41_2","first-page":"1","article-title":"Detecting Lateral Spear Phishing Attacks in Organizations","volume":"13","author":"Bhadane A.","year":"2018","unstructured":"BhadaneA. and ManeS.B., Detecting Lateral Spear Phishing Attacks in Organizations, IET Information Security 13 (2018), 1\u20138.","journal-title":"IET Information Security"},{"key":"e_1_3_1_42_2","unstructured":"HoG. SharmaA. JavedM. PaxsonV. and WagnerD. Detecting Credential Spearphishing Attacks in Enterprise Settings In Proceedings of the 26th USENIX Conference on Security Symposium CA United States (2017) 469\u2013485."},{"key":"e_1_3_1_43_2","doi-asserted-by":"crossref","unstructured":"ZhangR. HuoY. LiuJ. and WengF. Constructing APT Attack Scenarios Based on Intrusion Kill Chain and Fuzzy Clustering Security and Communication Networks (2017) Article ID 7536381 9 pages.","DOI":"10.1155\/2017\/7536381"},{"key":"e_1_3_1_44_2","doi-asserted-by":"publisher","DOI":"10.1080\/01969722.2018.1552906"},{"key":"e_1_3_1_45_2","unstructured":"TuorA. KaplanS. HutchinsonB. NicholsN. and RobinsonS. Deep Learning for Unsupervised Insider Threat Detection in StructuredCybersecurityData Streams In Proceedings of the AAAI-17Workshop on Artificial Intelligence for Cyber Security WS-17-04 San Francisco CA USA February 4\u20135 (2017)."},{"key":"e_1_3_1_46_2","first-page":"1","article-title":"Discovering Suspicious APT Behaviors by Analyzing DNS Activities","volume":"20","author":"Yan G.","year":"2020","unstructured":"YanG., LiQ., GuoD. and MengX., Discovering Suspicious APT Behaviors by Analyzing DNS Activities, Sensors 20 (2020), 1\u201317.","journal-title":"Sensors"},{"key":"e_1_3_1_47_2","doi-asserted-by":"crossref","unstructured":"EkeH.N. PetrovskiA. and AhrizH. The use of machine learning algorithms for detecting advanced persistent threats In Proceedings of the 12th International on Security of Information and Networks Conference 2019 (SINCONF 2019) Sochi Russia. 12\u201315 (2019) pp. 1\u20138.","DOI":"10.1145\/3357613.3357618"},{"key":"e_1_3_1_48_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.future.2018.06.055"},{"key":"e_1_3_1_49_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2018.2847671"},{"key":"e_1_3_1_50_2","first-page":"1","article-title":"A temporal correlation and traffic analysis approach for APT attacks detection","volume":"20","author":"Lu J.","year":"2017","unstructured":"LuJ., ChenK., ZhuoZ. and ZhangX., A temporal correlation and traffic analysis approach for APT attacks detection, Cluster Computing 20 (2017), 1\u201312.","journal-title":"Cluster Computing"},{"key":"e_1_3_1_51_2","doi-asserted-by":"publisher","DOI":"10.3233\/JCS-191293"},{"key":"e_1_3_1_52_2","doi-asserted-by":"publisher","DOI":"10.3233\/JIFS-169431"},{"key":"e_1_3_1_53_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2020.101734"},{"key":"e_1_3_1_54_2","doi-asserted-by":"crossref","unstructured":"Y\u00fcksel\u00d6. den HartogJ. and EtalleS. Reading between the fields: practical effective intrusion detection for industrial control systems In Proceedings of the 31st Annual ACM Symposium on Applied Computing Pisa Italy April (2016) 2063\u20132070.","DOI":"10.1145\/2851613.2851799"},{"key":"e_1_3_1_55_2","doi-asserted-by":"crossref","unstructured":"SchneiderP. and B\u00f6ttingerK. High-performance unsupervised anomaly detection for cyber-physical system networks In Proceedings of the 2018 Workshop on Cyber-Physical Systems Security and PrivaCy Toronto Canada (2018) 1\u201312.","DOI":"10.1145\/3264888.3264890"},{"key":"e_1_3_1_56_2","first-page":"22","article-title":"Detecting C&C Server in the APT Attack based on Network Traffic using Machine Learning","volume":"11","author":"Do Xuan C.","year":"2020","unstructured":"Do XuanC., Van DuongL. and NikolaevichT.V., Detecting C&C Server in the APT Attack based on Network Traffic using Machine Learning, International Journal of Advanced Computer Science and Applications 11 (2020), 22\u201327.","journal-title":"International Journal of Advanced Computer Science and Applications"}],"container-title":["Journal of Intelligent &amp; Fuzzy Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/journals.sagepub.com\/doi\/pdf\/10.3233\/JIFS-200694","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/journals.sagepub.com\/doi\/full-xml\/10.3233\/JIFS-200694","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/journals.sagepub.com\/doi\/pdf\/10.3233\/JIFS-200694","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,29]],"date-time":"2026-04-29T09:40:45Z","timestamp":1777455645000},"score":1,"resource":{"primary":{"URL":"https:\/\/journals.sagepub.com\/doi\/10.3233\/JIFS-200694"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,7,7]]},"references-count":55,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2020,10,7]]}},"alternative-id":["10.3233\/JIFS-200694"],"URL":"https:\/\/doi.org\/10.3233\/jifs-200694","relation":{},"ISSN":["1064-1246","1875-8967"],"issn-type":[{"value":"1064-1246","type":"print"},{"value":"1875-8967","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020,7,7]]}}}