{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,12]],"date-time":"2026-08-12T17:10:27Z","timestamp":1786554627751,"version":"3.56.0"},"reference-count":38,"publisher":"SAGE Publications","issue":"3","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IFS"],"published-print":{"date-parts":[[2023,3,9]]},"abstract":"<jats:p>Advanced Persistent Threat (APT) attack detection and monitoring has attracted a lot of attention recently when this type of cyber-attacks is growing in both number and dangerous levels. In this paper, a new APT attack model, which is the combination of three different neural network layers including: Multi-layer Perceptron (MLP), Inference (I), and Graph Convolutional Networks (GCN) is proposed. The new model is named MIG for short. In this model, the MLP layer is in charge of aggregating and extracting properties of the IPs based on flow network in Network traffic, while the Inference layer is responsible for building IP information profiles by grouping and concatenating flow networks generated from the same IP. Finally, the GCN layer is used for analyzing and reconstructing IP features based on the behavior extraction process from IP information records. The APT attacks detection method based on network traffic using this MIG model is new, and has yet been proposed and applied anywhere. The novelty and uniqueness of this method is the combination of many different data mining techniques in order to calculate, extract and represent the relationship and the correlation between APT attack behaviors based on Network traffic. In MIG model, many meaningful anomalous properties and behaviors of APT attacks are synthesized and extracted, which help improve the performance of APT attack detection. The experimental results showed that the proposed method is meaningful in both theory and practice since the MIG model not only improves the ability to correctly detect APT attacks in network traffic but also minimizes false alarms.<\/jats:p>","DOI":"10.3233\/jifs-221055","type":"journal-article","created":{"date-parts":[[2022,11,25]],"date-time":"2022-11-25T09:58:34Z","timestamp":1669370314000},"page":"3459-3474","source":"Crossref","is-referenced-by-count":16,"title":["A new framework for APT attack detection based on network traffic"],"prefix":"10.1177","volume":"44","author":[{"given":"Hoa Cuong","family":"Nguyen","sequence":"first","affiliation":[{"name":"Faculty of Information Science And Engineering, Yunnan University, China"},{"name":"Faculty of Information Security, Posts and Telecommunications Institute of Technology Hanoi, Vietnam"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Cho Do","family":"Xuan","sequence":"additional","affiliation":[{"name":"Faculty of Information Security, Posts and Telecommunications Institute of Technology Hanoi, Vietnam"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Long Thanh","family":"Nguyen","sequence":"additional","affiliation":[{"name":"Faculty of Information Technology, Posts and Telecommunications Institute of Technology Hanoi, Vietnam"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Hoa Dinh","family":"Nguyen","sequence":"additional","affiliation":[{"name":"Faculty of Information Technology, Posts and Telecommunications Institute of Technology Hanoi, Vietnam"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"179","reference":[{"issue":"2","key":"10.3233\/JIFS-221055_ref1","doi-asserted-by":"crossref","first-page":"1851","DOI":"10.1109\/COMST.2019.2891891","article-title":"Asurvey on advanced persistent threats: techniques, solutions,challenges, and research opportunities","volume":"21","author":"Adel Alshamrani","year":"2019","journal-title":"IEEE Comm Surveys &Tutorials"},{"key":"10.3233\/JIFS-221055_ref3","doi-asserted-by":"crossref","first-page":"26","DOI":"10.1016\/j.cose.2017.08.005","article-title":"Survey of publicly available reports on advanced persistentthreat actors","volume":"72","author":"Lemay","year":"2018","journal-title":"Computers & Security"},{"key":"10.3233\/JIFS-221055_ref4","doi-asserted-by":"crossref","first-page":"38","DOI":"10.3390\/app10113874","article-title":"A New Proposal on theAdvanced Persistent Threat: A Survey","volume":"10","author":"Quintero Bonilla","year":"2020","journal-title":"Applied Sciences"},{"issue":"6","key":"10.3233\/JIFS-221055_ref5","doi-asserted-by":"crossref","first-page":"1163","DOI":"10.1109\/TDSC.2018.2858786","article-title":"A risk management approach to defending against the advanced persistent threat","volume":"17","author":"Yang","year":"2020","journal-title":"IEEE Transactions on Dependable and Secure Computing"},{"key":"10.3233\/JIFS-221055_ref7","doi-asserted-by":"crossref","first-page":"501","DOI":"10.1016\/j.future.2020.01.032","article-title":"Modeling and detection of the multi-stages of Advanced Persistent Threats attacks based on semi-supervised learning and complex networks characteristics","volume":"106","author":"Zimba","year":"2020","journal-title":"Future Generation Computer Systems"},{"key":"10.3233\/JIFS-221055_ref8","doi-asserted-by":"crossref","first-page":"349","DOI":"10.1016\/j.future.2018.06.055","article-title":"Detection of advanced persistent threat using machine-learning correlation analysis","volume":"89","author":"Ibrahim Ghafir","year":"2018","journal-title":"Future Generation Computer Systems"},{"key":"10.3233\/JIFS-221055_ref9","doi-asserted-by":"crossref","first-page":"64","DOI":"10.1016\/j.future.2019.01.056","article-title":"A semantic-based correlation approach for detecting hybrid and low-level APTs","volume":"96","author":"Lajevardi","year":"2019","journal-title":"Future Generation Computer Systems"},{"key":"10.3233\/JIFS-221055_ref10","doi-asserted-by":"crossref","unstructured":"Juan Enrique Rubio , Cristina Alcaraz , Rodrigo Roman and Javier Lopez , Current cyber-defense trends in industrial control systems, Computers & Security 87 (2019), https:\/\/doi.org\/10.1016\/j.cose.2019.06.015","DOI":"10.1016\/j.cose.2019.06.015"},{"issue":"3","key":"10.3233\/JIFS-221055_ref11","doi-asserted-by":"crossref","first-page":"646","DOI":"10.1109\/TIFS.2018.2847671","article-title":"An Intelligence-Driven Security-Aware Defense Mechanism for Advanced Persistent Threats","volume":"14","author":"Yuqing Li","year":"2019","journal-title":"IEEE Transactions on Information Forensics and Security"},{"key":"10.3233\/JIFS-221055_ref12","doi-asserted-by":"crossref","first-page":"149","DOI":"10.1016\/j.neucom.2019.02.056","article-title":"Application of deep learning to cybersecurity: A survey","volume":"347","author":"Samaneh Mahdavifar","year":"2019","journal-title":"Neurocomputing"},{"key":"10.3233\/JIFS-221055_ref13","doi-asserted-by":"crossref","first-page":"316","DOI":"10.1016\/j.procs.2019.02.058","article-title":"A Method of Monitoring and Detecting APT Attacks Based on Unknown Domains","volume":"150","author":"Do Xuan Cho","year":"2019","journal-title":"Procedia Computer Science"},{"issue":"6","key":"10.3233\/JIFS-221055_ref14","doi-asserted-by":"crossref","first-page":"11311","DOI":"10.3233\/JIFS-202465","article-title":"A Multi Layer Approach for Advanced Persistent Threat Detection Using Machine Learning Based on Network Traffic","volume":"40","author":"Cho Do Xuan","year":"2021","journal-title":"Journal of Intelligent & Fuzzy Systems"},{"issue":"1","key":"10.3233\/JIFS-221055_ref15","first-page":"171","article-title":"Detecting APT Attacks Based on Network Traffic Using Machine Learning","volume":"20","author":"Cho Do Xuan","year":"2021","journal-title":"Journal of Web Engineering"},{"key":"10.3233\/JIFS-221055_ref16","doi-asserted-by":"crossref","first-page":"35","DOI":"10.1016\/j.cose.2014.09.006","article-title":"Combating advanced persistent threats: From network eventcorrelation to incident detection","volume":"48","author":"Ivo Friedberg","year":"2015","journal-title":"Computers & Security"},{"key":"10.3233\/JIFS-221055_ref17","doi-asserted-by":"crossref","first-page":"127","DOI":"10.1016\/j.comnet.2016.05.018","article-title":"Analysis of high volumes of network traffic for Advanced Persistent Threat detection","volume":"109","author":"Marchetti","year":"2016","journal-title":"Computer Networks"},{"key":"10.3233\/JIFS-221055_ref18","doi-asserted-by":"crossref","unstructured":"Juan Enrique Rubio , Cristina Alcaraz , Rodrigo Roman and Javier Lopez , Current cyber-defense trends in industrial control systems, Computers & Security 87 (2019), https:\/\/doi.org\/10.1016\/j.cose.2019.06.015","DOI":"10.1016\/j.cose.2019.06.015"},{"key":"10.3233\/JIFS-221055_ref20","doi-asserted-by":"crossref","first-page":"57","DOI":"10.1016\/j.aiopen.2021.01.001","article-title":"Graph neural networks: A review of methods and applications","volume":"1","author":"Jie Zhou","year":"2020","journal-title":"AI Open"},{"issue":"3","key":"10.3233\/JIFS-221055_ref21","doi-asserted-by":"crossref","first-page":"4785","DOI":"10.3233\/JIFS-200694","article-title":"APT attack detection based on flow network analysis techniques using deep learning","volume":"39","author":"Cho Do Xuan","year":"2020","journal-title":"Journal of Intelligent & Fuzzy Systems"},{"key":"10.3233\/JIFS-221055_ref22","doi-asserted-by":"crossref","unstructured":"Tero Bodstr\u00f6m and Timo H\u00e4m\u00e4l\u00e4inen , ANovel Deep Learning Stack for APT Detection, Applied Sciences 9(6) (2019), https:\/\/doi.org\/10.3390\/app9061055","DOI":"10.3390\/app9061055"},{"key":"10.3233\/JIFS-221055_ref23","doi-asserted-by":"crossref","unstructured":"Wen-Lin Chu , Chih-Jer Lin and Ke-Neng Chang , Detection and Classification of Advanced Persistent Threats and Attacks Using the Support Vector Machine, Applied Sciences 9(21) (2019), https:\/\/doi.org\/10.3390\/app9214579","DOI":"10.3390\/app9214579"},{"key":"10.3233\/JIFS-221055_ref25","doi-asserted-by":"crossref","unstructured":"Guanghua Yan , Qiang Li , Dong Guo and Xiangyu Meng , Discovering Suspicious APT Behaviors by Analyzing DNS Activities, Sensors 20(3) (2020), https:\/\/doi.org\/10.3390\/s20030731","DOI":"10.3390\/s20030731"},{"key":"10.3233\/JIFS-221055_ref27","doi-asserted-by":"crossref","first-page":"51","DOI":"10.1016\/j.neucom.2019.11.016","article-title":"A novel statistical analysis and autoencoder driven intelligent intrusion detection approach","volume":"387","author":"Cosimo Ieracitano","year":"2020","journal-title":"Neurocomputing"},{"key":"10.3233\/JIFS-221055_ref28","doi-asserted-by":"crossref","first-page":"186125","DOI":"10.1109\/ACCESS.2020.3029202","article-title":"Early detection of the advanced persistent threat attack using performance analysis of deep learning","volume":"8","author":"Hassannataj Joloudari","year":"2020","journal-title":"IEEE Access"},{"key":"10.3233\/JIFS-221055_ref30","first-page":"11","article-title":"DL-IDS: Extracting Features Using CNN-LSTM Hybrid Network for Intrusion Detection System","volume":"2020","author":"Pengfei Sun","year":"2020","journal-title":"Security and Communication Networks. Special Issue: Security Threats to Artificial Intelligence-Driven Wireless Communication Systems"},{"key":"10.3233\/JIFS-221055_ref31","doi-asserted-by":"crossref","first-page":"13251","DOI":"10.1007\/s00521-021-05952-5","article-title":"A novel approach for APT attack detection based on combined deep learning model","volume":"33","author":"Do Xuan","year":"2021","journal-title":"Neural Comput & Applic"},{"key":"10.3233\/JIFS-221055_ref34","doi-asserted-by":"crossref","first-page":"704","DOI":"10.3390\/electronics10060704","article-title":"The influences of feature sets on the detection of advanced persistent threats","volume":"10","author":"Hofer-Schmitz","year":"2021","journal-title":"Electronics"},{"key":"10.3233\/JIFS-221055_ref35","doi-asserted-by":"crossref","first-page":"100067","DOI":"10.1016\/j.array.2021.100067","article-title":"Advanced Persistent Threat attack detection method in cloud computing based on autoencoder and softmax regression algorithm","volume":"10","author":"Fargana Abdullayeva","year":"2021","journal-title":"Array"},{"key":"10.3233\/JIFS-221055_ref36","doi-asserted-by":"crossref","first-page":"107937","DOI":"10.1016\/j.comnet.2021.107937","article-title":"Discovering unknown advanced persistent threat using shared features mined by neural networks","volume":"189","author":"Longkang Shang","year":"2021","journal-title":"Computer Networks"},{"key":"10.3233\/JIFS-221055_ref37","doi-asserted-by":"crossref","first-page":"633","DOI":"10.1016\/j.ins.2020.08.095","article-title":"APT MalInsight: Identify and cognize APT malware based on system call information and ontology knowledge framework","volume":"546","author":"Weijie Han","year":"2021","journal-title":"Information Sciences"},{"key":"10.3233\/JIFS-221055_ref38","doi-asserted-by":"publisher","first-page":"162642","DOI":"10.1109\/ACCESS.2020.3021499","article-title":"\u201cAlerts Correlation and Causal Analysis for APT Based Cyber Attack Detection,\u201d","volume":"8","author":"Khosravi","year":"2020","journal-title":"in IEEE Access"},{"key":"10.3233\/JIFS-221055_ref39","doi-asserted-by":"publisher","first-page":"42919","DOI":"10.1109\/ACCESS.2021.3066289","article-title":"\u201cSBI Model for the Detection of Advanced Persistent Threat Based on Strange Behavior of Using Credential Dumping Technique,\u201d","volume":"9","author":"Mohamed","year":"2021","journal-title":"in IEEE Access"},{"issue":"1","key":"10.3233\/JIFS-221055_ref43","doi-asserted-by":"crossref","first-page":"43","DOI":"10.1016\/S0169-7439(97)00061-0","article-title":"Introduction to multi-layer feed-forward neural networks","volume":"39","author":"Daniel Svozil","year":"1997","journal-title":"Chemometrics and Intelligent Laboratory Systems"},{"issue":"1","key":"10.3233\/JIFS-221055_ref44","doi-asserted-by":"crossref","first-page":"26","DOI":"10.9781\/ijimai.2016.415","article-title":"Mohamed Ettaouil, Multilayer Perceptron: Architecture Optimization and Training","volume":"4","author":"Hassan Ramchoun","year":"2016","journal-title":"International Journal of Interactive Multimedia and Artificial Intelligence"},{"key":"10.3233\/JIFS-221055_ref45","first-page":"81","article-title":"A walk-based model on entity graphs for relation extraction. In Proceedings of the Annual Meeting of the Association for Computational Linguistics","volume":"2","author":"Fenia Christopoulou","year":"2018","journal-title":"Association for Computational Linguistics"},{"issue":"5","key":"10.3233\/JIFS-221055_ref50","doi-asserted-by":"crossref","first-page":"1252","DOI":"10.1109\/TMI.2016.2548501","article-title":"AutomaticSegmentation of MR Brain Images With a Convolutional Neural Network","volume":"35","author":"Pim Moeskops","year":"2016","journal-title":"IEEE Transactions on Medical Imaging"},{"key":"10.3233\/JIFS-221055_ref52","doi-asserted-by":"crossref","unstructured":"Kaibo Duan , Sathiya Keerthi S , Wei Chu , Shirish Krishnaj Shevade and Aun Neow Poo , Multi-category Classification by Soft-Max Combination of Binary Classifiers. In proceedings of the 4th International Workshop, MCS 2003 Guildford, UK, 11\u201313 June 2003; pp 125\u2013134.","DOI":"10.1007\/3-540-44938-8_13"},{"key":"10.3233\/JIFS-221055_ref53","doi-asserted-by":"crossref","unstructured":"Cho Do Xuan , Lai Van Duong and Tisenko Victor Nikolaevich , Detecting C&C Server in the APT Attack based on Network Traffic using Machine Learning, International Journal of Advanced Computer Science and Applications(IJACSA) 11(5) (2020). https:\/\/dx.doi.org\/10.14569\/IJACSA.2020.0110504","DOI":"10.14569\/IJACSA.2020.0110504"},{"issue":"3","key":"10.3233\/JIFS-221055_ref55","doi-asserted-by":"crossref","first-page":"3527","DOI":"10.3233\/JIFS-220233","article-title":"Toan, A Novel IntelligentCognitive Computing-based APT Malware Detection for EndpointSystems","volume":"43","author":"Xuan","year":"2022","journal-title":"Journal of Intelligent & Fuzzy Systems"}],"container-title":["Journal of Intelligent &amp; Fuzzy Systems"],"original-title":[],"link":[{"URL":"https:\/\/content.iospress.com\/download?id=10.3233\/JIFS-221055","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,29]],"date-time":"2026-04-29T09:43:50Z","timestamp":1777455830000},"score":1,"resource":{"primary":{"URL":"https:\/\/journals.sagepub.com\/doi\/full\/10.3233\/JIFS-221055"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,3,9]]},"references-count":38,"journal-issue":{"issue":"3"},"URL":"https:\/\/doi.org\/10.3233\/jifs-221055","relation":{},"ISSN":["1064-1246","1875-8967"],"issn-type":[{"value":"1064-1246","type":"print"},{"value":"1875-8967","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,3,9]]}}}