Lune

INFOCOM2025Top-tier venue

A Principled Approach for Detecting APTs in Massive Networks via Multi-Stage Causal Analytics

Jiaping Gui, Mingjie Nie, Jinyao Guo, Futai Zou, Mati Ur Rehman, Wajih Ul Hassan

2025Year
6Citations
1Top-tier citations

Abstract

Detecting Advanced Persistent Threats (APTs) in large enterprise networks with conventional Network Intrusion Detection Systems (NIDS) is challenging due to the stealthy, multi-stage, and long-running nature of APTs. This paper introduces Netguardian, a novel NIDS utilizing a comprehensive methodology to correlate anomalies across APT stages. By merging real traffic with simulated APT scenarios, Netguardian creates a detailed training dataset for enhanced anomaly detection. Netguardian implements custom models for each APT stage, extracting specific traffic features, such as periodicity and failed connections, to identify anomalies. These anomalies are then correlated to reconstruct attack paths. Our system leverages these paths to assign threat scores based on interconnected anomalies matching known APT progression, effectively prioritizing suspicious paths. Evaluation on a large dataset of enterprise network traffic merged with simulated APTs along with the DARPA OpTC dataset shows that Netguardian detects various APT stages with high accuracy and low false positives, outperforming state-of-the-art (SOTA) NIDS.

Ask about this paper

Your agent reads all of it.

Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.

Questions to start from

Your agent calls

Luneget_paper_fulltext

Ask in Lune

Free to start. No credit card required.

lune papers fulltext 703ae05e-a498-4531-b47e-089660f62131

Cited by top-tier papers1

Ask how each one uses it

Builds on22

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines