A Principled Approach for Detecting APTs in Massive Networks via Multi-Stage Causal Analytics
Jiaping Gui, Mingjie Nie, Jinyao Guo, Futai Zou, Mati Ur Rehman, Wajih Ul Hassan
Abstract
Detecting Advanced Persistent Threats (APTs) in large enterprise networks with conventional Network Intrusion Detection Systems (NIDS) is challenging due to the stealthy, multi-stage, and long-running nature of APTs. This paper introduces Netguardian, a novel NIDS utilizing a comprehensive methodology to correlate anomalies across APT stages. By merging real traffic with simulated APT scenarios, Netguardian creates a detailed training dataset for enhanced anomaly detection. Netguardian implements custom models for each APT stage, extracting specific traffic features, such as periodicity and failed connections, to identify anomalies. These anomalies are then correlated to reconstruct attack paths. Our system leverages these paths to assign threat scores based on interconnected anomalies matching known APT progression, effectively prioritizing suspicious paths. Evaluation on a large dataset of enterprise network traffic merged with simulated APTs along with the DARPA OpTC dataset shows that Netguardian detects various APT stages with high accuracy and low false positives, outperforming state-of-the-art (SOTA) NIDS.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 703ae05e-a498-4531-b47e-089660f62131Cited by top-tier papers1
Ask how each one uses itBuilds on22
- NoDoze: Combatting Threat Alert Fatigue with Automated Provenance TriageWajih Ul Hassan, Shengjian Guo, Ding Li, Zhengzhang Chen et al.NDSS 2019 · 411 citations
- Tactical Provenance Analysis for Endpoint Detection and Response SystemsWajih Ul Hassan, Adam Bates, Daniel MarinoS&P 2020 · 317 citations
- ATLAS: A Sequence-based Learning Approach for Attack InvestigationAbdulellah Alsaheel, Yuhong Nan, Shiqing Ma, Le Yu et al.USENIX Security 2021 · 256 citations
- Realtime Robust Malicious Traffic Detection via Frequency Domain AnalysisChuanpu Fu, Qi Li, Meng Shen, Ke XuCCS 2021 · 194 citations
- Ripple: A Programmable, Decentralized Link-Flooding Defense Against Adaptive AdversariesJiarong Xing, Wenqing Wu, Ang ChenUSENIX Security 2021 · 100 citations
Related papers
- Sentient: Detecting APTs via Capturing Indirect Dependencies and Behavioral LogicWenhao Yan, Ning An, Wei Qiao, Weiheng Wu et al.AAAI 2026 · 1 citation
- OCR-APT: Reconstructing APT Stories from Audit Logs using Subgraph Anomaly Detection and LLMsAhmed Aly, Essam Mansour, Amr M. YoussefCCS 2025 · 2 citations
- HyperDetector: Advanced Persistent Threat Detection via Hypergraph Neural Networks with Enhanced Global PerceptionZiyue Wu, Nan Wang, Jiqiang Liu, Hairong Dong et al.WWW 2026
- Unicorn: Runtime Provenance-Based Detector for Advanced Persistent ThreatsXueyuan Han, Thomas F. J.-M. Pasquier, Adam Bates, James Mickens et al.NDSS 2020
- Optimized Invariant Representation of Network Traffic for Detecting Unseen Malware VariantsKarel Bartos, Michal Sofka, Vojtech FrancUSENIX Security 2016 · 147 citations
