Research on APT Attack Behavior Tracing Method Based on Deep Neural Network

Authors

  • Mengyuan Tao Xinjiang College of Science & Technology, Korla, Xinjiang, 841000, China
  • Shuo Yang Xinjiang College of Science & Technology, Korla, Xinjiang, 841000, China
  • Fangru Duan Xinjiang College of Science & Technology, Korla, Xinjiang, 841000, China
  • Dong Zhu Xinjiang College of Science & Technology, Korla, Xinjiang, 841000, China
  • Guliasiman Abudukadier Xinjiang College of Science & Technology, Korla, Xinjiang, 841000, China
  • Aobo Zhang Xinjiang College of Science & Technology, Korla, Xinjiang, 841000, China

DOI:

https://doi.org/10.54097/dk7rny38

Keywords:

Advanced Persistent Threat, Attack Tracing, Deep Neural Network, Multi-class Classification, Class Imbalance, Network Traffic

Abstract

Advanced Persistent Threat (APT) attack tracing aims to identify attack behavior patterns and trace the attack source, which is a key step in security operations and incident response. To address the difficulties of multi-type attack behavior identification and severe class imbalance, this paper proposes an APT attack behavior tracing method based on a Deep Neural Network (DNN). Based on the public UNSW-NB15 network traffic dataset, network behaviors are divided into 10 categories, namely normal behavior and 9 types of attack behaviors. Through data cleaning, categorical feature encoding, and numerical standardization, a 70-dimensional feature sample set is constructed, and a multilayer perceptron network is employed to perform fine-grained classification of attack behaviors; the identification results are then mapped to APT kill-chain stages to assist attacker profiling and attribution. The proposed method is compared with XGBoost, linear support vector machine, AdaBoost, and random forest. Experimental results show that XGBoost achieves the best macro-averaged F1 of 0.5160, while the proposed DNN ranks second with a macro-averaged F1 of 0.4600; both significantly outperform the linear model and AdaBoost. Per-class analysis reveals that majority attack behaviors are identified with high accuracy, whereas minority classes such as Analysis and Backdoor are difficult to recognize, indicating that class imbalance is the main factor limiting tracing performance. A further oversampling ablation experiment shows that simple resampling cannot effectively improve minority-class identification, and more sophisticated cost-sensitive or semantic enhancement strategies are needed. This study provides a reproducible experimental reference for APT attack behavior tracing and attribution assistance.

Downloads

Download data is not yet available.

References

[1] Hutchins, E. M., Cloppert, M. J., & Amin, R. M. (2011). Intelligence-driven computer network defense informed by analysis of adversary campaigns and intrusion kill chains. Leading Issues in Information Warfare & Security Research, 1(1), 80–106.

[2] Yang, X. Z., Peng, G. J., Liu, S. D., et al. (2025). Survey on tracing and reasoning for APT attacks. Journal of Software, 36(1), 203–252.

[3] Marchetti, M., Pierazzi, F., Colajanni, M., et al. (2016). Analysis of high volumes of network traffic for advanced persistent threat detection. Computer Networks, 109, 127–141. https://doi.org/10.1016/j.comnet.2016.04.020.

[4] AL-Aamri, A. S., Abdulghafor, R., Turaev, S., et al. (2023). Machine learning for APT detection. Sustainability, 15(18), 13820. https://doi.org/10.3390/su151813820.

[5] Neuschmied, H., Winter, M., Stojanović, B., et al. (2022). APT-attack detection based on multi-stage autoencoders. Applied Sciences, 12(13), 6816. https://doi.org/10.3390/app12136816.

[6] Zipperle, M., Gottwalt, F., Chang, E., et al. (2022). Provenance-based intrusion detection systems: A survey. ACM Computing Surveys, 55(7), 1–36. https://doi.org/10.1145/3527849.

[7] Moustafa, N., & Slay, J. (2015). UNSW-NB15: A comprehensive data set for network intrusion detection systems (UNSW-NB15 network data set). In 2015 Military Communications and Information Systems Conference (MilCIS) (pp. 1–6). IEEE. https://doi.org/10.1109/MilCIS.2015.7348942.

[8] Moustafa, N., & Slay, J. (2016). The evaluation of network anomaly detection systems: Statistical analysis of the UNSW-NB15 data set and the comparison with the KDD99 data set. Information Security Journal: A Global Perspective, 25(1–3), 18–31. https://doi.org/10.1080/19393555.2015.1125454.

Downloads

Published

08-10-2026

Issue

Section

Articles