Advanced Persistent Threats (APT) Attribution Using Deep Reinforcement Learning
arXiv:2410.11463 · doi:10.1145/3736654
Abstract
The development of the DRL model for malware attribution involved extensive research, iterative coding, and numerous adjustments based on the insights gathered from predecessor models and contemporary research papers. This preparatory work was essential to establish a robust foundation for the model, ensuring it could adapt and respond effectively to the dynamic nature of malware threats. Initially, the model struggled with low accuracy levels, but through persistent adjustments to its architecture and learning algorithms, accuracy improved dramatically from about 7 percent to over 73 percent in early iterations. By the end of the training, the model consistently reached accuracy levels near 98 percent, demonstrating its strong capability to accurately recognise and attribute malware activities. This upward trajectory in training accuracy is graphically represented in the Figure, which vividly illustrates the model maturation and increasing proficiency over time.
21 Pages
References in corpus (8)
- A Brief Survey of Deep Reinforcement Learning
- Exploration in Deep Reinforcement Learning: A Survey
- Combating Advanced Persistent Threats: Challenges and Solutions
- ESASCF: Expertise Extraction, Generalization and Reply Framework for an Optimized Automation of Network Security Compliance
- GenDFIR: Advancing Cyber Incident Timeline Analysis Through Retrieval Augmented Generation and Large Language Models
- End-to-End Deep Neural Networks and Transfer Learning for Automatic Analysis of Nation-State Malware
- A Comprehensive Overview of Large Language Models (LLMs) for Cyber Defences: Opportunities and Directions
- D2WFP: A Novel Protocol for Forensically Identifying, Extracting, and Analysing Deep and Dark Web Browsing Activities