APTSHIELD: A Stable, Efficient and Real-time APT Detection System for Linux Hosts
Tiantian Zhu, Jinkai Yu, Tieming Chen, Jiayu Wang, Jie Ying, Ye Tian,, Mingqi Lv, Yan Chen, Yuan Fan, Ting Wang

TL;DR
APTSHIELD is a novel Linux host APT detection system that offers stable, efficient, and real-time attack detection by leveraging kernel data audit, optimized data processing, and an ATT&CK-based detection framework, outperforming existing solutions.
Contribution
This paper introduces APTSHIELD, a comprehensive APT detection system for Linux that improves accuracy, efficiency, and real-time response compared to prior methods.
Findings
Effectively detects web vulnerability, file-less, and remote access Trojan attacks.
Achieves low false positive rate in diverse testing environments.
Reduces data processing overhead through semantic skipping and node pruning.
Abstract
Advanced Persistent Threat (APT) attack usually refers to the form of long-term, covert and sustained attack on specific targets, with an adversary using advanced attack techniques to destroy the key facilities of an organization. APT attacks have caused serious security threats and massive financial loss worldwide. Academics and industry thereby have proposed a series of solutions to detect APT attacks, such as dynamic/static code analysis, traffic detection, sandbox technology, endpoint detection and response (EDR), etc. However, existing defenses are failed to accurately and effectively defend against the current APT attacks that exhibit strong persistent, stealthy, diverse and dynamic characteristics due to the weak data source integrity, large data processing overhead and poor real-time performance in the process of real-world scenarios. To overcome these difficulties, in this…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsNetwork Security and Intrusion Detection · Advanced Malware Detection Techniques · Digital and Cyber Forensics
