arXiv:2506.12108cs.CRcs.AI2025-06被引 3

用XGBoost+SHAP选出4个关键特征,实现早期APT精准检测

A Lightweight IDS for Early APT Detection Using a Novel Feature Selection Method

  • 基于SHAP分析筛选出初始攻击阶段最相关特征
  • 仅用4个特征即达97%精确率、100%召回率
  • 适合需要轻量级、高灵敏度威胁检测的系统

高级持续性威胁(APT)是一种多阶段、高度复杂且隐蔽的网络攻击,常在系统中潜伏长期以窃取数据或破坏网络。此类威胁往往难以及时发现,因此需在初始入侵阶段尽早识别。本文提出一种新型特征选择方法,用于构建轻量级入侵检测系统,可有效识别早期APT行为。该方法结合XGBoost与可解释人工智能(XAI),利用SHAP(SHapley Additive exPlanations)识别初始攻击阶段的关键特征。在SCVIC-APT-2021数据集上,特征数量从77个降至4个,同时保持稳定性能:精确率97%,召回率100%,F1分数98%。所提方法不仅有助于防止成功APT后果,还增强了对早期攻击行为的理解。

原文摘要 · Abstract (English)

An Advanced Persistent Threat (APT) is a multistage, highly sophisticated, and covert form of cyber threat that gains unauthorized access to networks to either steal valuable data or disrupt the targeted network. These threats often remain undetected for extended periods, emphasizing the critical need for early detection in networks to mitigate potential APT consequences. In this work, we propose a feature selection method for developing a lightweight intrusion detection system capable of effectively identifying APTs at the initial compromise stage. Our approach leverages the XGBoost algorithm and Explainable Artificial Intelligence (XAI), specifically utilizing the SHAP (SHapley Additive exPlanations) method for identifying the most relevant features of the initial compromise stage. The results of our proposed method showed the ability to reduce the selected features of the SCVIC-APT-2021 dataset from 77 to just four while maintaining consistent evaluation metrics for the suggested system. The estimated metrics values are 97% precision, 100% recall, and a 98% F1 score. The proposed method not only aids in preventing successful APT consequences but also enhances understanding of APT behavior at early stages.

APT检测特征选择XGBoostSHAP

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。