{"id":{"repo_id":"rgu","oai_identifier":"oai:rgu-repository.worktribe.com:2445760"},"canonical_url":"https://search.dev.ndltd.org/etd/rgu/oai:rgu-repository.worktribe.com:2445760","repository":{"repo_id":"rgu","name":"Robert Gordon University","base_url":"https://rgu-repository.worktribe.com/oaiprovider"},"display":{"title":"Securing information systems against advanced persistent threats (APTs).","abstract":"Advanced Persistent Threats (APTs) have been a major challenge in securing both Information Technology (IT) and Operational Technology (OT) systems. APTs are sophisticated attacks that masquerade their actions to navigate around defenses, breach networks, often over multiple network hosts, and evade detection. APTs also use a \"low-and-slow\" approach over a long period of time. While APTs have drawn increasing attention from the industrial security community, recent security products are inadequate at helping companies defend against APTs attacks due to APTs' prolonged, stealthy characteristics, sophisticated levels of expertise and significant resources. The current best practice for dealing with APTs requires a wide range of security countermeasures, resulting in a multi-step detection approach that opens new research directions. The detection of a single step of APT lifecycle does not infer detection of a complete APT full scenario. The accurate detection and prevention of APT in real time is an ongoing challenge. This research aims to investigate APT attack detection and develop a novel multi-step APT attack detection framework to detect APT attack steps. An APT steps analysis and correlation framework termed \"APTDASAC\" is proposed. This approach takes into consideration the distributed and multi-level nature of industrial control system (ICS) architecture, and reflects on multi-step APT attack lifecycles. The implementation is carried out in three stages: stage one is \"Data input and probing layer\", which involves data gathering and processing; the second stage is \"Data analysis and Correlation layer\", which applies the core process of APTDASAC to learn the behaviour of attack steps from the sequence data, correlate and link the related output; and stage three \"Decision layer\", in which the ensemble probability approach is utilized to integrate the output and make attack prediction. The framework was validated with four different datasets and four case studies: i) network transactions between a remote terminal unit (RTU) and a master control unit (MTU) in-house supervisory control and data acquisition (SCADA) gas pipeline control system; ii) a case study of command and response injection attack; iii) a scenario based on network traffic containing hybrid of the real modern normal and the contemporary synthesized attack activities of the network traffic; and iv) APT_alerts - a historic record of APT alerts generated through a monitored network. The system achieved the probability average prediction accuracy of 86.73%. It also achieved a significant detection rate of 93.50%, 80.98%, 85.19% and 80.90% for each individual APT lifecycle detectable steps (A, B, C and D). Experimentally, APTDASAC achieved a significant attacks detection capability, but also demonstrated that attack detection techniques that performed very well in one domain may not yield the same good result in another domain. This suggests that the robustness and resilience of operational systems to withstand attack and maintain system performance and resilience are determined by the safety and security measures in place, which are specific to the system in question.","abstract_html":"Advanced Persistent Threats (APTs) have been a major challenge in securing both Information Technology (IT) and Operational Technology (OT) systems. APTs are sophisticated attacks that masquerade their actions to navigate around defenses, breach networks, often over multiple network hosts, and evade detection. APTs also use a &quot;low-and-slow&quot; approach over a long period of time. While APTs have drawn increasing attention from the industrial security community, recent security products are inadequate at helping companies defend against APTs attacks due to APTs&#x27; prolonged, stealthy characteristics, sophisticated levels of expertise and significant resources. The current best practice for dealing with APTs requires a wide range of security countermeasures, resulting in a multi-step detection approach that opens new research directions. The detection of a single step of APT lifecycle does not infer detection of a complete APT full scenario. The accurate detection and prevention of APT in real time is an ongoing challenge. This research aims to investigate APT attack detection and develop a novel multi-step APT attack detection framework to detect APT attack steps. An APT steps analysis and correlation framework termed &quot;APTDASAC&quot; is proposed. This approach takes into consideration the distributed and multi-level nature of industrial control system (ICS) architecture, and reflects on multi-step APT attack lifecycles. The implementation is carried out in three stages: stage one is &quot;Data input and probing layer&quot;, which involves data gathering and processing; the second stage is &quot;Data analysis and Correlation layer&quot;, which applies the core process of APTDASAC to learn the behaviour of attack steps from the sequence data, correlate and link the related output; and stage three &quot;Decision layer&quot;, in which the ensemble probability approach is utilized to integrate the output and make attack prediction. The framework was validated with four different datasets and four case studies: i) network transactions between a remote terminal unit (RTU) and a master control unit (MTU) in-house supervisory control and data acquisition (SCADA) gas pipeline control system; ii) a case study of command and response injection attack; iii) a scenario based on network traffic containing hybrid of the real modern normal and the contemporary synthesized attack activities of the network traffic; and iv) APT_alerts - a historic record of APT alerts generated through a monitored network. The system achieved the probability average prediction accuracy of 86.73%. It also achieved a significant detection rate of 93.50%, 80.98%, 85.19% and 80.90% for each individual APT lifecycle detectable steps (A, B, C and D). Experimentally, APTDASAC achieved a significant attacks detection capability, but also demonstrated that attack detection techniques that performed very well in one domain may not yield the same good result in another domain. This suggests that the robustness and resilience of operational systems to withstand attack and maintain system performance and resilience are determined by the safety and security measures in place, which are specific to the system in question.","abstract_has_math":false,"creators":["Eke, Hope Nkiruka"],"institution":"Robert Gordon University","degree_name":"PhD","degree_level":"Doctoral","degree_discipline":null,"degree_department":null,"school":null,"contributors":[],"advisors":["A. Petrovski, H. Ahriz and O. Al-Kadri"],"committee_chairs":[],"committee_members":[],"year":2024,"date_issued":"2024","date_published":"2024","updated_at":"2026-07-24T04:10:06Z","subjects":["Systems security","Cybersecurity","Threat detection"],"languages":["en"],"rights":[],"rights_urls":[],"identifier_entries":[{"key":"dc:identifier","label":"Identifier","values":["oai:rgu-repository.worktribe.com:2445760","https://doi.org/10.48526/rgu-wt-2445760"],"render_values":[{"text":"oai:rgu-repository.worktribe.com:2445760","href":null,"code":true},{"text":"https://doi.org/10.48526/rgu-wt-2445760","href":"https://doi.org/10.48526/rgu-wt-2445760","code":true}]},{"key":"dc:creator.authoridentifier","label":"Author Identifier","values":["0000-0001-5049-8212"],"render_values":[{"text":"0000-0001-5049-8212","href":"https://orcid.org/0000-0001-5049-8212","code":true}]}]},"links":{"outbound_url":"https://rgu-repository.worktribe.com/2445760/1/EKE%202024%20Securing%20information%20systems%20against","outbound_label":"Repository record","outbound_source":"dc:identifier.uri"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor.advisor","label":"Advisor","values":["A. Petrovski, H. Ahriz and O. Al-Kadri"]},{"key":"dc:contributor.sponsor","label":"Sponsor","values":["No Funder Acknowledged (Outputs)"]},{"key":"dc:creator","label":"Author","values":["Eke, Hope Nkiruka"]},{"key":"dc:creator.authoridentifier","label":"Author Identifier","values":["0000-0001-5049-8212"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["2024-01-31"]},{"key":"dc:date.issued","label":"Date","values":["2024"]},{"key":"dc:publisher.institution","label":"Dc Publisher Institution","values":["Robert Gordon University"]},{"key":"dc:relation.isreferencedby","label":"Dc Relation Isreferencedby","values":["https://rgu-repository.worktribe.com/output/2445760"]},{"key":"dc:type","label":"Dc Type","values":["Thesis"]},{"key":"dc:type.qualificationlevel","label":"Dc Type Qualificationlevel","values":["Doctoral"]},{"key":"dc:type.qualificationname","label":"Dc Type Qualificationname","values":["PhD"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Systems security","Cybersecurity","Threat detection"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language","label":"Dc Language","values":["en"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["oai:rgu-repository.worktribe.com:2445760","https://doi.org/10.48526/rgu-wt-2445760"]},{"key":"dc:identifier.uri","label":"Identifier URI","values":["https://rgu-repository.worktribe.com/2445760/1/EKE%202024%20Securing%20information%20systems%20against"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description.abstract","label":"Abstract","values":["Advanced Persistent Threats (APTs) have been a major challenge in securing both Information Technology (IT) and Operational Technology (OT) systems. APTs are sophisticated attacks that masquerade their actions to navigate around defenses, breach networks, often over multiple network hosts, and evade detection. APTs also use a \"low-and-slow\" approach over a long period of time. While APTs have drawn increasing attention from the industrial security community, recent security products are inadequate at helping companies defend against APTs attacks due to APTs' prolonged, stealthy characteristics, sophisticated levels of expertise and significant resources. The current best practice for dealing with APTs requires a wide range of security countermeasures, resulting in a multi-step detection approach that opens new research directions. The detection of a single step of APT lifecycle does not infer detection of a complete APT full scenario. The accurate detection and prevention of APT in real time is an ongoing challenge. This research aims to investigate APT attack detection and develop a novel multi-step APT attack detection framework to detect APT attack steps. An APT steps analysis and correlation framework termed \"APTDASAC\" is proposed. This approach takes into consideration the distributed and multi-level nature of industrial control system (ICS) architecture, and reflects on multi-step APT attack lifecycles. The implementation is carried out in three stages: stage one is \"Data input and probing layer\", which involves data gathering and processing; the second stage is \"Data analysis and Correlation layer\", which applies the core process of APTDASAC to learn the behaviour of attack steps from the sequence data, correlate and link the related output; and stage three \"Decision layer\", in which the ensemble probability approach is utilized to integrate the output and make attack prediction. The framework was validated with four different datasets and four case studies: i) network transactions between a remote terminal unit (RTU) and a master control unit (MTU) in-house supervisory control and data acquisition (SCADA) gas pipeline control system; ii) a case study of command and response injection attack; iii) a scenario based on network traffic containing hybrid of the real modern normal and the contemporary synthesized attack activities of the network traffic; and iv) APT_alerts - a historic record of APT alerts generated through a monitored network. The system achieved the probability average prediction accuracy of 86.73%. It also achieved a significant detection rate of 93.50%, 80.98%, 85.19% and 80.90% for each individual APT lifecycle detectable steps (A, B, C and D). Experimentally, APTDASAC achieved a significant attacks detection capability, but also demonstrated that attack detection techniques that performed very well in one domain may not yield the same good result in another domain. This suggests that the robustness and resilience of operational systems to withstand attack and maintain system performance and resilience are determined by the safety and security measures in place, which are specific to the system in question."]},{"key":"dc:title","label":"Title","values":["Securing information systems against advanced persistent threats (APTs)."]}]}],"canonical_facts":{"dc:contributor.advisor":["A. Petrovski, H. Ahriz and O. Al-Kadri"],"dc:contributor.sponsor":["No Funder Acknowledged (Outputs)"],"dc:creator":["Eke, Hope Nkiruka"],"dc:creator.authoridentifier":["0000-0001-5049-8212"],"dc:date":["2024-01-31"],"dc:date.issued":["2024"],"dc:description.abstract":["Advanced Persistent Threats (APTs) have been a major challenge in securing both Information Technology (IT) and Operational Technology (OT) systems. APTs are sophisticated attacks that masquerade their actions to navigate around defenses, breach networks, often over multiple network hosts, and evade detection. APTs also use a \"low-and-slow\" approach over a long period of time. While APTs have drawn increasing attention from the industrial security community, recent security products are inadequate at helping companies defend against APTs attacks due to APTs' prolonged, stealthy characteristics, sophisticated levels of expertise and significant resources. The current best practice for dealing with APTs requires a wide range of security countermeasures, resulting in a multi-step detection approach that opens new research directions. The detection of a single step of APT lifecycle does not infer detection of a complete APT full scenario. The accurate detection and prevention of APT in real time is an ongoing challenge. This research aims to investigate APT attack detection and develop a novel multi-step APT attack detection framework to detect APT attack steps. An APT steps analysis and correlation framework termed \"APTDASAC\" is proposed. This approach takes into consideration the distributed and multi-level nature of industrial control system (ICS) architecture, and reflects on multi-step APT attack lifecycles. The implementation is carried out in three stages: stage one is \"Data input and probing layer\", which involves data gathering and processing; the second stage is \"Data analysis and Correlation layer\", which applies the core process of APTDASAC to learn the behaviour of attack steps from the sequence data, correlate and link the related output; and stage three \"Decision layer\", in which the ensemble probability approach is utilized to integrate the output and make attack prediction. The framework was validated with four different datasets and four case studies: i) network transactions between a remote terminal unit (RTU) and a master control unit (MTU) in-house supervisory control and data acquisition (SCADA) gas pipeline control system; ii) a case study of command and response injection attack; iii) a scenario based on network traffic containing hybrid of the real modern normal and the contemporary synthesized attack activities of the network traffic; and iv) APT_alerts - a historic record of APT alerts generated through a monitored network. The system achieved the probability average prediction accuracy of 86.73%. It also achieved a significant detection rate of 93.50%, 80.98%, 85.19% and 80.90% for each individual APT lifecycle detectable steps (A, B, C and D). Experimentally, APTDASAC achieved a significant attacks detection capability, but also demonstrated that attack detection techniques that performed very well in one domain may not yield the same good result in another domain. This suggests that the robustness and resilience of operational systems to withstand attack and maintain system performance and resilience are determined by the safety and security measures in place, which are specific to the system in question."],"dc:identifier":["oai:rgu-repository.worktribe.com:2445760","https://doi.org/10.48526/rgu-wt-2445760"],"dc:identifier.uri":["https://rgu-repository.worktribe.com/2445760/1/EKE%202024%20Securing%20information%20systems%20against"],"dc:language":["en"],"dc:publisher.institution":["Robert Gordon University"],"dc:relation.isreferencedby":["https://rgu-repository.worktribe.com/output/2445760"],"dc:subject":["Systems security","Cybersecurity","Threat detection"],"dc:title":["Securing information systems against advanced persistent threats (APTs)."],"dc:type":["Thesis"],"dc:type.qualificationlevel":["Doctoral"],"dc:type.qualificationname":["PhD"]},"updated_at":"2026-07-24T04:10:06Z"}