EconPapers    
Economics at your fingertips  
 

Research on APT groups malware classification based on TCN-GAN

Daowei Chen and Hongsheng Yan

PLOS ONE, 2025, vol. 20, issue 6, 1-33

Abstract: Advanced Persistent Threat (APT) malware attacks, characterized by their stealth, persistence, and high destructiveness, have become a critical focus in cybersecurity defense for large organizations. Verifying and identifying the sources and affiliated groups of APT malware is one of the effective means to counter APT attacks. This paper addresses the issue of tracing and attributing APT malware groups. By improving and innovating the extraction methods for image features and disassembled instruction N-gram features of APT malware, and based on the Temporal Convolutional Network (TCN) model, the paper achieves high-accuracy classification and identification of APT malware. To mitigate the impact of insufficient APT malware samples and data imbalance on classification performance, the paper employs Generative Adversarial Networks (GAN) to expand the sample size. Validation on both public and self-constructed datasets shows that the proposed method achieves an accuracy and precision rate of 99.8%, significantly outperforming other methods. This work provides a foundation for subsequent countermeasures and accountability against related APT attack groups.

Date: 2025
References: View complete reference list from CitEc
Citations:

Downloads: (external link)
https://journals.plos.org/plosone/article?id=10.1371/journal.pone.0323377 (text/html)
https://journals.plos.org/plosone/article/file?id= ... 23377&type=printable (application/pdf)

Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.

Export reference: BibTeX RIS (EndNote, ProCite, RefMan) HTML/Text

Persistent link: https://EconPapers.repec.org/RePEc:plo:pone00:0323377

DOI: 10.1371/journal.pone.0323377

Access Statistics for this article

More articles in PLOS ONE from Public Library of Science
Bibliographic data for series maintained by plosone ().

 
Page updated 2025-06-21
Handle: RePEc:plo:pone00:0323377