Skip to content

Author

Sofie Nielsen

1 paper indexed here

We haven’t gathered this author’s papers yet. Follow them and we’ll fetch their work.

Not the right person? Other researchers publish under this name.

Aug 2026

Early Warning of Advanced Persistent Threats Through Enterprise Network Behavior Profiling

Advanced persistent threats often begin with low-volume and stealthy network activities, such as reconnaissance, command-and-control beaconing, credential probing, and slow data staging. These behaviors are difficult to detect because they may not produce obvious traffic spikes or signature-matching patterns. This study proposes a SHAP-guided ensemble learning approach for early-stage APT traffic detection in enterprise campus networks. The framework integrates CatBoost, Extra Trees, and Balanced Random Forest classifiers to identify weak abnormal signals from flow-level and temporal communication features. SHAP analysis is used to explain both global feature importance and individual alerts, allowing security analysts to understand why specific flows are classified as suspicious. Experiments are conducted on a campus-scale network traffic dataset collected from 14 subnets, 9,600 active endpoints, and 31 internal servers over 28 days. The dataset includes 8.73 million flow records, with injected APT-like scenarios involving beaconing, internal reconnaissance, credential spraying, and staged exfiltration. A total of 57 features are extracted, including periodic connection interval, low-volume destination repetition, DNS query irregularity, failed authentication-related flow ratio, rare external endpoint access, and off-hour communication frequency. The proposed method achieves 96.87% accuracy, 94.92% macro-F1, and 97.76% AUC under highly imbalanced traffic conditions. For early-stage command-and-control beaconing, the detection recall reaches 93.41%, which is 4.68% higher than the best standalone classifier. The false alarm rate is controlled at 2.36% after probability calibration. SHAP results show that periodic low-volume connections, rare external destination access, abnormal DNS behavior, and off-hour communication are key indicators of early APT activity. These findings show that interpretable ensemble learning can help identify stealthy enterprise network threats before large-scale compromise occurs.

Mads Jensen, Sofie Nielsen, L. Andersen et al. · 0 citations