Skip to main content

Table 13 Results of evaluation per each APT sample of Table 11

From: Big knowledge-based semantic correlation for detecting slow and low-level advanced persistent threats

APT sample Number of APT events (P) Number of other events (N) TPR (%) TNR (%) Accuracy (%) Precision (%) Detection result
1 9.1 million 1.637 billion 86.29 90.14 90.08 4.59 APT
2 13.7 million 1.6322 billion 83.17 87.58 87.50 5.24 APT
3 6.3 million 1.6397 billion 94.9 89.94 89.91 3.47 APT
4 73 thousand 1.64527 billion 95.06 97.48 97.39 0.16 APT
5 26 million 1.62 billion 98.32 77.97 78.28 6.67 APT
6 1.6 million 1.6444 billion 81.02 95.1 94.85 1.50 APT
7 2.1 million 1.6439 billion 91.73 90.38 90.33 1.19 APT
8 27.7 million 1.6183 billion 60.33 89.87 89.35 8.70 Benign
9 10.1 million 1.6359 billion 94.13 97.80 97.17 16.96 APT