Skip to main content

Table 13 Results of evaluation per each APT sample of Table 11

From: Big knowledge-based semantic correlation for detecting slow and low-level advanced persistent threats

APT sample

Number of APT events (P)

Number of other events (N)

TPR (%)

TNR (%)

Accuracy (%)

Precision (%)

Detection result

1

9.1 million

1.637 billion

86.29

90.14

90.08

4.59

APT

2

13.7 million

1.6322 billion

83.17

87.58

87.50

5.24

APT

3

6.3 million

1.6397 billion

94.9

89.94

89.91

3.47

APT

4

73 thousand

1.64527 billion

95.06

97.48

97.39

0.16

APT

5

26 million

1.62 billion

98.32

77.97

78.28

6.67

APT

6

1.6 million

1.6444 billion

81.02

95.1

94.85

1.50

APT

7

2.1 million

1.6439 billion

91.73

90.38

90.33

1.19

APT

8

27.7 million

1.6183 billion

60.33

89.87

89.35

8.70

Benign

9

10.1 million

1.6359 billion

94.13

97.80

97.17

16.96

APT