<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE ArticleSet PUBLIC "-//NLM//DTD PubMed 2.7//EN" "https://dtd.nlm.nih.gov/ncbi/pubmed/in/PubMed.dtd">
<ArticleSet>
<Article>
<Journal>
				<PublisherName>Iranian Society of Cryptology</PublisherName>
				<JournalTitle>The ISC International Journal of Information Security</JournalTitle>
				<Issn>2008-2045</Issn>
				<Volume>17</Volume>
				<Issue>2</Issue>
				<PubDate PubStatus="epublish">
					<Year>2025</Year>
					<Month>07</Month>
					<Day>01</Day>
				</PubDate>
			</Journal>
<ArticleTitle>DSRL-APT-2023: A New Synthetic Dataset for Advanced Persistent Threats</ArticleTitle>
<VernacularTitle></VernacularTitle>
			<FirstPage>107</FirstPage>
			<LastPage>116</LastPage>
			<ELocationID EIdType="pii">214212</ELocationID>
			
<ELocationID EIdType="doi">10.22042/isecure.2025.214212</ELocationID>
			
			<Language>EN</Language>
<AuthorList>
<Author>
					<FirstName>Hossein</FirstName>
					<LastName>Shadabfar</LastName>
<Affiliation>Department of Management, Science and Technology of Amirkabir University , Technology Tehran,Iran</Affiliation>

</Author>
<Author>
					<FirstName>Motahareh</FirstName>
					<LastName>Dehghan</LastName>
<Affiliation>Department of Industrial and Systems Engineering Tarbiat Modares University Tehran, Iran</Affiliation>
<Identifier Source="ORCID">0000-0002-5316-8005</Identifier>

</Author>
<Author>
					<FirstName>Babak</FirstName>
					<LastName>Sadeghian</LastName>
<Affiliation>Department of Computer Engineering Amirkabir University of Technology Tehran, Iran</Affiliation>

</Author>
</AuthorList>
				<PublicationType>Journal Article</PublicationType>
			<History>
				<PubDate PubStatus="received">
					<Year>2024</Year>
					<Month>12</Month>
					<Day>26</Day>
				</PubDate>
			</History>
		<Abstract>Detecting Advanced Persistent Threats (APTs) is crucial, and a practical approach involves using an intrusion detection system (IDS) integrated with supervised machine learning algorithms. These algorithms require a balanced dataset with ample attack samples to learn and recognize attack patterns effectively. However, widely used APT datasets, such as DAPT2020 and SCVIC-APT-2021, suffer from imbalance issues that limit the performance of machine learning-based intrusion detection systems (IDS). We introduce DSRL-APT-2023, a new balanced synthetic APT dataset generated using CTGAN to address this challenge. The CTGAN model is trained on the DAPT2020 dataset to create this balanced dataset. We evaluate and compare the performance of six standard supervised machine learning algorithms—Decision Tree, Support Vector Machine, K-Nearest Neighbor, Logistic Regression, Random Forest, and Multi-Layer Perceptron— alongside an intrusion detection system (IDS) called Intelligent Intrusion Detection System, which is based on tree-structured machine learning models. Our evaluation focuses on detecting attacks in DSRL-APT-2023 and compares its performance to DAPT2020 and SCVIC-APT-2021. Additionally, we assess the data quality of synthetic datasets generated by two prominent GANs, CopulaGAN, and CTGAN, with CTGAN demonstrating slightly superior performance in generating high-quality tabular data. Our results demonstrate that machine learning algorithms and the Intelligent IDS can accurately detect attacks in the synthetic dataset, as evidenced by the F1-Score metrics.</Abstract>
		<ObjectList>
			<Object Type="keyword">
			<Param Name="value">Advanced Persistent Threat</Param>
			</Object>
			<Object Type="keyword">
			<Param Name="value">Intrusion Detection System</Param>
			</Object>
			<Object Type="keyword">
			<Param Name="value">Supervised Machine Learning Algorithms</Param>
			</Object>
			<Object Type="keyword">
			<Param Name="value">Generative Adversarial Networks</Param>
			</Object>
		</ObjectList>
<ArchiveCopySource DocType="pdf">https://www.isecure-journal.com/article_214212_40f652111c696f5eb8da62fe518390fa.pdf</ArchiveCopySource>
</Article>
</ArticleSet>
