Leveraging CPU Utilization Metrics and Zero Trust Architecture for APT Detection

Nachaat AbdElatif Mohamed, Adel Oubelaid, Akash Ghosh, Mohit Bajaj, Rabindra Kumar Barik · 2023

As Advanced Persistent Threats (APTs) proliferate and evolve, they constitute an increasingly formidable challenge to organizational cybersecurity frameworks. The imperative for innovative, multifaceted detection methodologies has never been more critical. This manuscript elucidates a groundbreaking framework that ingeniously synergizes Central Processing Unit (CPU) utilization metrics with the principles of Zero-Trust architecture. Our approach scrutinizes the nuanced, idiosyncratic patterns of CPU utilization that are indicative of APT activities. Significantly, this method is adept at identifying hallmarks of APTs congruent with criteria delineated in the MITRE ATT&CK framework-specifically in stages antecedent to lateral movement tactics. Parallel to this, the framework assimilates the austere security policies typified by Zero Trust architecture, culminating in a holistic, dynamically adaptive defense mechanism. Rigorous experimental validations conducted in realistic operational environments substantiate the efficacy of our approach, which attained an unparalleled accuracy rate of 99.7% in the detection of APTs. The manifest advantages of this multifaceted strategy extend beyond mere detection efficacy, offering perspicacious insights into the operational modalities of APTs, thereby fostering the capability for preemptive cybersecurity initiatives. The contributions of this study are poised to significantly augment both academic discourse and practical applications in the persistent endeavor to fortify cybersecurity infrastructures against ever-escalating APT threats.

Read the paper · More papers on PaperTik