Analyzing Advanced Persistent Threats (APTs) Using Passive Honeypot Sensors and Self-Organizing Maps

Sandeep Malipeddi · 2025

This paper explores the implementation of passive honeypot sensors for detecting Advanced Persistent Threats (APTs) within IT infrastructures. APTs pose significant risks to government entities, public administrations, and corporations due to their persistent and stealthy nature. The study highlights the commonality of malware propagation as a primary internal attack vector and examines the multivector nature of such attacks, emphasizing their complexity in exploiting various vulnerabilities. The strengths of honeypots, such as low resource requirements and minimal disruption to network traffic, are contrasted with their limitations, including their inability to capture vital network layer threats and the risk of detection by savvy attackers. Furthermore, the use of Self-Organizing Maps (SOM) to classify detected attacks demonstrates how machine learning can aid in visualizing and understanding cyber threats. The findings suggest a need for hybrid security architectures and the incorporation of diverse machine learning techniques to enhance threat detection capabilities, paving the way for future research in the field.

Read the paper · More papers on PaperTik