Strategies to Describe and Timely Detect Attacks
Tommaso Puccetti · 2025
Cyber threats to information and communication technology (ICT) systems are constantly evolving, posing risks to system availability and safety with potentially severe consequences. In this context, developing effective Intrusion Detection Systems (IDS) is crucial to mitigating security breaches. Machine learning is a promising solution to defend from the growing complexity of attacks. While many algorithms demonstrate efficiency in detecting attacks observed during training, identifying zero-day attacks and unprecedented events remains challenging. Furthermore, beyond classification accuracy, timely detection is essential to minimizing attack impact, particularly against Advanced Persistent Threats (APTs), which consist of multiple attack steps and persistently target systems over extended periods. This paper, presented by a third-year PhD student, outlines current and future research activities aimed at improving timely detection and addressing these challenges.