A Comparative Analysis of Advanced Persistent Threat Detection Methodologies: A Systematic Review
Wentao Li · Applied and Computational Engineering · 2025
Advanced Persistent Threats (APTs) represent sophisticated, long-term cyberattacks targeting critical infrastructure and sensitive data, posing significant challenges to conventional security mechanisms. This review systematically analyzes and compares state-of-the-art APT detection methodologies documented in recent scientific literature. The study examines peer-reviewed journals, conference proceedings, and seminal technical reports published between 2021 and 2025, focusing on detection frameworks, underlying technologies (including machine learning, deep learning, provenance analysis, and Large Language Models), performance metrics (accuracy, false positive rates, real-time capability), and operational constraints. Key findings indicate that approaches integrating behavioral analysis with artificial intelligence, particularly those leveraging provenance tracing and LLM-enhanced anomaly interpretation, demonstrate superior efficacy in identifying stealthy, multi-stage APT activities compared to signature-based or isolated ML solutions. Hybrid systems combining real-time data processing with contextual threat intelligence exhibit the highest resilience against evolving APT tactics. The conclusion underscores the necessity of adaptive, multi-layered detection frameworks and identifies emerging research trends, including explainable AI for forensic attribution and cross-platform detection standardization.