Advanced Persistent Threat (APT) Detection Using Context-Aware Machine Learning Models

R N Bhavanavika, M. Priya · 2025

Designing systems that can infiltrate networks, remain undetected for long periods, and extract sensitive information make Advanced Persistent Threats (APTs) some of the most sophisticated and powerful cyber-attacks. Most APTs circumvent conventional Intrusion Detection Systems (IDS) because of signature-based detection technology that relies on static patterns and is blind to new forms of threats. To bridge this gap, we put forth a comprehensive framework that applies machine learning through the incorporation of Random Forest, Isolation Forest, and Long Short-Term Memory (LSTM) networks aimed at APT detection. Random Forest, as a supervised learning algorithm, will extract known attack patterns while Isolation Forest, as an unsupervised algorithm, will capture anomalous network behavior corresponding to unknown attacks. With LSTM networks, complex multivariate network traffic patterns are analyzed to identify complex attack behaviors. The UNSW-NB15 dataset, which contains various attack scenarios as well as normal network traffic, is used for training and testing the models. The combination of these technologies is deployed on a scalable serverless infrastructure through A WS SageMaker and real-time data streams are processed using A WS Kinesis. The experimental findings show substantial improvements in accuracy, precision, and recall in both batch and real-time detection scenarios. This approach provides a comprehensive and flexible solution to counter evolving cyber threats with enhanced network security.

Read the paper · More papers on PaperTik