×

Neural Network Models For Advanced Persistent Threat (APT) Detection

Author : Tharushi Silva Journa Name: International Journal of Science, Engineering and Technology Volume: 11 issue: 2 Year: Volume-11-issue-2 Views : 176
Abstract:
Advanced Persistent Threats (APTs) represent the most sophisticated tier of cyber-adversaries, characterized by their stealthy, multi-stage nature and long-term residency within high-value networks. Traditional signature-based detection systems and classical machine learning models frequently fail to identify APTs because these threats utilize \"low and slow\" tactics that blend seamlessly with legitimate administrative traffic. This review examines the paradigm shift toward neural network-based detection frameworks, which leverage deep representation learning to identify subtle, non-linear correlations across massive, heterogeneous datasets. We analyze the efficacy of various architectures, including Convolutional Neural Networks (CNNs) for traffic-to-image pattern recognition, Recurrent Neural Networks (RNNs) and Long Short-Term Memory (LSTM) units for temporal sequence modeling of system calls, and Graph Neural Networks (GNNs) for mapping lateral movement across complex network topologies. The article categorizes the APT lifecycle into stages—reconnaissance, initial intrusion, lateral movement, and exfiltration—and evaluates how specific neural architectures address the unique data characteristics of each phase. Furthermore, we address the critical challenges of data imbalance in APT datasets, the \"black-box\" nature of deep models, and the emerging threat of adversarial machine learning. By synthesizing recent breakthroughs in transformer-based self-attention and self-supervised learning, this paper provides a strategic roadmap for building autonomous, resilient defense systems. The findings suggest that neural networks significantly enhance detection accuracy and reduce the mean time to detect (MTTD) by identifying the \"logical intent\" behind disparate events, rather than relying on static indicators.

Related Indexing Platform

Indexed

Zenodo Logo
Zenodo
Research Data Repository
https://zenodo.org/records/19417305
DOI
DOI Resolver
Global Persistent Identifier
https://doi.org/10.5281/zenodo.19417305
GS
Google Scholar
Search this title on Scholar
Search on Google Scholar
SS
Semantic Scholar
Search this title
Search on Semantic Scholar
Lens
Lens.org
Check citations via DOI
Search on Lens.org
Leave Your Comment

Related Reviewers

Chat with Expert