An Approach to detect Advanced Persistent Threats using Machine Learning Techniques
| dc.contributor.author | Bary A.A | |
| dc.contributor.author | Wijerupa W.D.O.D | |
| dc.contributor.author | Padukka P.V.G.G | |
| dc.contributor.author | Atapattu A.L.V.J. | |
| dc.contributor.author | Pandithage, D | |
| dc.contributor.author | Wijesooriya, A | |
| dc.date.accessioned | 2026-10-07T08:37:08Z | |
| dc.date.issued | 2025-12-09 | |
| dc.description.abstract | Advanced Persistent Threats (APTs) pose significant risks to organizations due to their stealthy, prolonged nature and ability to evade traditional detection mechanisms. Traditional solutions often analyze separate data elements, such as network traffic or endpoint activity, limiting their effectiveness against sophisticated APT campaigns. This research proposes a holistic machine learning (ML)-driven approach to detect APTs by integrating three critical data dimensions: user behavior anomalies, endpoint activity monitoring, and network traffic analysis. The system further incorporates Tactics, Techniques, and Procedures (TTP) analysis using the MITRE ATT&CK framework to provide actionable intelligence. A real-time dashboard visualizes the threat detection results, TTP mappings, and mitigation strategies, enabling cybersecurity teams to respond proactively. The integration of multiple ML models enhances detection accuracy while bridging the gap between threat identification and contextual understanding. Experimental validation demonstrates the system's capability to detect APT indicators across diverse attack vectors and prioritize high-risk TTPs. This work contributes to advancing APT detection methodologies by offering a scalable, multi-dimensional solution tailored for modern cybersecurity operations. | |
| dc.identifier.citation | A. A. Bary, W. D. O. D. Wijerupa, P. V. G. G. Padukka, A. L. V. J. Atapattu, D. Pandithage and A. Wijesooriya, "An Approach to Detect Advanced Persistent Threats Using Machine Learning Techniques," 2025 7th International Conference on Advancements in Computing (ICAC), Colombo, Sri Lanka, 2025, pp. 1-6, doi: 10.1109/ICAC69156.2025.11361465. | |
| dc.identifier.doi | doi: 10.1109/ICAC69156.2025.11361465 | |
| dc.identifier.isbn | 979-833156222-9 | |
| dc.identifier.uri | https://rda.sliit.lk/handle/123456789/5345 | |
| dc.language.iso | en | |
| dc.publisher | Institute of Electrical and Electronics Engineers Inc. | |
| dc.relation.ispartofseries | ICAC 2025 - 7th International Conference on Advancements in Computing: The Future of Computing; AI, Quantum, and Beyond | |
| dc.subject | Anomaly detection | |
| dc.subject | APT | |
| dc.subject | Machine Learning | |
| dc.subject | ML | |
| dc.subject | Supervised Learning | |
| dc.subject | TTP | |
| dc.subject | Unsupervised Learning | |
| dc.title | An Approach to detect Advanced Persistent Threats using Machine Learning Techniques | |
| dc.type | Conference Paper |
Files
Original bundle
1 - 1 of 1
No Thumbnail Available
- Name:
- An_Approach_to_Detect_Advanced_Persistent_Threats_Using_Machine_Learning_Techniques.pdf
- Size:
- 453.17 KB
- Format:
- Adobe Portable Document Format
License bundle
1 - 1 of 1
No Thumbnail Available
- Name:
- license.txt
- Size:
- 1.69 KB
- Format:
- Item-specific license agreed upon to submission
- Description:
