An Approach to detect Advanced Persistent Threats using Machine Learning Techniques

dc.contributor.authorBary A.A
dc.contributor.authorWijerupa W.D.O.D
dc.contributor.authorPadukka P.V.G.G
dc.contributor.authorAtapattu A.L.V.J.
dc.contributor.authorPandithage, D
dc.contributor.authorWijesooriya, A
dc.date.accessioned2026-10-07T08:37:08Z
dc.date.issued2025-12-09
dc.description.abstractAdvanced Persistent Threats (APTs) pose significant risks to organizations due to their stealthy, prolonged nature and ability to evade traditional detection mechanisms. Traditional solutions often analyze separate data elements, such as network traffic or endpoint activity, limiting their effectiveness against sophisticated APT campaigns. This research proposes a holistic machine learning (ML)-driven approach to detect APTs by integrating three critical data dimensions: user behavior anomalies, endpoint activity monitoring, and network traffic analysis. The system further incorporates Tactics, Techniques, and Procedures (TTP) analysis using the MITRE ATT&CK framework to provide actionable intelligence. A real-time dashboard visualizes the threat detection results, TTP mappings, and mitigation strategies, enabling cybersecurity teams to respond proactively. The integration of multiple ML models enhances detection accuracy while bridging the gap between threat identification and contextual understanding. Experimental validation demonstrates the system's capability to detect APT indicators across diverse attack vectors and prioritize high-risk TTPs. This work contributes to advancing APT detection methodologies by offering a scalable, multi-dimensional solution tailored for modern cybersecurity operations.
dc.identifier.citationA. A. Bary, W. D. O. D. Wijerupa, P. V. G. G. Padukka, A. L. V. J. Atapattu, D. Pandithage and A. Wijesooriya, "An Approach to Detect Advanced Persistent Threats Using Machine Learning Techniques," 2025 7th International Conference on Advancements in Computing (ICAC), Colombo, Sri Lanka, 2025, pp. 1-6, doi: 10.1109/ICAC69156.2025.11361465.
dc.identifier.doidoi: 10.1109/ICAC69156.2025.11361465
dc.identifier.isbn979-833156222-9
dc.identifier.urihttps://rda.sliit.lk/handle/123456789/5345
dc.language.isoen
dc.publisherInstitute of Electrical and Electronics Engineers Inc.
dc.relation.ispartofseriesICAC 2025 - 7th International Conference on Advancements in Computing: The Future of Computing; AI, Quantum, and Beyond
dc.subjectAnomaly detection
dc.subjectAPT
dc.subjectMachine Learning
dc.subjectML
dc.subjectSupervised Learning
dc.subjectTTP
dc.subjectUnsupervised Learning
dc.titleAn Approach to detect Advanced Persistent Threats using Machine Learning Techniques
dc.typeConference Paper

Files

Original bundle

Now showing 1 - 1 of 1
No Thumbnail Available
Name:
An_Approach_to_Detect_Advanced_Persistent_Threats_Using_Machine_Learning_Techniques.pdf
Size:
453.17 KB
Format:
Adobe Portable Document Format

License bundle

Now showing 1 - 1 of 1
No Thumbnail Available
Name:
license.txt
Size:
1.69 KB
Format:
Item-specific license agreed upon to submission
Description: