Advanced Persistent Threat
Advanced Persistent Threats (APTs) are sophisticated, stealthy cyberattacks designed to maintain unauthorized access to systems over extended periods. Current research focuses on improving APT detection using deep learning models, particularly autoencoders, convolutional neural networks, and transformers, often enhanced by optimization algorithms like Cat Swarm Optimization or integrated with graph-based approaches for analyzing provenance data. These efforts aim to increase detection accuracy, reduce false positives, and improve the interpretability of results, ultimately bolstering cybersecurity defenses against these highly damaging attacks. The impact of this research is directly felt in improved security systems and more effective incident response strategies.
Papers
CONTINUUM: Detecting APT Attacks through Spatial-Temporal Graph Neural Networks
Atmane Ayoub Mansour Bahara, Kamel Soaïd Ferrahia, Mohamed-Lamine Messai, Hamida Seba, Karima Amrouche
GraphDART: Graph Distillation for Efficient Advanced Persistent Threat Detection
Saba Fathi Rabooki, Bowen Li, Falih Gozi Febrinanto, Ciyuan Peng, Elham Naghizade, Fengling Han, Feng Xia