Towards Autonomous Cybersecurity: A Comparative Analysis of Agnostic and Hybrid AI Approaches for Advanced Persistent Threat Detection
摘要
The rapid evolution of cyber threats requires proactive and automated detection mechanisms. Although machine learning shows potential in this area, current models struggle to keep up with adversaries due to issues like model obsolescence, adversarial adaptation, and absence of current public datasets containing recent cybersecurity threats. This work investigates the spectrum of machine learning techniques utilized for cyber threat defense in detection, mitigation, and monitoring processes, with a focus on those addressing Advanced Persistent Threat (APT) characteristics and other less sophisticated threats. It highlights the constraints and obstacles impeding complete automation. The exploration also delves into the promise of agnostic methods that can function beyond dependence solely on Machine Learning (ML) models, emphasizing the significance of hybrid classifier strategies that integrate various techniques for improved performance. A thorough examination of recent studies evaluates the challenges in the path towards achieving, resilient, and adaptive cyber threat defense by examining various works and primary methodologies for detecting and attributing Advanced Persistent Threats (APTs), including the utilization of Cyber Threat Intelligence (CTI), Tactics, Techniques, and Procedures (TTP), and leveraging data from security tools like Security Information and Event Management (SIEM), Intrusion Prevention Systems (IPS), and Intrusion Detection Systems (IDS) responsible for recording electronic events in an enterprise’s information technology infrastructure.