Prospective Study of Models for Advanced Persistent Threat Detection: A Comprehensive Analysis
摘要
Advance persistent threats are target attacks carried out by sophisticated and well-resourced adversaries targeting specific information in high-profile companies and governments, typically throughout a long campaign with multiple steps. Researchers have investigated the same behavior patterns of this threat to develop methods and models for the timely detection of these attacks. The use of Machine Learning can assist in the detection, immediate notification, and automatic prediction of these types of threats, minimizing the time an attacker can spend on a network organization. The goal of this work is to assess the proposed models, characterize their distinctive traits, analyze their attack models, and identify the tools and approaches that they have employed. We also list a few unconventional defenses that can lessen the impact of APTs, underlining the directions for further study in cybersecurity abstract environment.