Data Modeling
Advanced Persistent Threats (APT): A Review of Detection Challenges and Emerging Approaches
Mohammad Ibnul Hasan 1*
Data Modeling 5 (1) 1-8 https://doi.org/10.25163/data.5110893
Submitted: 16 April 2024 Revised: 01 June 2024 Accepted: 11 June 2024 Published: 13 June 2024
Abstract
Advanced persistent threats (APTs) are targeted, well-resourced cyberattacks that differ from opportunistic malware in their patience, funding, and specificity of purpose. As organizations extend services across cloud and interconnected infrastructure, the attack surface available to such actors continues to widen. This paper is structured as a narrative review. The full search strategy, sources, and screening criteria are detailed in the Methodology section; in brief, the review drew on IEEE Xplore and Google Scholar and retained six primary sources after full-text screening. Results: The review synthesizes the APT kill chain and the two dominant intrusion-detection paradigms—signature-based and anomaly-based—against this threat category. Signature-based detection performs reliably against previously catalogued attacks but is structurally unsuited to the novel, zero-day techniques APT actors favor, while anomaly-based detection offers broader theoretical coverage at the cost of elevated false-positive and false-negative rates. Layered defense frameworks spanning network, payload, and endpoint visibility appear conceptually stronger, though consistent real-world evidence remains limited. Across the literature reviewed, the more persistent obstacle is not any single detection technique's weakness but the difficulty of correlating dispersed, low-signal indicators into a coherent multi-stage narrative over time. Conclusion: No single technique reviewed here reliably detects an APT across its full life cycle, and this review argues that future work should prioritize cross-stage correlation over incremental refinement of individual detection methods.
Keywords: Advanced Persistent Threat; Intrusion Detection; Anomaly-Based Detection; Cyber Kill Chain; Cybersecurity
References
Abbas, G., Farooq, U., Singh, P., Khurana, S. S., & Singh, P. (2023). Feature engineering and ensemble learning-based classification of VPN and non-VPN-based network traffic over temporal features. SN Computer Science, 4(5), 546. https://doi.org/10.1007/s42979-023-01944-5
Abu Bakar, R., Huang, X., Javed, M. S., Hussain, S., & Majeed, M. F. (2023). An intelligent agent-based detection system for DDoS attacks using automatic feature extraction and selection. Sensors, 23(6), 3333. https://doi.org/10.3390/s23063333
Adebowale, M. A., Lwin, K. T., & Hossain, M. A. (2023). Intelligent phishing detection scheme using deep learning algorithms. Journal of Enterprise Information Management, 36(3), 747–766. https://doi.org/10.1108/JEIM-01-2020-0036
Agrawal, G., Kaur, A., & Myneni, S. (2024). A review of generative models in generating synthetic attack data for cybersecurity. Electronics, 13(2), 322. https://doi.org/10.3390/electronics13020322
Ahmad, A., Webb, J., Desouza, K. C., & Boorman, J. (2019). Strategically-motivated advanced persistent threat: Definition, process, tactics and a disinformation model of counterattack. Computers & Security, 86, 402–418. https://doi.org/10.1016/j.cose.2019.07.001
Ahmad, H. B., Gao, H., Latif, N., Aziiz, A., Auraangzeb, M., & Khan, M. T. (2024). Adversarial machine learning for detecting advanced threats inspired by StuxNet in critical infrastructure networks. In 2024 12th International Symposium on Digital Forensics and Security (ISDFS) (pp. 1–7). IEEE. https://doi.org/10.1109/ISDFS60797.2024.10527326
AlDahoul, N., Karim, A. H., & Ba Wazir, A. S. (2021). Model fusion of deep neural networks for anomaly detection. Journal of Big Data, 8(1), 1–18.
Ali, S., Abuhmed, T., El-Sappagh, S., Muhammad, K., Alonso-Moral, J. M., Confalonieri, R., Guidotti, R., Del Ser, J., Díaz-Rodríguez, N., & Herrera, F. (2023). Explainable artificial intelligence (XAI): What we know and what is left to attain trustworthy artificial intelligence. Information Fusion, 99, 101805. https://doi.org/10.1016/j.inffus.2023.101805
Alkhadra, R., Abuzaid, J., AlShammari, M., & Mohammad, N. (2021). SolarWinds hack: In-depth analysis and countermeasures. In 2021 12th International Conference on Computing Communication and Networking Technologies (ICCCNT) (pp. 1–7). IEEE. https://doi.org/10.1109/ICCCNT51525.2021.9579611
Al-Selwi, S. M., Hassan, M. F., Abdulkadir, S. J., Muneer, A., Sumiea, E. H., Alqushaibi, A., & Ragab, M. G. (2024). RNN-LSTM: From applications to modeling techniques and beyond—Systematic review. Journal of King Saud University–Computer and Information Sciences, 36(5), 102068. https://doi.org/10.1016/j.jksuci.2024.102068
Alzubaidi, L., Zhang, J., Humaidi, A. J., Al-Dujaili, A., Duan, Y., Al-Shamma, O., Santamaría, J., Fadhel, M. A., Al-Amidie, M., & Farhan, L. (2021). Review of deep learning: Concepts, CNN architectures, challenges, applications, future directions. Journal of Big Data, 8(1), 53. https://doi.org/10.1186/s40537-021-00444-8
Angelov, P. P., Soares, E. A., Jiang, R., Arnold, N. I., & Atkinson, P. M. (2021). Explainable artificial intelligence: An analytical review. Wiley Interdisciplinary Reviews: Data Mining and Knowledge Discovery, 11(5), e1424. https://doi.org/10.1002/widm.1424
Antwarg, L., Miller, R. M., Shapira, B., & Rokach, L. (2021). Explaining anomalies detected by autoencoders using Shapley additive explanations. Expert Systems with Applications, 186, 115736. https://doi.org/10.1016/j.eswa.2021.115736
Bach, S., Binder, A., Montavon, G., Klauschen, F., Müller, K.-R., & Samek, W. (2015). On pixel-wise explanations for non-linear classifier decisions by layer-wise relevance propagation. PLoS ONE, 10(7), e0130140. https://doi.org/10.1371/journal.pone.0130140
Ballard. (2021). Cybercrime apparently cost the world over $1 trillion in 2020. TechRadar. https://www.techradar.com/news/cybercrime-cost-the-world-over-dollar1-trillion-in-2020
Band, S., Yarahmadi, S., Hsu, A., Biyari, C.-C., Sookhak, M., Ameri, M., Dehzangi, R., Chronopoulos, I. A. T., & Liang, H.-W. (2023). Application of explainable artificial intelligence in medical health: A systematic review of interpretability methods. Informatics in Medicine Unlocked, 40, 101286. https://doi.org/10.1016/j.imu.2023.101286
Barnard, P., Marchetti, N., & DaSilva, L. A. (2022). Robust network intrusion detection through explainable artificial intelligence (XAI). IEEE Networking Letters, 4(3), 167–171. https://doi.org/10.1109/LNET.2022.3186589
Bell, P. (2019, January 3). Cyber threat report [Threat intelligence report]. Publisher and URL to be confirmed by author prior to submission.
Beuhring, A., & Salous, K. (2014). Beyond blacklisting: Cyberdefense in the era of advanced persistent threats. IEEE Security & Privacy, 12(5), 90–93. https://doi.org/10.1109/MSP.2014.86
Bierwirth, T., Pfützner, S., Schopp, M., & Steininger, C. (2024). Design and evaluation of advanced persistent threat scenarios for cyber ranges. IEEE Access, 12, 72458–72472. https://doi.org/10.1109/ACCESS.2024.3402744
Bodström, T., & Hämäläinen, T. (2019). A novel deep learning stack for APT detection. Applied Sciences, 9, 1055. https://doi.org/10.3390/app9061055
Brown, D., Cianfarani, G., & Vlajic, N. (2022). Real-world snapshot of trends in IoT device and protocol deployment: IEEE CNS 22 poster. In 2022 IEEE Conference on Communications and Network Security (CNS), 1(2). IEEE. https://doi.org/10.1109/CNS56114.2022.9947257
Brunke, L., Agrawal, P., & George, N. (2020). Evaluating input perturbation methods for interpreting CNNs and saliency map comparison. In A. Bartoli & A. Fusiello (Eds.), Computer vision—ECCV 2020 workshops (pp. 120–134). Springer International Publishing.
Gartner. (2013, August 20). Five styles of advanced threat defense. https://www.gartner.com/en/documents/2576720
Ghosh, S., & Sampalli, S. (2019). A survey of security in SCADA networks: Current issues and future challenges. IEEE Access, 7, 135812–135831. https://doi.org/10.1109/ACCESS.2019.2926441
Homayoun, S., Dehghantanha, A., Ahmadzadeh, M., Hashemi, S., & Khayami, R. (2017). Know abnormal, find evil: Frequent pattern mining for ransomware threat hunting and intelligence. IEEE Transactions on Emerging Topics in Computing, 8(2), 341–351. https://doi.org/10.1109/TETC.2017.2756908
Jouini, M., & Rabai, L. B. A. (2019). A security framework for secure cloud computing environments. In Cloud security: Concepts, methodologies, tools, and applications (pp. 249–263). IGI Global. https://doi.org/10.4018/978-1-5225-8176-5.ch012
Liu, J., Gao, Y., & Hu, F. (2019). ANID-SEoKELM: Adaptive network intrusion detection based on selective ensemble of kernel ELMs with random features. Knowledge-Based Systems, 177, 104–116. https://doi.org/10.1016/j.knosys.2019.04.008
Recommended articles
Integrating Machine Learning, Business Analytics, and Cybersecurity: A Human-Centered Pathway for Strategic Resilience in the Age of Data
Save
Citation
View
Share