Submitted:
23 August 2025
Posted:
26 August 2025
You are already at the latest version
Abstract
Keywords:
1. Introduction
2. Foundations: APTs, Anatomy, and Network Anomalies
2.1. Definition and Nature
2.2. Kill Chain and TTPs (Mapped to ATT&CK)
2.3. Taxonomy of APT-Induced Anomalies
2.4. Mathematical Groundwork
3. Literature Review
4. Methodology (Rigorous Formalization)
4.1. Feature Space and Normalization
4.2. Approximate LRT via Generative Models
4.3. Sequential Detection
4.4. Graph Modeling and GNNs
4.5. Federated Learning and Robustness
4.6. Calibration and Active Learning
4.7. Metrics and Validation
5. Development: AI Solutions for APTs in Live Networks
5.1. Reference Architecture (Pipeline)
5.2. Algorithm 1 — VAE–LSTM for Beaconing and Exfiltration
5.3. Algorithm 2 — OC-SVM + Isolation Forest (Rare Behaviors)
5.5. Explainability and ATT&CK Mapping
5.6. Operational Robustness
6. Results (Controlled Experiments and Reproduction)
6.1. Global Metrics (Representative)
6.2. Ablation
6.3. By Kill-Chain Phase
6.4. Operational Cost
7. Discussion (In-Depth Reflection)
8. Conclusion
Funding
Data Availability Statement
Conflicts of Interest
References
- E. M. Hutchins, M. J. Cloppert, and R. M. Amin, "Intelligence-Driven Computer Network Defense Informed by Analysis of Adversary Campaigns and Intrusion Kill Chains," Proc. 6th Int. Conf. on Information Warfare and Security, 2011.
- MITRE, "ATT&CK®: A knowledge base of adversary tactics and techniques," 2023.
- Mandiant, "APT1: Exposing One of China’s Cyber Espionage Units," 2013.
- Verizon, "Data Breach Investigations Report (DBIR)," 2023.
- FireEye, "M-Trends 2022: Data, detections and disruptions," 2022.
- V. Chandola, A. Banerjee, and V. Kumar, "Anomaly detection: A survey," ACM Computing Surveys, vol. 41, no. 3, 2009.
- NIST, "Computer Security Incident Handling Guide," SP 800-61 Rev. 2, 2012.
- NIST, "Guide to Intrusion Detection and Prevention Systems (IDPS)," SP 800-94, 2007.
- M. Ahmed, A. N. Mahmood, and J. Hu, "A survey of network anomaly detection techniques," Journal of Network and Computer Applications, vol. 60, 2016. [CrossRef]
- R. Sommer and V. Paxson, "Outside the closed world: On using machine learning for network intrusion detection," IEEE S&P, 2010.
- K. L. Richer, P. Barford, and J. Crovella, "Learning communication profiles for network traffic anomaly detection," IMC, 2004.
- M. Tavallaee et al., "A detailed analysis of the KDD Cup 99 data set," CISDA, 2009. [CrossRef]
- I. Sharafaldin, A. H. Lashkari, and A. A. Ghorbani, "Toward generating a new intrusion detection dataset and intrusion traffic characterization," ICISSP, 2018.
- N. Moustafa and J. Slay, "UNSW-NB15: A comprehensive data set for network intrusion detection systems," MILCIS, 2015.
- I. Sharafaldin, A. H. Lashkari, and A. A. Ghorbani, "CICIDS2017 dataset," 2017.
- A. H. Lashkari et al., "Toward developing a systematic approach to generate benchmark datasets for intrusion detection," IEEE Access, 2019.
- S. García, M. Grill, J. Stiborek, and A. Zunino, "An empirical comparison of botnet detection methods," Computers & Security, 2014. [CrossRef]
- J. Gama et al., "A survey on concept drift adaptation," ACM Computing Surveys, 2014. [CrossRef]
- C. Cortes and V. Vapnik, "Support-vector networks," Machine Learning, 1995.
- M. M. Breunig et al., "LOF: Identifying density-based local outliers," SIGMOD, 2000.
- F. T. Liu, K. M. Ting, and Z.-H. Zhou, "Isolation forest," ACM TKDD, 2008.
- B. Schölkopf et al., "Estimating the support of a high-dimensional distribution," Neural Computation, 2001. [CrossRef]
- I. Goodfellow, Y. Bengio, and A. Courville, Deep Learning. MIT Press, 2016.
- P. Vincent et al., "Stacked denoising autoencoders," JMLR, 2010.
- D. P. Kingma and M. Welling, "Auto-Encoding Variational Bayes," ICLR, 2014.
- R. Patcha and J.-M. Park, "An overview of anomaly detection techniques: Existing solutions and latest technological trends," Computer Networks, 2007.
- S. Hochreiter and J. Schmidhuber, "Long short-term memory," Neural Computation, 1997.
- T. N. Kipf and M. Welling, "Semi-supervised classification with graph convolutional networks," ICLR, 2017.
- P. Veličković et al., "Graph attention networks," ICLR, 2018.
- Z. Wu et al., "A comprehensive survey on graph neural networks," IEEE TNNLS, 2021.
- B. Biggio et al., "Evasion attacks against machine learning at test time," ECML PKDD, 2013.
- N. Papernot et al., "Practical black-box attacks against machine learning," ACM CCS, 2017.
- J. Platt, "Probabilistic outputs for SVM and comparisons to regularized likelihood methods," 1999.
- C. Guo et al., "On calibration of modern neural networks," ICML, 2017.
- N. Provos and T. Holz, Virtual Honeypots: From Botnet Tracking to Intrusion Detection. Addison-Wesley, 2007.
- H. Kim et al., "Deep learning for network traffic classification," IEEE Network, 2018.
- A. Moore and D. Zuev, "Internet traffic classification using Bayesian analysis techniques," SIGMETRICS, 2005. [CrossRef]
- A. Clements et al., "Analyzing the adversarial robustness of ML-based network intrusion detectors," RAID, 2019.
- M. Rigaki and S. García, "Bringing a GAN to a knife-fight: Adapting malware communication to avoid detection," Security and ML Workshop, 2018.
- Y. Xin et al., "Machine learning and deep learning methods for cybersecurity," IEEE Access, 2018. [CrossRef]
- M. Roesch, "Snort—Lightweight intrusion detection for networks," LISA, 1999.
- V. Paxson, "Bro: A system for detecting network intruders in real-time," Computer Networks, 1999. [CrossRef]
- OISF, "Suricata IDS/IPS/NSM," 2021.
- E. S. Page, "Continuous inspection schemes," Biometrika, 1954.
- M. Basseville and I. Nikiforov, Detection of Abrupt Changes: Theory and Application. Prentice Hall, 1993. [CrossRef]
- S. W. Roberts, "A comparison of some control chart procedures," Technometrics, 1966.
- T. Ergen and M. White, "Unsupervised anomaly detection with LSTM neural networks," UAI Workshop, 2017.
- A. Lim et al., "Time-series forecasting with deep learning: A survey," arXiv:2004.13408, 2020.
- H. He et al., "Concept drift adaptation by online learning," IEEE SMC, 2011.
- ISO/IEC, "ISO/IEC 27001:2022 Information security management systems," 2022.
- NIST, "Security and Privacy Controls for Information Systems and Organizations," SP 800-53 Rev. 5, 2020.
- A. Sperotto et al., "An overview of IP flow-based intrusion detection," IEEE Communications Surveys & Tutorials, 2010. [CrossRef]
- L. Zong et al., "Deep autoencoding Gaussian mixture model for unsupervised anomaly detection," ICLR Workshop, 2018.
- A. Boracchi et al., "Anomaly detection in streams with concept drift based on density ratio estimation," ICDM Workshops, 2018.
- B. Settles, Active Learning, Morgan & Claypool, 2012.
- Y. LeCun, Y. Bengio, and G. Hinton, "Deep learning," Nature, 2015.
- M. Abadi et al., "TensorFlow: Large-scale machine learning on heterogeneous systems," 2016.
- B. McMahan et al., "Communication-efficient learning of deep networks from decentralized data," AISTATS, 2017.
- P. Blanchard et al., "Byzantine-tolerant machine learning," NeurIPS, 2017.
- S. Lundberg and S.-I. Lee, "A unified approach to interpreting model predictions," NeurIPS, 2017.
- M. T. Ribeiro, S. Singh, and C. Guestrin, "Why should I trust you?: Explaining the predictions of any classifier," KDD, 2016.
- J. Saxe and K. Berlin, Malware Data Science, No Starch Press, 2018.
- B. Anderson and D. McGrew, "Machine learning for encrypted malware traffic classification," AISec, 2016.
- A. Sperotto and R. Sadre, "Flow-based intrusion detection," in Flow-based Monitoring and Analysis of Internet Traffic, Wiley, 2013.
- R. Sommer and V. Paxson, "Challenges of machine learning in high-speed networks," HotNets, 2003.
- A. Lazarevic et al., "A comparative study of anomaly detection schemes in network intrusion detection," SDM, 2003.
- G. Salton and C. Buckley, "Term-weighting approaches in automatic text retrieval," Information Processing & Management, 1988. [CrossRef]
- B. Nelson et al., "Toward secure ML: Security and privacy risks of ML systems," IEEE S&P Workshops, 2018.
- M. Kantarcioglu et al., "Adversarial data mining: Big data perspective," KDD, 2012.
- J. Shapiro and A. Varghese, "DNS tunneling detection using entropy and ML," MILCOM, 2013.
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2025 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (http://creativecommons.org/licenses/by/4.0/).