English
Related papers

Related papers: OCR-APT: Reconstructing APT Stories from Audit Log…

200 papers

Advanced Persistent Threats (APTs) pose a severe challenge to cyber defense due to their stealthy behavior and the extreme class imbalance inherent in detection datasets. To address these issues, we propose a novel active learning-based…

Machine Learning · Computer Science 2025-08-27 Sidahmed Benabderrahmane , Talal Rahwan

Advanced Persistent Threat (APT) attribution is a critical challenge in cybersecurity and implies the process of accurately identifying the perpetrators behind sophisticated cyber attacks. It can significantly enhance defense mechanisms and…

Cryptography and Security · Computer Science 2024-10-08 Nanda Rani , Bikash Saha , Sandeep Kumar Shukla

Advanced Persistent Threats (APTs) represent a growing menace to modern digital infrastructure. Unlike traditional cyberattacks, APTs are stealthy, adaptive, and long-lasting, often bypassing signature-based detection systems. This paper…

Cryptography and Security · Computer Science 2025-08-27 Sidahmed Benabderrahmane , Talal Rahwan

Software Defined Networking (SDN) has brought significant advancements in network management and programmability. However, this evolution has also heightened vulnerability to Advanced Persistent Threats (APTs), sophisticated and stealthy…

Cryptography and Security · Computer Science 2024-11-12 Hedyeh Nazari , Abbas Yazdinejad , Ali Dehghantanha , Fattane Zarrinkalam , Gautam Srivastava

APT detection is difficult to detect due to the long-term latency, covert and slow multistage attack patterns of Advanced Persistent Threat (APT). To tackle these issues, we propose TBDetector, a transformer-based advanced persistent threat…

Cryptography and Security · Computer Science 2025-07-18 Nan Wang , Xuezhi Wen , Dalin Zhang , Xibin Zhao , Jiahui Ma , Mengxia Luo , Fan Xu , Sen Nie , Shi Wu , Jiqiang Liu

Previous works on the CERT insider threat detection case have neglected graph and text features despite their relevance to describe user behavior. Additionally, existing systems heavily rely on feature engineering and audit data aggregation…

Machine Learning · Computer Science 2020-07-15 Mathieu Garchery , Michael Granitzer

Cyber Threat hunting is a proactive search for known attack behaviors in the organizational information system. It is an important component to mitigate advanced persistent threats (APTs). However, the attack behaviors recorded in…

Cryptography and Security · Computer Science 2021-04-21 Renzheng Wei , Lijun Cai , Aimin Yu , Dan Meng

As Advanced Persistent Threats (APTs) grow increasingly sophisticated, the demand for effective detection methods has intensified. This study addresses the challenge of identifying APT campaign attacks through system event logs. A cascading…

Cryptography and Security · Computer Science 2024-10-31 Yi-Ting Huang , Ying-Ren Guo , Guo-Wei Wong , Meng Chang Chen

One of the most common and important destructive attacks on the victim system is Advanced Persistent Threat (APT)-attack. The APT attacker can achieve his hostile goals by obtaining information and gaining financial benefits regarding the…

Cryptography and Security · Computer Science 2021-01-19 Javad Hassannataj Joloudari , Mojtaba Haderbadi , Amir Mashmool , Mohammad GhasemiGol , Shahab S. , Amir Mosavi

This paper presents an underlying framework for both automating and accelerating malware classification, more specifically, mapping malicious executables to known Advanced Persistent Threat (APT) groups. The main feature of this analysis is…

Cryptography and Security · Computer Science 2025-04-23 Noah Subedar , Taeui Kim , Saathwick Venkataramalingam

Advanced persistent threat (APT) is a kind of stealthy, sophisticated, and long-term cyberattack that has brought severe financial losses and critical infrastructure damages. Existing works mainly focus on APT defense under stable network…

Computer Science and Game Theory · Computer Science 2023-09-04 Zixuan Wang , Jiliang Li , Yuntao Wang , Zhou Su , Shui Yu , Weizhi Meng

In the last decade, a new class of cyber-threats has emerged. This new cybersecurity adversary is known with the name of "Advanced Persistent Threat" (APT) and is referred to different organizations that in the last years have been "in the…

Cryptography and Security · Computer Science 2018-10-18 Giuseppe Laurenza , Riccardo Lazzeretti , Luca Mazzotti

Anomaly detection is a critical task in cybersecurity, where identifying insider threats, access violations, and coordinated attacks is essential for ensuring system resilience. Graph-based approaches have become increasingly important for…

Cryptography and Security · Computer Science 2026-03-31 Laura Jiang , Reza Ryan , Qian Li , Nasim Ferdosian

Event logs are widely used to record the status of high-tech systems, making log anomaly detection important for monitoring those systems. Most existing log anomaly detection methods take a log event count matrix or log event sequences as…

Software Engineering · Computer Science 2024-01-25 Zhong Li , Jiayang Shi , Matthijs van Leeuwen

With the increasing sophistication of Advanced Persistent Threats (APTs), the demand for effective detection and mitigation strategies and methods has escalated. Program execution leaves traces in the system audit log, which can be analyzed…

Cryptography and Security · Computer Science 2026-01-15 Yi-Ting Huang , Ying-Ren Guo , Yu-Sheng Yang , Guo-Wei Wong , Yu-Zih Jheng , Yeali Sun , Jessemyn Modini , Timothy Lynar , Meng Chang Chen

Critical and sophisticated cyberattacks often take multitudes of reconnaissance, exploitations, and obfuscation techniques to penetrate through well protected enterprise networks. The discovery and detection of attacks, though needing…

Cryptography and Security · Computer Science 2021-03-26 Shanchieh Jay Yang , Ahmet Okutan , Gordon Werner , Shao-Hsuan Su , Ayush Goel , Nathan D. Cahill

Provenance graphs are useful and powerful tools for representing system-level activities in cybersecurity; however, existing approaches often struggle with complex queries and flexible reasoning. This paper presents a novel approach using…

Cryptography and Security · Computer Science 2025-01-27 Fang Li , Fei Zuo , Gopal Gupta

Lateral movement is a crucial component of advanced persistent threat (APT) attacks in networks. Attackers exploit security vulnerabilities in internal networks or IoT devices, expanding their control after initial infiltration to steal…

Cryptography and Security · Computer Science 2024-11-18 Jiajun Zhou , Jiacheng Yao , Xuanze Chen , Shanqing Yu , Qi Xuan , Xiaoniu Yang

Large-scale, standardized datasets for Advanced Persistent Threat (APT) research are scarce, and inconsistent actor aliases and redundant samples hinder reproducibility. This paper presents APT-ClaritySet and its construction pipeline that…

Cryptography and Security · Computer Science 2025-12-18 Zhenhao Yin , Hanbing Yan , Huishu Lu , Jing Xiong , Xiangyu Li , Rui Mei , Tianning Zang

The rapid expansion of cloud infrastructures and distributed identity systems has significantly increased the complexity and attack surface of modern enterprises. Traditional rule based or signature driven detection systems are often…

Cryptography and Security · Computer Science 2025-12-12 Venkata Tanuja Madireddy