{"title":"Real-Time APT Detection Technologies: A Literature Review","authors":"S. Mönch, Hendrik Roth","doi":"10.1109/CSR57506.2023.10224983","DOIUrl":null,"url":null,"abstract":"Recently, the usage of advanced persistent threats (APT) increased rapidly in the context of cyberwar. To perform countermeasures against such attacks, an efficient APT detection is necessary. Detecting these attacks in real-time reduces the resulting damage since countermeasures can be applied more quickly. However, not every detection method is applicable in real-time. This paper presents a literature review of technologies used for real-time APT detection based on 26 research articles. The identified technologies are machine learning algorithms, graph inferences, statistical metrics, and rule-based systems.","PeriodicalId":354918,"journal":{"name":"2023 IEEE International Conference on Cyber Security and Resilience (CSR)","volume":"26 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2023-07-31","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2023 IEEE International Conference on Cyber Security and Resilience (CSR)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/CSR57506.2023.10224983","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0
Abstract
Recently, the usage of advanced persistent threats (APT) increased rapidly in the context of cyberwar. To perform countermeasures against such attacks, an efficient APT detection is necessary. Detecting these attacks in real-time reduces the resulting damage since countermeasures can be applied more quickly. However, not every detection method is applicable in real-time. This paper presents a literature review of technologies used for real-time APT detection based on 26 research articles. The identified technologies are machine learning algorithms, graph inferences, statistical metrics, and rule-based systems.