Skip to content
Conference

Predicting Advanced Persistent Threats using Cyber Threat Intelligence and Machine Learning Techniques

Jul 2026 · 2026 6th International Conference on Inventive Computation and Information Technologies (ICICIT) · pp. 250-255 · 0 citations · 13 references

Abstract

APTs can be very advanced, able to hide within an organization for years, potentially compromising sensitive data and information. Old-fashioned signature-driven security tools don't keep up with the latest and most advanced attacks, and thus require proactive and intel-driven threats detection products. This research aims to design an early prediction and detection system of Advanced Persistent Threat activities with a machine learning system that works on Cyber Threat Intelligence. The architecture pulls together any and all threat intelligence gathered from network traffic logs, security alerts and external sources including Indicators of Compromise that include suspicious IP addresses, malicious website addresses, and other unusual communications. After data preprocessing and feature engineering, machine learning models such as Random Forest, Support Vector Machine, and Gradient Boosting are employed to learn the harmful user actions and foresee potentially high-risk actions. This suggested methodology is tested using the CICIDS2017 and UNSW-NB15 benchmark datasets of cyber security. It was observed from the experimental results that the best results has been obtained by Random Forest classifier with the highest accuracy as 97.8% after the differentiation of the legitimate and harmful activity. The results show that the integration of Cyber Threat Intelligence with machine learning has a significant impact on early threat detection, reduces the number of false-positive alerts and strengthens cyber security efforts to prevent Advanced Persistent Threat attacks.

View source

Similar papers

Open access Jul 2026

Advanced Machine Learning Model for Anticipating and Preventing Cyber Attacks Using Random Forest (RF)

An Advanced Machine Learning Model for Anticipating and Preventing Cyber Attacks Using Random Forest is presented, which effectively detects cyber threats with high accuracy and reliability, thereby improving threat anticipation and reducing security risks.

T Pushpalatha and RP Rajeshwari · 0 citations
Review Open access Jul 2026

A Review on Supervised Machine Learning Techniques for Enhancing Cyber Threat Prediction Accuracy

Experimental results demonstrate that an ensemble-optimized model achieves improved predictive accuracy, reduced false positives, and enhanced generalization to unseen attack patterns, providing a scalable and adaptive defense against evolving cyber threats in online banking.

Bandana Gupta, C. S. Gautam · 0 citations
Open access 2026

AI-DRIVEN THREAT DETECTION USING DATA SCIENCE: A COMPARATIVE STUDY OF MACHINE LEARNING MODELS ON CYBERSECURITY DATASETS

They originate from the rapid rise of cyber threats such as malware, phishing, ransomware, denial of service, and unauthorised network intrusion, which have proven to be so difficult to tackle that traditional security measures can hardly deal with the issue. Signature-based intrusion detection system techniques in particular, which are commonly adopted by traditional methods, usually lack the ability to detect novel and evolving attack vectors in addition to high false positive rate and response time. In this regard, this paper proposes an AI threat detection framework, employing data science methods to boost cybersecurity performances. The researchers of this paper have tested the effectiveness of several models using a benchmark dataset for cyber security, including CICIDS2017 or NSL-KDD and machine learning techniques such as Random Forest, Support Vector Machine, Logistic Regression and XGBoost for evaluating performance. Using measures of accuracy, precision, recall and F1- score, the experiments show that the performance of ensemble learning models is higher than shallow learning models in this research; XGBoost and Random Forest.

Praveen Kumar Reddy Gouni · 0 citations
Open access Jul 2026

Beyond the Signature: Machine Learning for Adaptive Cyber Threat Intelligence

Modern cyberattacks are increasingly dynamic, multi-stage, and difficult to recognize with static signatures alone. Machine learning (ML) provides a complementary approach by learning patterns from large volumes of security telemetry and identifying behavior that may indicate compromise. This paper presents an integrated framework for applying ML across the cyber threat intelligence lifecycle, from data ingestion and preprocessing to model training, deployment, continuous monitoring, and response. It discusses supervised classification and anomaly detection, together with specialized security functions such as web filtering, dynamic sandboxing, behavioral analysis, deceptive-domain detection, and email protection. The paper also emphasizes a human-in-the-loop model in which automated systems prioritize evidence while analysts validate important decisions. Finally, it considers data drift, concept drift, adversarial manipulation, privacy, and retraining. The proposed approach treats ML as one layer of a broader defense system, combining automated pattern recognition with threat context and human expertise to improve detection speed, reduce alert fatigue, and support adaptive cyber defense.

Mitra Bhargeshbhai Patel, Bindi Bhatt, Dharvi Soni et al. · 0 citations
Aug 2026

AI-Based Cybersecurity Threat Detection Using Machine Learning

A multi-layered intelligent detection system that unites supervised learning, unsupervised anomaly analysis, and ensemble decision strategies to identify network intrusions, malicious software activity, and stealthy advanced persistent threats in near real time is introduced.

Ameen Pasha.A · 0 citations
Open access Jul 2026

Artificial Intelligence-Driven Cybersecurity Framework for Enterprise Threat Detection: A Machine Learning Approach

The increasing complexity of cyber threats has exposed the limitations of traditional signature-based intrusion detection systems, creating a need for intelligent and adaptive cybersecurity solutions. This study proposes an artificial intelligence-driven cybersecurity framework for enterprise threat detection using the CICIDS2017 benchmark dataset. The framework incorporates data preprocessing, feature engineering, and supervised machine learning to classify network traffic as benign or malicious. Seven machine learning algorithms, including Logistic Regression, Decision Tree, Support Vector Machine, Random Forest, Extra Trees, LightGBM, and XGBoost, were evaluated using accuracy, precision, recall, F1-score, and AUC-ROC. The results indicate that ensemble learning models outperform conventional classifiers, with XGBoost achieving the highest performance, recording 99.42% accuracy, 99.39% precision, 99.31% recall, 99.35% F1-score, and an AUC-ROC of 0.999. LightGBM also demonstrated excellent performance with lower computational time. The findings suggest that the proposed XGBoost-based framework provides an accurate, scalable, and efficient solution for real-time enterprise threat detection and can be effectivel

Sanjida Akter Tisha · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.