Advanced Persistent Threath Identification
Youness Bouchari
Advanced Persistent Threath Identification.
Rel. Marco Mellia. Politecnico di Torino, Corso di laurea magistrale in Ingegneria Informatica (Computer Engineering), 2025
|
Preview |
PDF (Tesi_di_laurea)
- Tesi
Licenza: Creative Commons Attribution Non-commercial No Derivatives. Download (1MB) | Preview |
Abstract
Advanced Persistent Threat Identification. Advanced Persistent Threats (APTs) represent one of the most critical challenges in modern cybersecurity. Their stealthy and evolving nature makes them particularly difficult to detect within the massive volume of system logs generated by enterprise environments. This thesis investigates the use of machine learning for APT detection from log data, comparing shallow classifiers, deep learning approaches, and a tactic-aware ensemble of fine-tuned BERT heads. \\ The experiments demonstrate that while shallow models can achieve competitive performance under random data splits, they fail to generalize when evaluated chronologically, underscoring their limited ability to adapt to the evolving behaviors characteristic of APT campaigns.
Deep learning models, especially fine-tuned BERT, provide stronger and more stable performance, benefiting from their ability to capture contextual relationships within logs
Tipo di pubblicazione
URI
![]() |
Modifica (riservato agli operatori) |
