2026· International Journal of Latest Technology in Engineering, Management & Applied Science· Vol 15, pp. 1447-1461· 0 citations
TL;DR
It is argued that unsupervised and semi-supervised machine learning, combined with AWS-native security services and governed by the NIST CSF, offer a more resilient conceptual basis for cloud APT defense than any single method in isolation.
Abstract
Cloud environments, and Amazon Web Services (AWS) in particular, host high-value data assets and mission-critical workloads that make them attractive targets for Advanced Persistent Threat (APT) actors. Because forensic investigation techniques are applied only after a breach has already been discovered, the volume and velocity of cloud-generated telemetry make proactive, automated detection capabilities essential. This paper reviews machine learning-driven anomaly detection paradigms — supervised, unsupervised, semi-supervised, and deep learning — and examines their suitability for APT detection in AWS environments. It also reviews the AWS shared-responsibility security architecture, including Identity and Access Management (IAM), encryption services, and logging and monitoring services such as AWS Cloud Trail, AWS Config, Amazon Guard Duty, Amazon Detective, and Amazon Inspector, and considers the NIST Cyber security Framework (CSF) as a governance overlay that connects these technical capabilities to organizational risk management. Drawing on this review of the peer-reviewed and primary-source literature, the paper argues that no single detection paradigm is likely sufficient on its own, and that unsupervised and semi-supervised machine learning, combined with AWS-native security services and governed by the NIST CSF, offer a more resilient conceptual basis for cloud APT defense than any single method in isolation. On this basis, the paper proposes an Integrated Cloud APT Detection and Defense Model (ICADDM) as a conceptual architecture for researchers and practitioners, maps AWS security services against the MITRE ATT&CK Cloud Matrix, and identifies the empirical validation of the model against real cloud telemetry as the principal direction for future work.
With the accelerated proliferation of cloud services and web-based applications, exposure to sophisticated cy-ber threats like zero-day vulnerabilities, advanced persistent threats, and application-layer attacks, has sharply increased. Conventional intrusion detection systems, along with cryptographic security mechanis...
Tanu Sharma, Farheen Siddiqui, Khyai Chopra et al.· International Journal of Wir...· 0 citations
Cloud is the essential component for modern computer systems, offering businesses flexible scalability and on-demand resources. However, as attackers use more complex techniques to compromise cloud networks, this technological advancement has ushered in a new era of cybersecurity challenges. Wide-ranging effects, such...
Pradnya Patil, J. Bakal· 2026 7th International Confe...· 0 citations
An AI-powered scalable anomaly detection framework for secure data processing in cloud architectures that uses machine learning techniques such as Isolation Forest, Random Forest, and deep learning models to detect abnormal patterns in cloud data.
H. S, R. .Suganeswaran, S. M et al.· International Journal of Cre...· 0 citations
An intelligent DDoS detection and mitigation framework that combines classical Machine Learning (ML) classifiers with Deep Learning (DL) architectures to achieve high-fidelity, low-latency attack identification across heterogeneous network topologies is presented.
S. Singh, Alok Kumar· International Journal of Com...· 0 citations
This review paper critically examines the integration of Artificial Intelligence (AI) and Machine Learning (ML) techniques to enhance information security within Cloud-IoT networks, focusing on hybrid Deep Learning models (CNN-LSTM), predictive analytics, and automated threat response mechanisms.
R. Saravanakumar, V.Anuratha, M.Elamparithi· International journal of com...· 0 citations
: The increased reliance on wireless and mobile communication has intensified the need for practical, real-time cybersecurity measures. This paper presents a smart Intrusion Detection System (IDS) that inspects live network traffic and identifies malicious activity with minimal delay. Built on dynamic packet sniffing w...
M. R., V. Y, Y. R. et al.· Proceedings of the 1st Inter...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.