Skip to content
Review

AWS Security Architecture and Machine Learning for APT Detection in Cloud Environments

2026 · International Journal of Latest Technology in Engineering, Management & Applied Science · Vol 15, pp. 1447-1461 · 0 citations

TL;DR

It is argued that unsupervised and semi-supervised machine learning, combined with AWS-native security services and governed by the NIST CSF, offer a more resilient conceptual basis for cloud APT defense than any single method in isolation.

Abstract

Cloud environments, and Amazon Web Services (AWS) in particular, host high-value data assets and mission-critical workloads that make them attractive targets for Advanced Persistent Threat (APT) actors. Because forensic investigation techniques are applied only after a breach has already been discovered, the volume and velocity of cloud-generated telemetry make proactive, automated detection capabilities essential. This paper reviews machine learning-driven anomaly detection paradigms — supervised, unsupervised, semi-supervised, and deep learning — and examines their suitability for APT detection in AWS environments. It also reviews the AWS shared-responsibility security architecture, including Identity and Access Management (IAM), encryption services, and logging and monitoring services such as AWS Cloud Trail, AWS Config, Amazon Guard Duty, Amazon Detective, and Amazon Inspector, and considers the NIST Cyber security Framework (CSF) as a governance overlay that connects these technical capabilities to organizational risk management. Drawing on this review of the peer-reviewed and primary-source literature, the paper argues that no single detection paradigm is likely sufficient on its own, and that unsupervised and semi-supervised machine learning, combined with AWS-native security services and governed by the NIST CSF, offer a more resilient conceptual basis for cloud APT defense than any single method in isolation. On this basis, the paper proposes an Integrated Cloud APT Detection and Defense Model (ICADDM) as a conceptual architecture for researchers and practitioners, maps AWS security services against the MITRE ATT&CK Cloud Matrix, and identifies the empirical validation of the model against real cloud telemetry as the principal direction for future work.

View source

Similar papers

Open access Aug 2026

Integrating Machine Learning–Driven Threat Detection with Advanced Cryptographic Solutions for Secure Cloud and Web Applications

With the accelerated proliferation of cloud services and web-based applications, exposure to sophisticated cy-ber threats like zero-day vulnerabilities, advanced persistent threats, and application-layer attacks, has sharply increased. Conventional intrusion detection systems, along with cryptographic security mechanis...

Tanu Sharma, Farheen Siddiqui, Khyai Chopra et al. · 0 citations
Conference Jul 2026

Review of Cyber Threat Detection Techniques in Cloud Computing Environment

Cloud is the essential component for modern computer systems, offering businesses flexible scalability and on-demand resources. However, as attackers use more complex techniques to compromise cloud networks, this technological advancement has ushered in a new era of cybersecurity challenges. Wide-ranging effects, such...

Pradnya Patil, J. Bakal · 0 citations
Open access Aug 2026

AI-Powered Scalable Anomaly Detection Framework for Secure Data Processing in Modern Cloud Architectures

An AI-powered scalable anomaly detection framework for secure data processing in cloud architectures that uses machine learning techniques such as Isolation Forest, Random Forest, and deep learning models to detect abnormal patterns in cloud data.

H. S, R. .Suganeswaran, S. M et al. · 0 citations
Open access Aug 2026

Intelligent DDOS Attack Detection and Mitigation Using Machine Learning Techniques

An intelligent DDoS detection and mitigation framework that combines classical Machine Learning (ML) classifiers with Deep Learning (DL) architectures to achieve high-fidelity, low-latency attack identification across heterogeneous network topologies is presented.

S. Singh, Alok Kumar · 0 citations
Review Open access Aug 2026

AI-ENHANCED INFORMATION SECURITY FRAMEWORKS FOR CLOUD-ENABLED IOT NETWORKS: A COMPREHENSIVE REVIEW

This review paper critically examines the integration of Artificial Intelligence (AI) and Machine Learning (ML) techniques to enhance information security within Cloud-IoT networks, focusing on hybrid Deep Learning models (CNN-LSTM), predictive analytics, and automated threat response mechanisms.

R. Saravanakumar, V.Anuratha, M.Elamparithi · 0 citations
Conference Open access 2025

Transparent Threat Detection in Mobile Networks: A Real-Time IDS with Scapy

: The increased reliance on wireless and mobile communication has intensified the need for practical, real-time cybersecurity measures. This paper presents a smart Intrusion Detection System (IDS) that inspects live network traffic and identifies malicious activity with minimal delay. Built on dynamic packet sniffing w...

M. R., V. Y, Y. R. et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.