Electronic Thesis/Dissertation
 

Securing Critical IoT/IIoT Infrastructures: An Investigation into Detecting Advanced Persistent Threats Using Machine Learning Methodologies.

Open Access Deposited

Advanced persistent threats (APTs) are a critical concern for large organizations, particularly those with valuable intellectual property, critical infrastructure, and sensitive data. These attacks result in large-scale data breaches, defined as costing an organization at least $4.45 million (Reed, 2023). For instance, an attack targeting SolarWinds’ Orion system enabled hackers to access systems, networks, and data belonging to an estimated 33,000 customers, resulting in an estimated $18 million loss (US General Administrative Services, 2022; Satter, 2021). The rising prevalence and increased severity of APTs underscore the urgent need for more effective detection and response mechanisms.Conventional signature-based antivirus solutions and perimeter-based defenses are ineffective against APTs, however, as the latter employ advanced evasion techniques and exploit zero-day vulnerabilities. Moreover, the widespread adoption of remote work and the growing interconnections between systems have enlarged the attack surface, rendering traditional perimeter-based defenses obsolete. In this context, the novel adaptive risk (AR) model presents an effective risk mitigation approach against APTs and other sophisticated threats. This praxis proposes an ensemble machine learning (EML) model for APT detection and prediction using an AR approach. It develops a multiclass classification model utilizing a multilayered machine learning (ML) approach that integrates deep learning (DL) techniques to identify the common indicators of compromise and behavioral patterns characterizing APTs. It evaluates the performance of the algorithm based on real-world datasets and simulated APT scenarios, noting the accuracy, precision, recall, and F-1 score. The praxis makes three critical contributions to research and practice. Firstly, it develops an AR inspired APT detection and prediction using EML algorithms. Secondly, it demonstrates that using an EML model within an AR approach ensures higher APT detection and prediction capabilities than do traditional perimeter-based approaches. The performance of the model will be evaluated using metrics such as accuracy, precision, F1-score, recall, ROC-AUC, and cost function, providing a comprehensive assessment of its effectiveness. Finally, the proposed ensembled WaveNet model addresses the main challenges of traditional ML models, including limited scalability, and rigidity in adjusting to evolving APTs, while optimizing for low cost function to improve prediction confidence and trustworthiness.

Author Language Keyword Date created Type of Work License
  • All rights reserved
Rights statement GW Unit Degree Advisor Committee Member(s) Persistent URL

Notice to Authors

If you are the author of this work and you have any questions about the information on this page, please use the Contact form to get in touch with us.

Thumbnail Title Date Uploaded Visibility Actions
Preview of Gangisetti_gwu_0075A_17104.pdf Gangisetti_gwu_0075A_17104.pdf 2025-04-09 Open Access