Machine Learning Driven Behavioral Analytics for Detecting Advanced Persistent Cyber Intrusions across Hybrid Enterprise Clouds
DOI:
https://doi.org/10.64235/5tgt6g53Keywords:
Machine learning, behavioral analytics, advanced persistent threats, hybrid cloud security, cyber intrusion detection, anomaly detection, enterprise cybersecurity, threat detection, cloud security, behavioral profiling, machine learning-driven security, persistent intrusionAbstract
Advanced persistent threats (APTs) represent a significant challenge for enterprises operating hybrid cloud environments because attackers can maintain long-term access while adapting their behavior to avoid conventional security controls. Hybrid enterprise clouds combine private infrastructure, public cloud services, virtual machines, containers, applications, APIs, identity platforms, and interconnected networks, creating a highly dynamic attack surface. Signature-based intrusion detection and static security rules can be effective against known threats but may struggle to identify subtle behavioral changes associated with persistent compromise. Machine learning-driven behavioral analytics provides an alternative approach by establishing representations of normal enterprise activity and identifying deviations across users, workloads, identities, applications, and network resources. This study investigates a behavioral analytics framework for detecting advanced persistent cyber intrusions across hybrid enterprise clouds. The proposed methodology integrates network, identity, endpoint, application, cloud audit, and resource telemetry; applies temporal feature engineering and behavioral profiling; and evaluates supervised, unsupervised, and hybrid machine learning techniques. Cross-domain correlation is incorporated to identify multi-stage attack behavior that may appear benign when individual events are analyzed independently. Performance is evaluated using precision, recall, F1-score, false-positive rate, detection latency, and robustness under concept drift and incomplete telemetry. The research further examines adversarial manipulation, class imbalance, model explainability, and scalability. The proposed approach seeks to improve early identification of persistent threats while supporting contextual, adaptive, and explainable security monitoring across heterogeneous enterprise cloud infrastructures.
Downloads
Published
Issue
Section
License

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.

