Advanced Persistent Threat (APT) Detection Using SIEM: A Review of Techniques and Tools
Downloads
APTs are hard to fight in cybersecurity since they are difficult to spot, aimed at a single target and continue for a long time. Advanced threats evade traditional security solutions which is why it’s important to use stronger defense systems. Because they centralize the collection of security events, security information and event management (SIEM) systems have grown in significance, compare them instantly and analyze them for large organizations. In this review paper, it analyzes existing ways and tools for finding APT threats using SIEM platforms. First, the article describes what APTs are and how SIEM works. Different ways to detect APTs, such as using signatures, abnormal behavior and machine learning, are looked at, and their pros and cons are presented. The document explains how well-known SIEM programs perform in terms of capabilities and how easily they can fetch information from third-party sources of threat intelligence. When performing a detailed literature review, the author summarizes current research, explores new frameworks and highlights the challenges that come with the lack of data, trouble measuring outcomes and limited resources. To finish, the paper highlights upcoming trends and research goals designed to boost SIEM’s protection against APTs by urging the use of adaptive, smart and situation-aware security architectures. The main purpose of this study is to give researchers and practitioners advice on how to secure organizations against difficult cyber threats.
H. Okamoto, “The Role of Information Security Event Management (SIEM) in Enhancing Intrusion Detection and Cybersecurity Through Machine Learning Technology.” 2021.
doi: 10.13140/RG.2.2.35096.00003.
N. K. Prajapati, “Federated Learning for Privacy-Preserving Cybersecurity: A Review on Secure Threat Detection,” Int. J. Adv. Res. Sci. Commun. Technol., pp. 520–528, Apr. 2025, doi: 10.48175/IJARSCT-25168.
G. Wang, Y. Cui, J. Wang, L. Wu, and G. Hu, “A Novel Method for Detecting Advanced Persistent Threat Attack Based on Belief Rule Base,” Appl. Sci., vol. 11, no. 21, 2021, doi: 10.3390/app11219899.
B. Stojanović, K. Hofer-Schmitz, and U. Kleb, “APT datasets and attack modeling for automated detection methods: A review,” Comput. & Secur., vol. 92, p. 101734, 2020.
A. Alshamrani, S. Myneni, A. Chowdhary, and D. Huang, “A Survey on Advanced Persistent Threats: Techniques, Solutions, Challenges, and Research Opportunities,” IEEE Commun. Surv. Tutorials, vol. 21, no. 2, pp. 1851–1877, 2019, doi: 10.1109/COMST.2019.2891891.
A. R. Muhammad, P. Sukarno, and A. A. Wardana, “Integrated Security Information and Event Management (SIEM) with Intrusion Detection System (IDS) for Live Analysis based on Machine Learning,” Procedia Comput. Sci., vol. 217, pp. 1406–1415, 2023, doi: 10.1016/j.procs.2022.12.339.
B. Genge, P. Haller, and A.-S. Roman, “E-APTDetect: Early Advanced Persistent Threat Detection in Critical Infrastructures with Dynamic Attestation,” Appl. Sci., vol. 13, no. 6, 2023, doi: 10.3390/app13063409.
S. B. Shah, “Machine Learning for Cyber Threat Detection and Prevention in Critical Infrastructure,” J. Glob. Res. Electron. Commun., vol. 2, no. 2, pp. 1–7, 2025, doi: 10.5281/zenodo.14955016.
A. Singla, E. Bertino, and D. Verma, “Preparing network intrusion detection deep learning models with minimal data using adversarial domain adaptation,” in Proceedings of the 15th ACM Asia conference on computer and communications security, 2020, pp. 127–140.
V. Prajapati, “Enhancing Threat Intelligence and Cyber Defense through Big Data Analytics : A Review Study,” J. Glob. Res. Math. Arch., vol. 12, no. 4, pp. 1–6, 2025.
S. Chatterjee, “Risk Management in Advanced Persistent Threats (APTs ) for Critical Infrastructure in the Utility Industry,” Int. J. Multidiscip. Res., vol. 3, no. 4, pp. 1–10, 2021.
S. Krishnapriya and S. Singh, “A Comprehensive Survey on Advanced Persistent Threat (APT) Detection Techniques.,” Comput. Mater. & Contin., vol. 80, no. 2, 2024.
A. K. Polinati, “AI-Powered Anomaly Detection in Cybersecurity: Leveraging Deep Learning for Intrusion Prevention,” Int. J. Commun. Networks Inf. Secur., vol. 17, no. 3, 2025.
L. Hase, “The Path to Choosing a SIEM System – A Systematic Literature Review,” Semin. IT-Management Digit. Age, no. Summer, pp. 1–12, 2024.
M. Sheeraz et al., “Effective Security Monitoring Using Efficient SIEM Architecture,” Human-centric Comput. Inf. Sci., vol. 13, 2023, doi: 10.22967/HCIS.2023.13.023.
M. Aymard, “Security Monitoring System Applied to IoT,” Universidad Politécnica de Madrid, 2019.
G. Granadillo, S. González-Zarzosa, and R. Diaz, “Security Information and Event Management (SIEM): Analysis, Trends, and Usage in Critical Infrastructures,” Sensors, vol. 21, p. 4759, 2021, doi: 10.3390/s21144759.
H. Kali, “The Future of HR Cybersecurity: AI-Enabled Anomaly Detection in Workday Security,” Int. J. Recent Technol. Sci. Manag., vol. 8, no. 6, pp. 80–88, 2023.
W. Ahmed, “Advanced Persistent Threats (APTs) Analysing: Current Detection Techniques and Emerging Countermeasures,” Prem. J. Artif. Intell., 2025, doi: 10.70389/PJAI.100011.
A. Meliboev, J. Alikhanov, and W. Kim, “Performance Evaluation of Deep Learning Based Network Intrusion Detection System across Multiple Balanced and Imbalanced Datasets,” Electronics, vol. 11, no. 4, p. 515, Feb. 2022,
doi: 10.3390/electronics11040515.
S. R. Pulyala, “From Detection to Prediction: AI-powered SIEM for Proactive Threat Hunting and Risk Mitigation,” Turkish J. Comput. Math. Educ., 2024, doi: 10.61841/turcomat.v15i1.14393.
Z. Oughannou, Z. EL Rhadiouini, H. Chaoui, and S. Bourekkadi, “Anomaly-Based Intrusion Detection System To Detect Advanced Persistent Threats: Environmental Sustainability,” E3S Web Conf., vol. 412, pp. 1–6, 2023,
doi: 10.1051/e3sconf/202341201106.
A. Bhardwaj, K. Kaushik, A. Alomari, A. Alsirhani, M. M. Alshahrani, and S. Bharany, “BTH: Behavior-Based Structured Threat Hunting Framework to Analyze and Detect Advanced Adversaries,” Electronics, vol. 11, no. 19, 2022,
doi: 10.3390/electronics11192992.
S. Murri, “Data Security Challenges and Solutions in Big Data Cloud Environments,” Int. J. Curr. Eng. Technol., vol. 12, no. 06, Jun. 2022, doi: 10.14741/ijcet/v.12.6.11.
V. Malik, A. Khanna, N. Sharma, and S. Nalluri, “Advanced Persistent Threats (APTs): Detection Techniques and Mitigation Strategies,” Int. J. Glob. Innov. Solut., 2024,
doi: 10.21428/e90189c8.91e89a3e.
S. Arora and S. R. Thota, “Ethical Considerations and Privacy in AI-Driven Big Data Analytics,” Int. Res. J. Eng. Technol., vol. 11, no. 05, 2024.
J. Manzoor, A. Waleed, A. F. Jamali, and A. Masood, “Cybersecurity on a budget: Evaluating security and performance of open-source SIEM solutions for SMEs,” PLoS One, vol. 19, no. 3, Mar. 2024, doi: 10.1371/journal.pone.0301183.
K. Bezas and F. Filippidou, “Comparative Analysis of Open Source Security Information & Event Management Systems (SIEMs),” Indones. J. Comput. Sci., vol. 12, pp. 443–468, 2023,
doi: 10.33022/ijcs.v12i2.3182.
A. Elkosairy, N. Abdelbaki, and H. K. Aslan, “A Survey on the Integration of Cyber Threat Feeds and Blockchain Technology,” Int. J. Saf. Secur. Eng., vol. 14, no. 5, Oct. 2024, doi: 10.18280/ijsse.140502.
R. Buchta, G. Gkoktsis, F. Heine, and C. Kleiner, “Advanced Persistent Threat Attack Detection Systems: A Review of Approaches, Challenges, and Trends,” Digit. Threat. Res. Pract., vol. 5, no. 4, pp. 1–37, Dec. 2024, doi: 10.1145/3696014.
A. S. AL-Aamri, R. Abdulghafor, S. Turaev, I. Al-Shaikhli, A. Zeki, and S. Talib, “Machine Learning for APT Detection,” Sustainability, vol. 15, no. 18, 2023, doi: 10.3390/su151813820.
A. A. Al-Kadhimi, M. M. Singh, and M. N. A. Khalid, “A Systematic Literature Review and a Conceptual Framework Proposition for Advanced Persistent Threats (APT) Detection for Mobile Devices Using Artificial Intelligence Techniques,” Appl. Sci., vol. 13, no. 14, 2023, doi: 10.3390/app13148056.
S. R. Pulyala, “The Future of SIEM in a Machine Learning-Driven Cybersecurity Landscape,” Turkish J. Comput. Math. Educ., vol. 14, no. 03, pp. 1309–1314, Jul. 2023,
doi: 10.61841/turcomat.v14i03.14392.
N. Jeffrey, Q. Tan, and J. R. Villar, “A Review of Anomaly Detection Strategies to Detect Threats to Cyber-Physical Systems,” Electron., vol. 12, no. 15, pp. 1–34, 2023, doi: 10.3390/electronics12153283.
A. Şimşek and A. Koltuksuz, “Detection of Advanced Persistent Threats Using Siem Rulesets,” Int. J. 3D Print. Technol. Digit. Ind., vol. 7, no. 3, pp. 471–477, Dec. 2023, doi: 10.46519/ij3dptdi.1353341.
