Finding Anomalies in Communication Flows to Strengthen Network Security Against Advanced Persistent Threats (APTs) Using SVM-Based Network Traffic Analysis
摘要
The increasing frequency of advanced persistent threats (APTs) in the dynamic sector of cybersecurity calls for new techniques to increase network security. This work constructs and evaluates a sophisticated network traffic monitoring system that uses a Kernel Function to train a nonlinear support vector machine (SVM) in order to counteract APTs. Current models often fail to provide comprehensive and accurate threat detection. Recall of 94%, accuracy of 92%, precision of 88%, and F1-score of 0.95 show how much better our proposed system performs. Scalability and quick processing of large-scale datasets are ensured by the connection with Apache Spark MLlib, which is a crucial part of real-time threat detection. This work presents a novel integration of nonlinear support vector machines (SVMs) with distributed computing, resulting in a robust and adaptive method that outperforms earlier models in APT detection with respect to accuracy and reliability. The measurements that have been provided and displayed in a thorough bar chart help our suggested model stand out from the competitors. This study not only creates a new technique for detecting APTs but also sets a new benchmark for network security efficacy. This will enable more resilient cybersecurity frameworks to survive evolving threats.