00
Days
00
Hrs
00
Min
00
Sec
Submit Your Paper

AWS Security Architecture and Machine Learning for APT Detection in Cloud Environments

Authors

Adeolu Opeyemi Ojo

University of Greater Manchester, Deane Road, Bolton, BL3 5AB, UK (United Kingdom)

Samuel Babafemi Olabisi

Dept. of Computer Science, Sikiru Adetona College of Education, Science and Technology, Omu-Ajose, Ogun State, Nigeria (Nigeria)

Article Information

DOI: 10.51583/IJLTEMAS.2026.150700111

Subject Category: Architecture

Volume/Issue: 15/7 | Page No: 1447-1461

Publication Timeline

Submitted: 2026-08-02

Accepted: 2026-08-12

Published: 2026-08-20

Abstract

Cloud environments, and Amazon Web Services (AWS) in particular, host high-value data assets and mission-critical workloads that make them attractive targets for Advanced Persistent Threat (APT) actors. Because forensic investigation techniques are applied only after a breach has already been discovered, the volume and velocity of cloud-generated telemetry make proactive, automated detection capabilities essential. This paper reviews machine learning-driven anomaly detection paradigms — supervised, unsupervised, semi-supervised, and deep learning — and examines their suitability for APT detection in AWS environments. It also reviews the AWS shared-responsibility security architecture, including Identity and Access Management (IAM), encryption services, and logging and monitoring services such as AWS Cloud Trail, AWS Config, Amazon Guard Duty, Amazon Detective, and Amazon Inspector, and considers the NIST Cyber security Framework (CSF) as a governance overlay that connects these technical capabilities to organizational risk management. Drawing on this review of the peer-reviewed and primary-source literature, the paper argues that no single detection paradigm is likely sufficient on its own, and that unsupervised and semi-supervised machine learning, combined with AWS-native security services and governed by the NIST CSF, offer a more resilient conceptual basis for cloud APT defense than any single method in isolation. On this basis, the paper proposes an Integrated Cloud APT Detection and Defense Model (ICADDM) as a conceptual architecture for researchers and practitioners, maps AWS security services against the MITRE ATT&CK Cloud Matrix, and identifies the empirical validation of the model against real cloud telemetry as the principal direction for future work.

Keywords

Advanced Persistent Threats, Machine Learning, Anomaly Detection, AWS Security Architecture, NIST Cyber security Framework, MITRE ATT&CK.

Downloads

References

1. Brewer, R. (2014). Advanced persistent threats: Minimising the damage. Network Security, 2014(4), 5–9. https://doi.org/10.1016/S1353-4858(14)70040-6 [Google Scholar] [Crossref]

2. Khaleefa, E. J., & Abdulah, D. A. (2022). Concept and difficulties of advanced persistent threats (APT): Survey. International Journal of Nonlinear Analysis and Applications. http://dx.doi.org/10.22075/ijnaa.2022.6230 [Google Scholar] [Crossref]

3. Sharma, A., Gupta, B. B., Singh, A. K., & Saraswat, V. K. (2023). Advanced persistent threats (APT): Evolution, anatomy, attribution and countermeasures. Journal of Ambient Intelligence and Humanized Computing, 1–27. [Google Scholar] [Crossref]

4. Okoli, U., Obi, O., Adewusi, A., & Abrahams, T. (2024). Machine learning in cybersecurity: A review of threat detection and defense mechanisms. International Journal of Cyber-Security and Digital Forensics, 9, 147–154. https://doi.org/10.17781/P002677 [Google Scholar] [Crossref]

5. Teichmann, F., Boticiu, S. R., & Sergi, B. S. (2023). The evolution of ransomware attacks in light of recent cyber threats. International Cybersecurity Law Review, 4, 259–280. [Google Scholar] [Crossref]

6. National Institute of Standards and Technology. (2011). Managing information security risk: Organization, mission, and information system view (NIST Special Publication 800-39). U.S. Department of Commerce. https://doi.org/10.6028/NIST.SP.800-39 [Google Scholar] [Crossref]

7. Ghafir, I., & Prenosil, V. (2015). Advanced persistent threat and spear phishing emails. In M. Hrubý (Ed.), Proceedings of the International Conference Distance Learning, Simulation and Communication ‘DLSC 2015’ (pp. 34–41). University of Defence. [Google Scholar] [Crossref]

8. Alshaikh, A., Alanesi, M., Yang, D., & Alshaikh, A. (2023). Advanced techniques for cyber threat intelligence-based APT detection and mitigation in cloud environments. In P. Loskot & S. Niu (Eds.), Proceedings of the International Conference on Cyber Security, Artificial Intelligence, and Digital Economy (CSAIDE 2023) (Vol. 12718, Article 127180M). SPIE. https://doi.org/10.1117/12.2681627 [Google Scholar] [Crossref]

9. Khan, S., Kabanov, I., Hua, Y., & Madnick, S. (2022). A systematic analysis of the Capital One data breach: Critical lessons learned. ACM Transactions on Privacy and Security, 26(1), Article 3. https://doi.org/10.1145/3546068 [Google Scholar] [Crossref]

10. Cybersecurity and Infrastructure Security Agency, Federal Bureau of Investigation, Royal Canadian Mounted Police, Australian Cyber Security Centre, Australian Federal Police, Canadian Centre for Cyber Security, & National Cyber Security Centre (UK). (2025). Scattered Spider (Cybersecurity Advisory AA23-320A, updated). Cybersecurity and Infrastructure Security Agency. https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-320a [Google Scholar] [Crossref]

11. MITRE Corporation. (2024). Cloud matrix. MITRE ATT&CK. https://attack.mitre.org/matrices/enterprise/cloud/ [Google Scholar] [Crossref]

12. Mandiant (Google Cloud). (2025). M-Trends 2025 special report. Google Cloud Security. https://services.google.com/fh/files/misc/m-trends-2025-en.pdf [Google Scholar] [Crossref]

13. Li, Z., Ge, Y., Guo, J., Chen, M., & Wang, J. (2022). Security threat model under internet of things using deep learning and edge analysis of cyberspace governance. International Journal of Systems Assurance Engineering and Management, 13, 1164–1176. [Google Scholar] [Crossref]

14. Saabith, A. S., Vinothraj, T., Fareez, M. M. M., & Marzook, M. M. (2023). A survey of machine learning techniques for anomaly detection in cybersecurity. International Journal of Research in Engineering and Science (IJRES), 11(10), 183–193. [Google Scholar] [Crossref]

15. Neuschmied, H., Winter, M., Stojanović, B., Hofer-Schmitz, K., Boegl, U., & Kleb, U. (2022). APT-attack detection based on multi-stage autoencoders. Applied Sciences, 12(13), 6816. https://doi.org/10.3390/app12136816 [Google Scholar] [Crossref]

16. Abhinav, R., Raghav, K. N., Reddy, S. S., Koushik, P. S., Thangavel, S. K., & Srinivasan, K. (2023). A cloud-based intrusion detection system for advanced threat detection and prevention using machine learning techniques. 2023 14th International Conference on Computing Communication and Networking Technologies (ICCCNT), 1–8. [Google Scholar] [Crossref]

17. Myneni, S., Jha, K., Deng, Y., Chowdhary, A., Pisharody, S., & Huang, D. (2023). Unraveled — a semi-synthetic dataset for advanced persistent threats. Computer Networks, 227, 109688. https://doi.org/10.1016/j.comnet.2023.109688 [Google Scholar] [Crossref]

18. Amazon Web Services. (2024). Logging and events. AWS Security Incident Response Guide. https://docs.aws.amazon.com/whitepapers/latest/aws-security-incident-response-guide/logging-and-events.html [Google Scholar] [Crossref]

19. Singh, T. (2021, November). The effect of Amazon Web Services (AWS) on cloud-computing. International Journal of Engineering Research & Technology (IJERT), 10(11). [Google Scholar] [Crossref]

20. Amazon Web Services. (2024). AWS Key Management Service (KMS). https://aws.amazon.com/kms/ [Google Scholar] [Crossref]

21. Amazon Web Services. (2025). AWS CloudTrail user guide. https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-user-guide.html [Google Scholar] [Crossref]

22. Amazon Web Services. (2025). What is Amazon Security Lake? Amazon Security Lake user guide. https://docs.aws.amazon.com/security-lake/latest/userguide/what-is-security-lake.html [Google Scholar] [Crossref]

23. Amazon Web Services. (2022, January 5). Announcing AWS CloudTrail Lake, a managed audit and security lake. AWS What’s New. https://aws.amazon.com/about-aws/whats-new/2022/01/aws-cloudtrail-lake-audit-security [Google Scholar] [Crossref]

24. National Institute of Standards and Technology. (2018). Framework for improving critical infrastructure cybersecurity, Version 1.1 (NIST CSWP 04162018). U.S. Department of Commerce. https://doi.org/10.6028/NIST.CSWP.04162018 [Google Scholar] [Crossref]

25. Hay, B., & Nance, K. (2008). Forensics examination of volatile system data using virtual introspection. ACM SIGOPS Operating Systems Review, 42(3), 74–82. https://doi.org/10.1145/1368506.1368517 [Google Scholar] [Crossref]

Metrics

Views & Downloads

Similar Articles

© 2026 IJLTEMAS · RSIS International. All rights reserved. ISSN 2278-2540.