Abstract
Advanced Persistent Threats (APTs) represent a significant security threat to cloud environments because they exhibit a stealthy, multi-phase attack pattern, long dwell time and circumvent the traditional signature-based and unimodal intrusion detection systems. To overcome these issues, this paper will introduce (Deep Learning Architecture for Persistent Threat Detection (MM-DLAPT), a multi-modal deep learning framework to detect APTs, which will analyze heterogeneous data sources of the cloud, such as network traffic, system logs, user behavior and resource utilization. The proposed structure will combine the modality-specific deep learning models of the spatial traffic patterns of Convolutional Neural Networks, temporal and behavioral dynamics of Long Short-Term Memory networks and Gated Recurrent Units with an attention-based feature fusion mechanism that will see to it that the relevance of each modality will be dynamically weighted at each stage of the attack. Extensive testing on datasets of cloud security systems with multi-stage APTs indicates that MM-DLAPT is highly superior compared to the latest APT detection systems. MM-DLAPT has a higher detection accuracy (97.8), a high precision (97.1) and a higher recall (98.3) than the conventional models and has a lower amount of false positives and higher detection latency when operating in real-time conditions. These findings affirm that attention-based fusion and multi-modal deep learning is a scalable and effective method of identifying long-duration and stealthy cyber threats in the contemporary cloud infrastructures.