Publicación: Detección temprana de ataques cibernéticos avanzados (APT) mediante modelos ocultos de Markov aplicados al análisis de comportamientos en sistemas de seguridad
| dc.contributor.advisor | Chacón Rivera, Lina María | |
| dc.contributor.author | Cortes Arandia, Andrés Felipe | |
| dc.creator.id | 1011085020 | |
| dc.date.accessioned | 2026-10-08T12:53:10Z | |
| dc.date.issued | 2026-09-19 | |
| dc.description.abstract | Las amenazas persistentes avanzadas, conocidas por su sigla en inglés APT, pertenecen a los problemas de seguridad más difíciles de resolver para las organizaciones colombianas. A diferencia de los ataques convencionales, que buscan un efecto rápido y más fácil de detectar, las APT operan durante semanas o meses dentro de los sistemas comprometidos sin disparar ninguna alerta. Cuando finalmente son descubiertas, el daño acumulado suele ser irreversible. Los métodos de detección vigentes los cuales están basados en bases de firmas maliciosas conocidas o en reglas estáticas predefinidas, procesan cada evento de seguridad de manera independiente y son incapaces de leer el significado que emerge cuando esos eventos se encadenan en el tiempo. El presente proyecto responde a esa limitación con un sistema de detección temprana construido sobre modelos ocultos de Márkov (HMM) de arquitectura jerárquica, entrenado sobre secuencias de eventos reales provenientes de los datasets DARPA Transparent Computing, LANL y cierto grupo de logs extraídos de un ataque simulado usando máquinas virtuales Windows y Linux. El modelo infiere probabilísticamente la fase del ciclo de vida del ataque en que opera el adversario, produce alertas progresivas integradas en Elastic Stack y supera, en precisión, recall, F1-score, a métodos de referencia Random Forest y redes LSTM. Los hallazgos esperados confirman la viabilidad del enfoque para su aplicación en organizaciones que carecen de soluciones comerciales de alto costo (Centro Cibernético Policial, 2024, secc. “Cifras generales”; IBM Security, 2024, p. 8; Rabiner, 1989, p. 258; Ghafir et al., 2019, p. 99510). | spa |
| dc.description.abstract | Advanced Persistent Threats (APTs) are among the most difficult cybersecurity challenges faced by organizations in Colombia. Unlike conventional cyberattacks, which are often designed to cause immediate and noticeable effects, APTs can remain hidden inside compromised systems for weeks or even months without being detected. During this time, attackers are able to carry out malicious activities while avoiding security controls. As a result, when the attack is finally discovered, the damage is often significant and difficult to undo. Most current detection methods rely on known malware signatures or predefined security rules. While these approaches can identify familiar threats, they usually examine security events separately and therefore have difficulty recognizing the patterns that emerge when multiple events are linked over time. This limitation makes it harder to detect sophisticated attacks that unfold gradually and in several stages. To address this problem, this project proposes an early detection system based on hierarchical Hidden Markov Models (HMMs), the model is trained using real-world event data from the DARPA Transparent Computing and Los Alamos National Laboratory (LANL) datasets, as well as logs generated from a controlled simulation of an APT attack carried out in virtualized Windows and Linux environments. By analyzing sequences of events, the system estimates the stage of the attack being carried out and generates progressive alerts through the Elastic Stack platform. Its performance is evaluated using precision, recall, and F1- score and compared with well-known approaches such as Random Forest and Long ShortTerm Memory (LSTM) Networks, the expected results seek to demonstrate that this approach can provide an effective and affordable alternative for organizations that do not have access to high-cost commercial cybersecurity solutions (Centro Cibernético Policial, 2024, secc. “Cifras generales”; IBM Security, 2024, p. 8; Rabiner, 1989, p. 258; Ghafir et al., 2019, p. 99510). | eng |
| dc.description.degreelevel | Trabajo de grado | spa |
| dc.description.degreename | Ingeniero de Sistemas | spa |
| dc.description.tableofcontents | Resumen..................................................................................................................................4 Abstract ...................................................................................................................................5 Introducción ............................................................................................................................6 Marco teórico ........................................................................................................................10 Ataques cibernéticos avanzados y sistemas de detección .....................................................10 Modelos Ocultos de Markov.................................................................................................11 Estado del arte (metodología PRISMA) ...............................................................................12 Metodología ..........................................................................................................................17 Resultados .............................................................................................................................20 Análisis de resultados............................................................................................................23 Discusión...............................................................................................................................25 Plan de divulgación ...............................................................................................................27 Análisis de viabilidad............................................................................................................28 Fuentes de inversión y participación de semilleros...............................................................29 Conclusiones .........................................................................................................................30 Referencias............................................................................................................................32 | spa |
| dc.description.tableofcontents | Summary ..................................................................................................................................4 Abstract ...................................................................................................................................5 Introduction .............................................................................................................................6 Theoretical Framework .........................................................................................................10 Advanced Cyberattacks and Detection Systems .....................................................................10 Hidden Markov Models .........................................................................................................11 State of the Art (PRISMA Methodology) ..............................................................................12 Methodology ..........................................................................................................................17 Results ...................................................................................................................................20 Analysis of Results ................................................................................................................23 Discussion ..............................................................................................................................25 Dissemination Plan ................................................................................................................27 Feasibility Analysis ...............................................................................................................28 Sources of Investment and Research Seedbed Participation .................................................29 Conclusions ...........................................................................................................................30 References .............................................................................................................................32 | eng |
| dc.format | ||
| dc.format.extent | 36 páginas | |
| dc.format.medium | Recurso electrónico | spa |
| dc.format.mimetype | application/pdf | |
| dc.identifier.instname | instname:Universidad Ean | spa |
| dc.identifier.local | BDM-FIS | |
| dc.identifier.reponame | reponame:Repositorio Institucional Biblioteca Digital Minerva | spa |
| dc.identifier.repourl | https://repository.ean.edu.co/ | |
| dc.identifier.uri | https://hdl.handle.net/10882/19646 | |
| dc.language.iso | spa | |
| dc.publisher.faculty | Facultad de Ingeniería | spa |
| dc.publisher.program | Ingeniería de Sistemas | spa |
| dc.relation.references | Banco Mundial. (2024). Economía de la ciberseguridad para los mercados emergentes. Grupo Banco Mundial. https://blogs.worldbank.org/es/latinamerica/seguridadcibernetica-en-america-latina-y-el-caribe Cano Martínez, J. J. (2022). Ciberseguridad empresarial: Reflexiones y retos para las organizaciones en entornos digitales. Ediciones de la U. Centro Cibernético Policial. (2024). Informe de ciberseguridad 2024: Incidentes reportados en Colombia. Policía Nacional de Colombia. https://www.policia.gov.co/centro-cibernetico Check Point Research. (2025, marzo 10). The growing danger of Blind Eagle: One of Latin America's most dangerous cyber criminal groups targets Colombia. Check Point Blog. https://blog.checkpoint.com/research/the-growing-danger-of-blind-eagle *Chadza, T., Kyriakopoulos, K. G., & Lambotharan, S. (2020). Analysis of hidden Markov model learning algorithms for the detection and prediction of multi-stage network attacks. Future Generation Computer Systems, 108, 636–649. https://doi.org/10.1016/j.future.2020.02.032 Confederación Colombiana de Cámaras de Comercio. (2022). Dinámica empresarial en Colombia: Informe anual de estructura empresarial. Confecámaras. https://www.confecamaras.org.co Darktrace. (2025). Patch and persist: Darktrace's detection of Blind Eagle (APT-C-36). Darktrace Blog. https://www.darktrace.com/es/blog/patch-and-persist-darktracesdetection-of-blind-eagle-apt-c-36 *Du, H., Zhang, Q., & Liu, X. (2023). Hierarchical hidden Markov model for APT lateral movement detection. IEEE Transactions on Information Forensics and Security, 18(3), 1045–1058. https://doi.org/10.1109/TIFS.2023.3241892 Fortinet. (2024). ¿Qué es la protección de amenazas avanzadas (ATP)? Fortinet Resource Center. https://www.fortinet.com/lat/resources/cyberglossary/advanced-threatprotection-atp Galicia, D. (2024). Seguridad y ciberseguridad en la era de la IA: Explorar los desafíos y soluciones relacionados con la seguridad digital en un mundo donde la IA desempeña un papel determinante. Independently published. *Ghafir, I., Hammoudeh, M., Prenosil, V., Han, L., Hegarty, R., Rabie, K., & AparicioNavarro, F. J. (2019). Hidden Markov models and alert correlations for the prediction of advanced persistent threats. IEEE Access, 7, 99508–99520. https://doi.org/10.1109/ACCESS.2019.2930200 IBM Security. (2024). Cost of a data breach report 2024. IBM Corporation. https://www.ibm.com/reports/data-breach Infoblox. (2023). Global cybersecurity study 2023: State of the threat landscape. Infoblox Inc. https://www.infoblox.com/resources/report/global-cybersecurity-study-2023/ Kaspersky. (2024). ¿Qué es una amenaza persistente avanzada (APT)? Kaspersky Resource Center. https://latam.kaspersky.com/resource-center/definitions/advancedpersistent-threats Lay, D. C., Lay, S. R., & McDonald, J. J. (2016). Álgebra lineal y sus aplicaciones (5.ª ed.). Pearson Educación. *Milajerdi, S. M., Gjomemo, R., Eshete, B., Sekar, R., & Venkatakrishnan, V. N. (2019). HOLMES: Real-time APT detection through correlation of suspicious information flows. Proceedings of the IEEE Symposium on Security and Privacy, 1137–1152. https://doi.org/10.1109/SP.2019.00026 Ministerio de Tecnologías de la Información y las Comunicaciones. (2024). Estrategia Nacional de Seguridad Digital 2025–2027. Gobierno de Colombia. https://www.mintic.gov.co MITRE Corporation. (2024). MITRE ATT&CK: Enterprise matrix (v15). MITRE. https://attack.mitre.org Norris, J. R. (1997). Markov chains. Cambridge University Press. https://doi.org/10.1017/CBO9780511810633 Ortega Candel, J. M. (2021). Hacking ético con herramientas Python. Ediciones de la U. Ortega Candel, J. M. (2022). Big Data, Machine Learning y Data Science en Python. Ediciones de la U. *Ou, Y. H., Tsai, Y. L., & Wu, Z. Y. (2025). Detecting trajectory of targeted attack by Hidden Markov Model. Wireless Networks. https://doi.org/10.1007/s11276-025-04047-6 Positive Technologies. (2024). Cybersecurity threatscape for Latin America and the Caribbean 2023–2024. PT Security. https://global.ptsecurity.com/es/research/analytics/cybersecurity-threatscape-forlatin-america-and-the-caribbean-2023-2024/ *Rabiner, L. R. (1989). A tutorial on hidden Markov models and selected applications in speech recognition. Proceedings of the IEEE, 77(2), 257–286. https://doi.org/10.1109/5.18626 Russell, S. J., & Norvig, P. (2020). Inteligencia artificial: Un enfoque moderno (4.ª ed.). Pearson Educación. *Sakthivelu, U., & Vinoth Kumar, C. N. S. (2024). A multi-step APT attack detection using hidden Markov models by molecular magnetic sensors. Optical and Quantum Electronics, 56(3), 282. https://doi.org/10.1007/s11082-023-05905-3 Scarfone, K., & Mell, P. (2007). Guide to intrusion detection and prevention systems (IDPS) (NIST Special Publication 800-94). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-94 *Shen, Y., Mariconti, E., Vervier, P. A., & Stringhini, G. (2022). Tiresias: Predicting security events through deep learning. Proceedings of the ACM Conference on Computer and Communications Security, 592–605. https://doi.org/10.1145/3243734.3243811 Téllez Piñerez, C. F., & Morales Rivera, M. A. (2022). Modelos estadísticos lineales. Ediciones de la U. | |
| dc.rights.accessrights | info:eu-repo/semantics/openAccess | |
| dc.rights.coar | http://purl.org/coar/access_right/c_abf2 | |
| dc.rights.creativecommons | Atribución-NoComercial-CompartirIgual 4.0 Internacional (CC BY-NC-SA 4.0) | |
| dc.rights.license | Atribución-NoComercial-CompartirIgual 4.0 Internacional (CC BY-NC-SA 4.0) | |
| dc.rights.local | Abierto (Texto Completo) | spa |
| dc.rights.uri | https://creativecommons.org/licenses/by-nc-sa/4.0/ | |
| dc.subject.armarc | Seguridad informática | spa |
| dc.subject.armarc | Protección de datos | spa |
| dc.subject.armarc | Detección de anomalías (Seguridad informática) | spa |
| dc.subject.armarc | Sistemas de detección de intrusos (Seguridad informática) | spa |
| dc.subject.armarc | Redes de computadores -- Medidas de seguridad | spa |
| dc.subject.proposal | Amenazas persistentes avanzadas (APT) | spa |
| dc.subject.proposal | Modelos Ocultos de Markov (HMM) | spa |
| dc.subject.proposal | Detección temprana de intrusiones | spa |
| dc.subject.proposal | Análisis secuencial de eventos | spa |
| dc.subject.proposal | Ciberseguridad | spa |
| dc.subject.proposal | Registros de seguridad | spa |
| dc.subject.proposal | Advanced Persistent Threats (APT) | eng |
| dc.subject.proposal | Hidden Markov Models (HMM) | eng |
| dc.subject.proposal | Early intrusion detection | eng |
| dc.subject.proposal | Sequential event analysis | eng |
| dc.subject.proposal | Cybersecurity | eng |
| dc.subject.proposal | Security logs | eng |
| dc.title | Detección temprana de ataques cibernéticos avanzados (APT) mediante modelos ocultos de Markov aplicados al análisis de comportamientos en sistemas de seguridad | spa |
| dc.title | Early detection of advanced persistent threats (APT) using hidden markov models applied to behavioral analysis in security systems | eng |
| dc.type | Trabajo de grado - Pregrado | spa |
| dc.type.coar | http://purl.org/coar/resource_type/c_7a1f | |
| dc.type.coarversion | http://purl.org/coar/version/c_ab4af688f83e57aa | |
| dc.type.content | Text | |
| dc.type.driver | info:eu-repo/semantics/bachelorThesis | |
| dc.type.other | Trabajo de grado - Pregrado | |
| dc.type.redcol | http://purl.org/redcol/resource_type/TP | |
| dc.type.version | info:eu-repo/semantics/acceptedVersion | |
| dspace.entity.type | Publication | |
| person.affiliation.name | Ingeniería de Sistemas |
Archivos
Bloque original
Bloque de licencias
1 - 1 de 1
Cargando...
- Nombre:
- license.txt
- Tamaño:
- 1.92 KB
- Formato:
- Item-specific license agreed upon to submission
- Descripción:
