Repository logo

Threat Actor Attribution Applying a Tactics–Techniques–Procedures Approach: An Empirical Investigation

Loading...
Thumbnail Image

Files

Size: 684.42 KB, File format: Adobe PDF

Authors

Hussain, Shaheen

Petrova, Krassie

Supervisor

Degree name

Journal Title

Journal ISSN

Volume Title

Publisher

MDPI

Abstract

The increasing frequency and growing impact of cyberattacks have led organizations to adopt proactive defense approaches to cybersecurity risk mitigation, especially in the case of advanced persistent threats (APTs). The correct identification of the specific malicious actors behind a cyberattack is important for the success of incident response and for the investigative work of the security operations center (SOC) team. This research explores the capabilities and limitations of a machine learning (ML) approach to identifying malicious actors and the threats they pose (threat actor attribution) based on the tactics, techniques, and procedures (TTP) observed in specific cybersecurity incidents and on the incident context (the geographical location and industry affiliation of the victims targeted in the attack). A large language model (LLM) was used to extract TTPs from the MITRE ATT&CK database of cybersecurity incidents. The experiments included modeling threat actor attribution using five ML algorithms: k-nearest neighbors (KNN), decision tree (DT), random forest (RF), support vector machine (SVM), and naïve Bayes (NB), with different methods applied for feature selection and weighting. The results indicated that model accuracy and other performance metrics were significantly improved when the input dataset included both TTP and contextual features. The KNN and SVM models produced the best performance results; the highest classification accuracy achieved was 93.19%. The outcomes of this study may be applied by cybersecurity professionals to identify malicious actors, estimate the number and types of data points that are required to adequately attribute a cyberattack to an actor, and improve the accuracy of the classification by weighting the input dataset features.

Description

Keywords

4604 Cybersecurity and privacy, 46 Information and computing sciences, threat actor attribution, advanced persistent threats, tactics, techniques and procedures, APT, TTP, machine learning, ML, KNN, SVM, RF, DT, cybersecurity, cyberattack, cybersecurity incident

Source

Future Internet, ISSN: 1999-5903 (Print); 1999-5903 (Online), MDPI, 18(8), 433-433. doi: 10.3390/fi18080433

Rights statement

Creative Commons Attribution (CC BY)

Endorsement

Review

Supplemented By

Referenced By

Creative Commons license

Except where otherwise noted, this item's license is described as Creative Commons Attribution (CC BY)