Repository logo

Threat Actor Attribution Applying a Tactics–Techniques–Procedures Approach: An Empirical Investigation

aut.relation.articlenumber433
aut.relation.endpage433
aut.relation.issue8
aut.relation.journalFuture Internet
aut.relation.startpage433
aut.relation.volume18
dc.contributor.authorHussain, Shaheen
dc.contributor.authorPetrova, Krassie
dc.date.accessioned2026-08-17T03:31:24Z
dc.date.issued2026-08-13
dc.description.abstractThe increasing frequency and growing impact of cyberattacks have led organizations to adopt proactive defense approaches to cybersecurity risk mitigation, especially in the case of advanced persistent threats (APTs). The correct identification of the specific malicious actors behind a cyberattack is important for the success of incident response and for the investigative work of the security operations center (SOC) team. This research explores the capabilities and limitations of a machine learning (ML) approach to identifying malicious actors and the threats they pose (threat actor attribution) based on the tactics, techniques, and procedures (TTP) observed in specific cybersecurity incidents and on the incident context (the geographical location and industry affiliation of the victims targeted in the attack). A large language model (LLM) was used to extract TTPs from the MITRE ATT&CK database of cybersecurity incidents. The experiments included modeling threat actor attribution using five ML algorithms: k-nearest neighbors (KNN), decision tree (DT), random forest (RF), support vector machine (SVM), and naïve Bayes (NB), with different methods applied for feature selection and weighting. The results indicated that model accuracy and other performance metrics were significantly improved when the input dataset included both TTP and contextual features. The KNN and SVM models produced the best performance results; the highest classification accuracy achieved was 93.19%. The outcomes of this study may be applied by cybersecurity professionals to identify malicious actors, estimate the number and types of data points that are required to adequately attribute a cyberattack to an actor, and improve the accuracy of the classification by weighting the input dataset features.
dc.identifier.citationFuture Internet, ISSN: 1999-5903 (Print); 1999-5903 (Online), MDPI, 18(8), 433-433. doi: 10.3390/fi18080433
dc.identifier.doi10.3390/fi18080433
dc.identifier.issn1999-5903
dc.identifier.issn1999-5903
dc.identifier.urihttp://hdl.handle.net/10292/21779
dc.languageEnglish
dc.publisherMDPI
dc.relation.urihttps://www.mdpi.com/1999-5903/18/8/433
dc.rightsCreative Commons Attribution (CC BY)
dc.rights.accessrightsOpenAccess
dc.rights.urihttps://creativecommons.org/licenses/by/4.0/
dc.subject4604 Cybersecurity and privacy
dc.subject46 Information and computing sciences
dc.subjectthreat actor attribution
dc.subjectadvanced persistent threats
dc.subjecttactics
dc.subjecttechniques and procedures
dc.subjectAPT
dc.subjectTTP
dc.subjectmachine learning
dc.subjectML
dc.subjectKNN
dc.subjectSVM
dc.subjectRF
dc.subjectDT
dc.subjectcybersecurity
dc.subjectcyberattack
dc.subjectcybersecurity incident
dc.titleThreat Actor Attribution Applying a Tactics–Techniques–Procedures Approach: An Empirical Investigation
dc.typeJournal Article
pubs.elements-id771455

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
Hussain_Petrova_2026_Threat actor attribution applying a tactics.pdf
Size:
684.42 KB
Format:
Adobe Portable Document Format
Description:
Journal article

License bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
license.txt
Size:
1.37 KB
Format:
Plain Text
Description: