paper-with-me

홈 › Papers

From Threat Reports to Continuous Threat Intelligence: A Comparison of Attack Technique Extraction Methods from Textual Artifacts

2022-10-05 · Md Rayhanur Rahman, Laurie Williams

The cyberthreat landscape is continuously evolving. Hence, continuous monitoring and sharing of threat intelligence have become a priority for organizations. Threat reports, published by cybersecurity vendors, contain detailed descriptions of attack Tactics, Techniques, and Procedures (TTP) written in an unstructured text format. Extracting TTP from these reports aids cybersecurity practitioners and researchers learn and adapt to evolving attacks and in planning threat mitigation. Researchers have proposed TTP extraction methods in the literature, however, not all of these proposed methods are compared to one another or to a baseline. \textit{The goal of this study is to aid cybersecurity researchers and practitioners choose attack technique extraction methods for monitoring and sharing threat intelligence by comparing the underlying methods from the TTP extraction studies in the literature.} In this work, we identify ten existing TTP extraction studies from the literature and implement five methods from the ten studies. We find two methods, based on Term Frequency-Inverse Document Frequency(TFIDF) and Latent Semantic Indexing (LSI), outperform the other three methods with a F1 score of 84\% and 83\%, respectively. We observe the performance of all methods in F1 score drops in the case of increasing the class labels exponentially. We also implement and evaluate an oversampling strategy to mitigate class imbalance issues. Furthermore, oversampling improves the classification performance of TTP extraction. We provide recommendations from our findings for future cybersecurity researchers, such as the construction of a benchmark dataset from a large corpus; and the selection of textual features of TTP. Our work, along with the dataset and implementation source code, can work as a baseline for cybersecurity researchers to test and compare the performance of future TTP extraction methods.

📄 PDF Abstract BibTeX arXiv:2210.02601

Code (0)

등록된 구현이 없습니다.

Methods 이 논문이 사용한 방법론

Test 설명 없음

Similar Papers 제목 키워드 기반

MALOnt: An Ontology for Malware Threat Intelligence

2020-06-20 · Nidhi Rastogi, Sharmishtha Dutta, Mohammed J. Zaki, Alex Gittens 외

Malware threat intelligence uncovers deep information about malware, threat actors, and their tactics, Indicators of Compromise(IoC), and vulnerabilities in different platforms from scattered threat sources. This collect…

Decision MakingGraph GenerationKnowledge Graphs

TINKER: A framework for Open source Cyberthreat Intelligence

2021-02-10 · Nidhi Rastogi, Sharmishtha Dutta, Mohammed J. Zaki, Alex Gittens 외

Threat intelligence on malware attacks and campaigns is increasingly being shared with other security experts for a cost or for free. Other security analysts use this intelligence to inform them of indicators of compromi…

Information RetrievalIntrusion DetectionKnowledge GraphsNamed Entity Recognition (NER)+1

LOCALINTEL: Generating Organizational Threat Intelligence from Global and Local Cyber Knowledge

2024-01-18 · Shaswata Mitra, Subash Neupane, Trisha Chakraborty, Sudip Mittal 외

Security Operations Center (SoC) analysts gather threat reports from openly accessible global threat repositories and tailor the information to their organization's needs, such as developing threat intelligence and secur…

Retrieval

A System for Automated Open-Source Threat Intelligence Gathering and Management

2021-01-19 · Peng Gao, Xiaoyuan Liu, Edward Choi, Bhavna Soman 외

To remain aware of the fast-evolving cyber threat landscape, open-source Cyber Threat Intelligence (OSCTI) has received growing attention from the community. Commonly, knowledge about threats is presented in a vast numbe…

Management

EXTRACTOR: Extracting Attack Behavior from Threat Reports

2021-04-17 · Kiavash Satvat, Rigel Gjomemo, V. N. Venkatakrishnan

The knowledge on attacks contained in Cyber Threat Intelligence (CTI) reports is very important to effectively identify and quickly respond to cyber threats. However, this knowledge is often embedded in large amounts of …