دورية أكاديمية

Context-aware cyber-threat attribution based on hybrid features

التفاصيل البيبلوغرافية
العنوان: Context-aware cyber-threat attribution based on hybrid features
المؤلفون: Ehtsham Irshad, Abdul Basit Siddiqui
المصدر: ICT Express, Vol 10, Iss 3, Pp 553-569 (2024)
بيانات النشر: Elsevier, 2024.
سنة النشر: 2024
المجموعة: LCC:Information technology
مصطلحات موضوعية: Cyber threat intelligence (CTI), Incident of compromise (IOC), Cyber-threat actor (CTA), Tactics techniques and procedures (TTP), Structured threat information expression (STIX), Security operation center (SOC), Information technology, T58.5-58.64
الوصف: With the rapid technological development, identifying the attackers behind cyber-attacks is getting more sophisticated. To cope with this phenomenon, the current process of cyber-threat attribution includes features like tactics techniques and procedures (TTP), tools, target country/ company and application. They do not include attacker context and motives; thus, they demand more refined traits. Adding behavioral features to this process is essential to better understand the attacker’s context, motivations and goals. This research study accentuates the impact of adding behavioral features with existing technical features in determining the actual actor. The behavioral features are extracted from Threat actor encyclopedia, a dataset published by Thai CERT. This research investigation also analyzes the impact of hybrid features (technical & and behavioral). For this procedure, the best features are chosen by implementing feature selection techniques. For empirical results, we use the threat actor encyclopedia, a data set published by Thai Cert, for extraction of behavioral attributes. With this augmentation, we achieve elevated results of 97%, 98.8%, 97%, and 97.2% in terms of accuracy, precision, recall and F1-measure using machine/deep learning algorithms.
نوع الوثيقة: article
وصف الملف: electronic resource
اللغة: English
تدمد: 2405-9595
Relation: http://www.sciencedirect.com/science/article/pii/S2405959524000420; https://doaj.org/toc/2405-9595
DOI: 10.1016/j.icte.2024.04.005
URL الوصول: https://doaj.org/article/920c53708bc144e6a315bf82ca7398de
رقم الأكسشن: edsdoj.920c53708bc144e6a315bf82ca7398de
قاعدة البيانات: Directory of Open Access Journals
الوصف
تدمد:24059595
DOI:10.1016/j.icte.2024.04.005