REVIEW 2 cited by
Towards Automated Classification of Attackers' TTPs by combining NLP with ML Techniques
Not yet reviewed by Pith; the record is open.
This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.
SPECIMEN: schema-true, not a live event
T0 review · schema-true
One-sentence machine reading of the paper's core claim.
pith:XXXXXXXX · record.json · timestamp
Signed reviews
read the original abstract
The increasingly sophisticated and growing number of threat actors along with the sheer speed at which cyber attacks unfold, make timely identification of attacks imperative to an organisations' security. Consequently, persons responsible for security employ a large variety of information sources concerning emerging attacks, attackers' course of actions or indicators of compromise. However, a vast amount of the needed security information is available in unstructured textual form, which complicates the automated and timely extraction of attackers' Tactics, Techniques and Procedures (TTPs). In order to address this problem we systematically evaluate and compare different Natural Language Processing (NLP) and machine learning techniques used for security information extraction in research. Based on our investigations we propose a data processing pipeline that automatically classifies unstructured text according to attackers' tactics and techniques derived from a knowledge base of adversary tactics, techniques and procedures.
Forward citations
Cited by 2 Pith papers
-
Operationalizing Cyber Threat Intelligence with GraphRAG
In an AI-judged comparison on nine cyber threat reports, GraphRAG produced detection plans that appeared more resilient to rotating attacker indicators than standard vector search, but the judge's scores broke the pap...
-
Cyber-Attack Technique Classification Using Two-Stage Trained Large Language Models
A two-stage fine-tuning approach that augments rare attack-technique classes with similar MITRE descriptions improves Macro-F1 by 5 to 9 points on the TRAM benchmark.
Discussion (0). Continue with ORCID to comment.