{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2023:XNDJTI7ANHWDRN5ISJLU6PVLQO","short_pith_number":"pith:XNDJTI7A","schema_version":"1.0","canonical_sha256":"bb4699a3e069ec38b7a892574f3eab839efcc4c93dbf1fa136df2376fe48f8a2","source":{"kind":"arxiv","id":"2307.10252","version":1},"attestation_state":"computed","paper":{"title":"A Machine Learning based Empirical Evaluation of Cyber Threat Actors High Level Attack Patterns over Low level Attack Patterns in Attributing Attacks","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CR","authors_text":"Rimsha Kanwal, Sawera Shahid, Umara Noor, Zahid Rashid","submitted_at":"2023-07-17T08:58:39Z","abstract_excerpt":"Cyber threat attribution is the process of identifying the actor of an attack incident in cyberspace. An accurate and timely threat attribution plays an important role in deterring future attacks by applying appropriate and timely defense mechanisms. Manual analysis of attack patterns gathered by honeypot deployments, intrusion detection systems, firewalls, and via trace-back procedures is still the preferred method of security analysts for cyber threat attribution. Such attack patterns are low-level Indicators of Compromise (IOC). They represent Tactics, Techniques, Procedures (TTP), and soft"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2307.10252","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2023-07-17T08:58:39Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"e37d94079d2e13102e64db0331e270af3ef18f03a768d4bcefacdad99e079332","abstract_canon_sha256":"62733031b95832f312964be5b2717647c41d7a2093c4bd62ed0bf4729faa4ffa"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T06:32:55.909196Z","signature_b64":"lzeO0ukQCssOsnrHqLP8AAF9b4vq+wo2FGXWHze2eeMjhIrU7v+KPoMjn/5RHrMyRRFq+fk0fpAkqKI1YL6fBQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"bb4699a3e069ec38b7a892574f3eab839efcc4c93dbf1fa136df2376fe48f8a2","last_reissued_at":"2026-07-05T06:32:55.908704Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T06:32:55.908704Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"A Machine Learning based Empirical Evaluation of Cyber Threat Actors High Level Attack Patterns over Low level Attack Patterns in Attributing Attacks","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CR","authors_text":"Rimsha Kanwal, Sawera Shahid, Umara Noor, Zahid Rashid","submitted_at":"2023-07-17T08:58:39Z","abstract_excerpt":"Cyber threat attribution is the process of identifying the actor of an attack incident in cyberspace. An accurate and timely threat attribution plays an important role in deterring future attacks by applying appropriate and timely defense mechanisms. Manual analysis of attack patterns gathered by honeypot deployments, intrusion detection systems, firewalls, and via trace-back procedures is still the preferred method of security analysts for cyber threat attribution. Such attack patterns are low-level Indicators of Compromise (IOC). They represent Tactics, Techniques, Procedures (TTP), and soft"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2307.10252","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2307.10252/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2307.10252","created_at":"2026-07-05T06:32:55.908767+00:00"},{"alias_kind":"arxiv_version","alias_value":"2307.10252v1","created_at":"2026-07-05T06:32:55.908767+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2307.10252","created_at":"2026-07-05T06:32:55.908767+00:00"},{"alias_kind":"pith_short_12","alias_value":"XNDJTI7ANHWD","created_at":"2026-07-05T06:32:55.908767+00:00"},{"alias_kind":"pith_short_16","alias_value":"XNDJTI7ANHWDRN5I","created_at":"2026-07-05T06:32:55.908767+00:00"},{"alias_kind":"pith_short_8","alias_value":"XNDJTI7A","created_at":"2026-07-05T06:32:55.908767+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":1,"sample":[{"citing_arxiv_id":"2505.11547","citing_title":"On Technique Identification and Threat-Actor Attribution using LLMs and Embedding Models","ref_index":18,"is_internal_anchor":true}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/XNDJTI7ANHWDRN5ISJLU6PVLQO","json":"https://pith.science/pith/XNDJTI7ANHWDRN5ISJLU6PVLQO.json","graph_json":"https://pith.science/api/pith-number/XNDJTI7ANHWDRN5ISJLU6PVLQO/graph.json","events_json":"https://pith.science/api/pith-number/XNDJTI7ANHWDRN5ISJLU6PVLQO/events.json","paper":"https://pith.science/paper/XNDJTI7A"},"agent_actions":{"view_html":"https://pith.science/pith/XNDJTI7ANHWDRN5ISJLU6PVLQO","download_json":"https://pith.science/pith/XNDJTI7ANHWDRN5ISJLU6PVLQO.json","view_paper":"https://pith.science/paper/XNDJTI7A","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2307.10252&json=true","fetch_graph":"https://pith.science/api/pith-number/XNDJTI7ANHWDRN5ISJLU6PVLQO/graph.json","fetch_events":"https://pith.science/api/pith-number/XNDJTI7ANHWDRN5ISJLU6PVLQO/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/XNDJTI7ANHWDRN5ISJLU6PVLQO/action/timestamp_anchor","attest_storage":"https://pith.science/pith/XNDJTI7ANHWDRN5ISJLU6PVLQO/action/storage_attestation","attest_author":"https://pith.science/pith/XNDJTI7ANHWDRN5ISJLU6PVLQO/action/author_attestation","sign_citation":"https://pith.science/pith/XNDJTI7ANHWDRN5ISJLU6PVLQO/action/citation_signature","submit_replication":"https://pith.science/pith/XNDJTI7ANHWDRN5ISJLU6PVLQO/action/replication_record"}},"created_at":"2026-07-05T06:32:55.908767+00:00","updated_at":"2026-07-05T06:32:55.908767+00:00"}