Technique Inference Engine: A Recommender Model to Support Cyber Threat Hunting

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Turner, Matthew J., Carenzo, Mike, Lasky, Jackie, Morris-King, James, Ross, James
Format: Preprint
Veröffentlicht: 2025
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866915184781557760
author Turner, Matthew J.
Carenzo, Mike
Lasky, Jackie
Morris-King, James
Ross, James
author_facet Turner, Matthew J.
Carenzo, Mike
Lasky, Jackie
Morris-King, James
Ross, James
contents Cyber threat hunting is the practice of proactively searching for latent threats in a network. Engaging in threat hunting can be difficult due to the volume of network traffic, variety of adversary techniques, and constantly evolving vulnerabilities. To aid analysts in identifying techniques which may be co-occurring as part of a campaign, we present the Technique Inference Engine, a tool to infer tactics, techniques, and procedures (TTPs) which may be related to existing observations of adversarial behavior. We compile the largest (to our knowledge) available dataset of cyber threat intelligence (CTI) reports labeled with relevant TTPs. With the knowledge that techniques are chronically under-reported in CTI, we apply several implicit feedback recommender models to the data in order to predict additional techniques which may be part of a given campaign. We evaluate the results in the context of the cyber analyst's use case and apply t-SNE to visualize the model embeddings. We provide our code and a web interface.
format Preprint
id arxiv_https___arxiv_org_abs_2503_04819
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Technique Inference Engine: A Recommender Model to Support Cyber Threat Hunting
Turner, Matthew J.
Carenzo, Mike
Lasky, Jackie
Morris-King, James
Ross, James
Cryptography and Security
Artificial Intelligence
Cyber threat hunting is the practice of proactively searching for latent threats in a network. Engaging in threat hunting can be difficult due to the volume of network traffic, variety of adversary techniques, and constantly evolving vulnerabilities. To aid analysts in identifying techniques which may be co-occurring as part of a campaign, we present the Technique Inference Engine, a tool to infer tactics, techniques, and procedures (TTPs) which may be related to existing observations of adversarial behavior. We compile the largest (to our knowledge) available dataset of cyber threat intelligence (CTI) reports labeled with relevant TTPs. With the knowledge that techniques are chronically under-reported in CTI, we apply several implicit feedback recommender models to the data in order to predict additional techniques which may be part of a given campaign. We evaluate the results in the context of the cyber analyst's use case and apply t-SNE to visualize the model embeddings. We provide our code and a web interface.
title Technique Inference Engine: A Recommender Model to Support Cyber Threat Hunting
topic Cryptography and Security
Artificial Intelligence
url https://arxiv.org/abs/2503.04819