Enhancing Incident Response Through Effective TTPs Analysis: A Design Approach

Citations

WEB OF SCIENCE

0
Citations

SCOPUS

1

초록

To effectively defend against intelligent cyberattacks, it is essential to understand the attacker's intent and enable proactive responses. However, identifying patterns in attack incidents and quantifying them remains highly challenging. Without this capability, predicting the attacker's next action becomes difficult, thereby hindering proactive defense. The key challenge lies in discovering unique correlations among attack behaviors. In this study, we employ an embedding model to uncover and quantify relationships between attack activities. By managing these relationships through clustering, we were able to predict subsequent attacker behaviors. Furthermore, we propose an advanced attack-group identification framework by detecting attack patterns and integrating them with existing methodologies. The proposed approach achieved 91.73% accuracy in predicting the attacker's next action and demonstrated 93.49% accuracy in identifying attack groups. Additionally, we present two use cases to illustrate the practical applicability of our methodology. Through this research, we aim to pave the way for next-generation intrusion response technologies.

키워드

SecurityCorrelationSemanticsDatabasesAccuracyTrainingThreat modelingTaggingStatistical analysisPrevention and mitigationAttack group identificationattack predictionincident responseMITRE ATT&CKTTPs(tactics techniques and procedures) analysisCYBERCHALLENGESATTACKSFUTURE
제목
Enhancing Incident Response Through Effective TTPs Analysis: A Design Approach
저자
Han, Tae-HyunHwang, Sang-YeonLee, Tae-Jin
DOI
10.1109/ACCESS.2025.3645226
발행일
2025-12
유형
Article
저널명
IEEE Access
13
페이지
217799 ~ 217810