Technique Inference Engine: A Recommender Model to Support Cyber Threat Hunting

📅 2025-03-04
📈 Citations: 0
Influential: 0
📄 PDF

career value

182K/year
🤖 AI Summary
In threat hunting, analysts struggle to identify co-occurring Tactics, Techniques, and Procedures (TTPs) from massive network traffic and fragmented cyber threat intelligence (CTI). To address this, we propose the first implicit-feedback recommendation framework for TTP association inference. Our method constructs the largest ATT&CK-aligned CTI report annotation dataset to date; introduces Bayesian Personalized Ranking (BPR) and LightGCN—state-of-the-art implicit-feedback models—into TTP co-occurrence modeling to mitigate intelligence omission; and integrates t-SNE visualization with interpretable embedding spaces to enable tactic-level association analysis. Experiments demonstrate significant improvements in TTP association prediction accuracy. All code, data, and an interactive web interface are publicly released to support operational threat hunting.

Technology Category

Application Category

📝 Abstract
Cyber threat hunting is the practice of proactively searching for latent threats in a network. Engaging in threat hunting can be difficult due to the volume of network traffic, variety of adversary techniques, and constantly evolving vulnerabilities. To aid analysts in identifying techniques which may be co-occurring as part of a campaign, we present the Technique Inference Engine, a tool to infer tactics, techniques, and procedures (TTPs) which may be related to existing observations of adversarial behavior. We compile the largest (to our knowledge) available dataset of cyber threat intelligence (CTI) reports labeled with relevant TTPs. With the knowledge that techniques are chronically under-reported in CTI, we apply several implicit feedback recommender models to the data in order to predict additional techniques which may be part of a given campaign. We evaluate the results in the context of the cyber analyst's use case and apply t-SNE to visualize the model embeddings. We provide our code and a web interface.
Problem

Research questions and friction points this paper is trying to address.

Proactively identifies latent cyber threats in networks
Predicts related adversarial tactics, techniques, and procedures
Uses implicit feedback models to enhance threat detection
Innovation

Methods, ideas, or system contributions that make the work stand out.

Technique Inference Engine predicts related TTPs
Uses implicit feedback recommender models
Visualizes model embeddings with t-SNE
🔎 Similar Papers
No similar papers found.
M
Matthew J. Turner
MITRE Center for Threat-Informed Defense
M
Mike Carenzo
MITRE Center for Threat-Informed Defense
J
Jackie Lasky
MITRE Center for Threat-Informed Defense
J
James Morris-King
MITRE Center for Threat-Informed Defense
J
James Ross
MITRE Center for Threat-Informed Defense