Enhancing Cyber Attribution through Behavior Similarity Detection on Linux Shell Honeypots with ATT&CK Framework
Kevin Hobert, Charles Ci-Wen Lim, Eka Budiarto · 2023
Cyber attribution poses significant challenges for researchers and investigators, particularly due to the constantly changing tools and infrastructure used by attackers, making it difficult to establish correlations and relationships between attacks. Analyzing large volumes of data to filter out malicious commands presents a daunting task. To address this, honeypots are employed as deception solutions to capture attackers without causing harm to real systems. By studying attacker behaviors and identifying correlations between their Tactics, Techniques, and Procedures (TTPs) using the MITRE ATT&CK framework, valuable insights can be gained to complement cyber attribution by establishing connections between different attack events. The detection of similarities in cyber attacks can serve as evidence of a certain perpetrator group conducting multiple attacks. In this paper, we propose a novel method that utilizes a vector representation to identify similarities in Linux commands used by attackers in their TTPs. We analyzed 793 pre-processed unique command sets, leading to the discovery of eight attacker groups with distinct TTPs.