Automated Threat Hunting, Detection, and Threat Actor Profiling Using TIRA

Semi Yulianto, Gerard Nathaniel Cac Ngo · 2024

Logs play a crucial role in cybersecurity by providing valuable insights. This study introduces TIRA, a system specifically designed for low-computational power environments. TIRA aims to assist in threat hunting, detection, and analysis. It utilizes the OWASP Top 10 and MITRE ATT&CK frameworks to improve log parsing, threat pattern recognition, and actor profiling. TIRA integrates threat profiling based on patterns and combined attack complexity. It enables non-expert users to efficiently identify and address cyber threats using advanced detection rules and integrated framework mapping. During testing, TIRA analyzed a 1.1 GB log file with over 11 million entries in under an hour, compared to 24 hours for manual analysis, representing a 95.83% reduction in threat detection and response time. This resource-efficient solution enhances cybersecurity for organizations with limited resources and promotes a more secure digital ecosystem. TIRA is expected to improve incident handling, organizational preparedness, and industry cooperation by providing actionable threat information. It represents a significant advancement in combating cybercrimes in this rapidly evolving field.

Read the paper · More papers on PaperTik