TTPMapper: Accurate Mapping of TTPs from Unstructured CTI Reports
Asad Ali, Min-Chun Peng · 2024
Cyber Threat Intelligence (CTI) is crucial for understanding and mitigating threats from Advanced Persistent Threat (APT) groups. APTs utilize various Tactics, Techniques, and Procedures (TTPs), as cataloged by MITRE ATT&CK, to execute their attacks. Identifying the specific techniques used by the APTs is vital for improving threat detection, enhancing situational awareness, streamlining incident response, and implementing proactive defense measures. The primary source for identification of these techniques is threat reports, as they contain detailed information about APT activities. However, extracting and mapping these TTPs from threat reports is challenging due to the unstructured nature of these reports, and variability in sentence structure and vocabulary. This paper presents TTPMapper, a novel approach to extract and map TTPs from threat reports accurately. Given the limitations in TTP descriptions and the need for extensive training data, TTPMapper incorporates data augmentation from sources like AlienVault, SNORT, and MITRE ATT&CK. TTPMapper comprises two machine learning models utilizing CyBERT: one trained on keyword-specific sentences and another on simplified and elaborated sentences. TTPMapper leverages multiple trained models to determine the most likely Technique for any given input. Additionally, we integrate GPT-4o to handle unseen sentences with low classification probabilities. This multi-model approach, combined with a heuristic confidence scoring system, enhances the accuracy of TTP mapping from unstructured text. We demonstrate TTPMapper's superior performance (94.08% accuracy) compared to existing models like TTPHunter in terms of accuracy, precision, recall, and F1-score.