Reproducing ATT&CK Techniques and Lifecycles to Train Machine Learning Classifier

Fietyata Yudha, Ying–Dar Lin, Yuan‐Cheng Lai, Didik Sudyana, Ren‐Hung Hwang · IEEE Network · 2025

The MITRE adversarial tactics, techniques, and common knowledge (ATT&CK) framework categorizes threat actor behaviors into a sequence of techniques called the attack lifecycle. Based on this, Our work introduces a dual-labeled dataset that is accurately labeled with distinct techniques and lifecycles defined by ATT&CK. The dataset offered a more thorough perspective than previous datasets that employed binary or attack classification. It encompassed 17 distinct techniques throughout five lifecycles and was generated through an automated method that guarantees reproducibility and learnability. Reproducibility guarantees the dataset’s consistency, whereas learnability signifies its use in training machine learning models. Our analysis produced a positive result. The dataset achieved a Pearson correlation coefficient of 0.7 for reproducibility. Regarding distinguishing classes, it exhibits an average AUC-ROC score of 0.92 for techniques and 0.82 for lifecycles. The model training yielded an average F1 score of 0.95 for technique classification and 0.9 for lifecycle classification, but only for the traffic dataset.

Read the paper · More papers on PaperTik