Decoding shadows: Towards Tactics, Techniques, and Procedures (TTP)-based Advanced Persistent Threat (APT) attribution

Nanda Rani, Bikash Saha, Vikas Maurya, Sandeep K. Shukla · Information Security Journal A Global Perspective · 2025

Attributing Advanced Persistent Threats (APTs) is a critical challenge, often hindered by the unreliability of low-level indicators such as malware signatures or IP addresses, which are easily forged or evaded. In contrast, Tactics, Techniques, and Procedures (TTPs) reflect higher-order behavioral patterns that are harder to disguise, making them a more robust basis for attribution. This paper presents ATTRACT (ATTRibuting Advanced Cyber Threats), a novel attribution framework that leverages structured TTP sequences extracted from real-world threat reports. ATTRACT encodes these sequences according to kill-chain phases and employs a custom similarity measure that captures both the order and repetition of attacker behaviors. By comparing the observed sequence of TTPs from a new attack to known threat group profiles, ATTRACT provides interpretable and data-efficient attribution without requiring extensive training. Experimental results demonstrate that ATTRACT achieves 61.36% Top-1 and 69.98% Top-2 precision, outperforming traditional similarity and learning-based approaches. Through a detailed case study and comprehensive evaluation, we show that ATTRACT offers a scalable, transparent, and behavior-driven approach to APT attribution. By offering transparent and data-efficient attribution, ATTRACT bridges the gap between intelligence extraction and decision-making, providing analysts with a scalable, behavior-driven alternative to opaque or data intensive models.

Read the paper · More papers on PaperTik