• Home
  • Search
  • Threat Intelligence Extraction Framework (TIEF) for TTP Extraction
  • Cite Icon1
  • https://doi.org/10.3390/jcp5030063Copy DOI Icon

Threat Intelligence Extraction Framework (TIEF) for TTP Extraction

Show More
  • Abstract
  • Literature Map
  • References
  • Citations
  • Similar Papers
Abstract

The increasing complexity and scale of cyber threats demand advanced, automated methodologies for extracting actionable cyber threat intelligence (CTI). The automated extraction of Tactics, Techniques, and Procedures (TTPs) from unstructured threat reports remains a challenging task, constrained by the scarcity of labeled data, severe class imbalance, semantic variability, and the complexity of multi-class, multi-label learning for fine-grained classification. To address these challenges, this work proposes the Threat Intelligence Extraction Framework (TIEF) designed to autonomously extract Indicators of Compromise (IOCs) from heterogeneous textual threat reports and represent them by the STIX 2.1 standard for standardized sharing. TIEF employs the DistilBERT Base-Uncased model as its backbone, achieving an F1 score of 0.933 for multi-label TTP classification, while operating with 40% fewer parameters than traditional BERT-base models and preserving 97% of their predictive performance. Distinguishing itself from existing methodologies such as TTPDrill, TTPHunter, and TCENet, TIEF incorporates a multi-label classification scheme capable of covering 560 MITRE ATT&CK classes comprising techniques and sub-techniques, thus facilitating a more granular and semantically precise characterization of adversarial behaviors. BERTopic modeling integration enabled the clustering of semantically similar textual segments and captured the variations in threat report narratives. By operationalizing sub-technique-level discrimination, TIEF contributes to context-aware automated threat detection.

Similar Papers
  • Book Chapter
  • Citations25

An Overview of Cyber Threat Intelligence Platform and Role of Artificial Intelligence and Machine Learning

  • Jan 01, 2020
  • Abir Dutta +1
  • PDF
  • Research Article
  • Citations15

Generative AI for cyber threat intelligence: applications, challenges, and analysis of real-world case studies

  • Aug 20, 2025
  • Artificial Intelligence Review
  • Prasasthy Balasubramanian +6
  • Supplementary Content
  • Citations2

Inferring Cyber Threat Intelligence -- A Knowledge Graph-based Approach

  • Feb 10, 2021
  • Nidhi Rastogi +6
  • PDF
  • Research Article
  • Citations8

Attack Behavior Extraction Based on Heterogeneous Cyberthreat Intelligence and Graph Convolutional Networks

  • Jan 01, 2023
  • Computers, Materials & Continua
  • Binhui Tang +5
  • PDF
  • Research Article
  • Citations4

Weighted quality criteria for cyber threat intelligence: assessment and prioritisation in the MISP data model

  • Jun 19, 2025
  • International Journal of Information Security
  • Dimitrios Chatziamanetoglou +1
  • Research Article

Enhancing Cyber Threat Intelligence (CTI) Exchange: A Governance Model for the DYNAMO Platform

  • Jun 25, 2025
  • European Conference on Cyber Warfare and Security
  • Jyri Rajamäki +2
  • Conference Article
  • Citations4

Cyber Threat Intelligence and the Cyber Meta-Reality and Cyber Microbiome

  • Jun 01, 2020
  • Joshua A Sipper
  • Conference Article
  • Citations49

Data-Driven Threat Hunting Using Sysmon

  • Mar 16, 2018
  • Vasileios Mavroeidis +1
  • Research Article
  • Citations27

Generating Quality Threat Intelligence Leveraging OSINT and a Cyber Threat Unified Taxonomy

  • May 19, 2022
  • ACM Transactions on Privacy and Security
  • Cláudio Martins +1
  • Research Article
  • Citations2

BVTED: A Specialized Bilingual (Chinese–English) Dataset for Vulnerability Triple Extraction Tasks

  • Aug 20, 2024
  • Applied Sciences
  • Kai Liu +4
  • Research Article
  • Citations9

Cyber Threat Intelligence: Current Trends and Future Perspectives

  • Jun 23, 2023
  • Journal of Engineering Research and Reports
  • Burak Cinar
  • Research Article
  • Citations53

BFLS: Blockchain and Federated Learning for sharing threat detection models as Cyber Threat Intelligence

  • Feb 03, 2023
  • Computer Networks
  • Tongtong Jiang +4
  • Research Article
  • Citations13

AI-Based Holistic Framework for Cyber Threat Intelligence Management

  • Jan 01, 2025
  • IEEE Access
  • Arnolnt Spyros +8
  • Research Article

INVESTIGATING THE ROLE OF AI-POWERED CYBER THREAT INTELLIGENCE SHARING FRAMEWORKS IN ENHANCING NATIONAL SECURITY ACROSS U.S. PUBLIC SECTOR ENTITIES

  • Dec 28, 2025
  • EPRA International Journal of Multidisciplinary Research (IJMR)
  • Mariatu Mahmoud +2
  • Research Article
  • Citations34

Cyber Threat Intelligence for Improving Cybersecurity and Risk Management in Critical Infrastructure

  • Nov 28, 2019
  • Journal of Universal Computer Science
  • Halima Ibrahim Kure +1
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.