Kitten or Panda? Measuring the Specificity of Threat Group Behaviors in Public CTI Knowledge Bases
Aakanksha Saha, Martina Lindorfer, Juan Caballero

TL;DR
This study evaluates the uniqueness of threat group behaviors in public CTI knowledge bases, revealing limited group-specific signatures and highlighting challenges in threat attribution accuracy.
Contribution
It systematically analyzes threat group profiles from MITRE ATT&CK and Malpedia, assessing their specificity and proposing insights for improving threat attribution methods.
Findings
Only 34% of groups have group-specific techniques.
73% of groups use group-specific software in ATT&CK.
Over 60% of groups lack any group-specific behavior even after data enhancement.
Abstract
In recent years, the cyber threat intelligence (CTI) community has invested significant effort in building knowledge bases that catalog threat groups. These knowledge bases associate each threat group with its observed behaviors, including their Tactics, Techniques, and Procedures (TTPs) as well as the malware and tools they employ during attacks. However, the distinctiveness and completeness of such behavioral profiles remain largely unexplored, despite being critical for tasks such as threat group attribution. In this work, we systematically analyze threat group profiles built from two public CTI knowledge bases: MITRE ATT&CK and Malpedia. We first investigate what fraction of threat groups have group-specific behaviors, i.e., behaviors used exclusively by a single group. We find that only 34% of threat groups in ATT&CK have group-specific techniques, limiting the use of techniques as…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsInformation and Cyber Security · Cybercrime and Law Enforcement Studies · Network Security and Intrusion Detection
