Cyber threats pose significant challenges to global security, as attackers constantly evolve their tactics and techniques. This paper introduces a novel methodology for classifying cyber threats using Natural Language Processing (NLP) applied to the comprehensive MITRE ATT&CK framework. By integrating NLP techniques with machine learning algorithms, including tokenization, lemmatization, and the application of transformer-based models like SecBERT, we develop a sophisticated system capable of analyzing and categorizing cyber threat data with enhanced precision. Our study systematically evaluates the performance of several classifiers, including Logistic Regression, K-Nearest Neighbors, Support Vector Machines, and SecBERT, using metrics such as accuracy, precision, recall, and F1-score. The results demonstrate that our NLP-based approach not only improves the accuracy and speed of threat classification, but also provides deeper insights into attack patterns, enabling more effective security measures. This research contributes to cybersecurity analytics by offering a scalable and efficient solution to cyber threat classification and highlighting the benefits of leveraging NLP within existing cybersecurity frameworks.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

NLP-Driven Cyber Threat Classification Leveraging the MITRE ATT&CK Framework

  • Zakaria Baou,
  • Nour Amellouk,
  • Mahmoud El Hamlaoui,
  • Anas Motii

摘要

Cyber threats pose significant challenges to global security, as attackers constantly evolve their tactics and techniques. This paper introduces a novel methodology for classifying cyber threats using Natural Language Processing (NLP) applied to the comprehensive MITRE ATT&CK framework. By integrating NLP techniques with machine learning algorithms, including tokenization, lemmatization, and the application of transformer-based models like SecBERT, we develop a sophisticated system capable of analyzing and categorizing cyber threat data with enhanced precision. Our study systematically evaluates the performance of several classifiers, including Logistic Regression, K-Nearest Neighbors, Support Vector Machines, and SecBERT, using metrics such as accuracy, precision, recall, and F1-score. The results demonstrate that our NLP-based approach not only improves the accuracy and speed of threat classification, but also provides deeper insights into attack patterns, enabling more effective security measures. This research contributes to cybersecurity analytics by offering a scalable and efficient solution to cyber threat classification and highlighting the benefits of leveraging NLP within existing cybersecurity frameworks.