Primary supervisor
Mengmeng GeCyber Threat Intelligence (CTI) plays a vital role in today's cybersecurity landscape by collecting and analysing data about current and potential threats, providing insights to better understand, mitigate and respond in this ever-evolving environment. A core component of CTI is the identification of adversarial Tactics, Techniques, and Procedures (TTPs), which describe how attackers operate at a strategic and operational level. These TTPs are commonly structured using frameworks such as MITRE ATT&CK and are widely used to support threat hunting, attacker attribution, and incident response.
In recent years, substantial research effort has focused on automating the extraction of TTPs from unstructured CTI reports using Natural Language Processing (NLP) and machine learning techniques. While increasingly sophisticated models, including large language models (LLMs), have been proposed, recent systematisation studies reveal that performance improvements remain insufficient for reliable real-world deployment. This creates opportunities to investigate, compare, and improve different approaches for automatically extracting TTPs.
Aim/outline
This project aims to investigate approaches for automatically extracting TTPs from Cyber Threat Intelligence (CTI). It will study existing TTP extraction approaches, investigate key challenges, and explore methods for improving extraction performance. The project will develop and evaluate a TTP extraction approach using existing CTI datasets and appropriate evaluation metrics.
Required knowledge
- Strong Python programming skills.
- Have some interest and basic knowledge in cybersecurity and/or machine learning.