<div class="csl-bib-body">
<div class="csl-entry">Saha, A., Lindorfer, M., & Caballero, J. (2026). Kitten or Panda? Measuring the Specificity of Threat Group Behaviors in Public CTI Knowledge Bases. In M. Agrawal, I. Molloy, V. Pandit, D. Mukhopadhyay, & K. Paterson (Eds.), <i>ASIA CCS ’26: Proceedings of the ACM Asia Conference on Computer and Communications Security</i> (pp. 1356–1370). The Association for Computing Machinery. https://doi.org/10.1145/3779208.3786258</div>
</div>
-
dc.identifier.uri
http://hdl.handle.net/20.500.12708/230094
-
dc.description.abstract
In recent years, the cyber threat intelligence (CTI) community has invested significant effort in building knowledge bases that catalog threat groups. These knowledge bases associate each threat group with its observed behaviors, including their Tactics, Techniques, and Procedures (TTPs) as well as the malware and tools they employ during attacks. However, the distinctiveness and completeness of such behavioral profiles remain largely unexplored, despite being critical for tasks such as threat group attribution. In this work, we systematically analyze threat group profiles built from two public CTI knowledge bases: MITRE ATT&CK and Malpedia. We first investigate what fraction of threat groups have group-specific behaviors, i.e., behaviors used exclusively by a single group. We find that only 34% of threat groups in ATT&CK have group-specific techniques, limiting the use of techniques as reliable behavioral signatures to identify the threat group behind an attack. The software used by a threat group proves to be more distinctive, with 73% of ATT&CK groups using group-specific software. However, this percentage drops to 24% in the broader Malpedia dataset. Next, we evaluate how group profiles improve when data from both sources are combined. While coverage improves modestly, the proportion of groups with group-specific behaviors remains under 30%. We then enhance profiles by adding exploited vulnerabilities and additional techniques extracted from threat reports. Despite the additional information, 64% of groups still lack any group-specific behavior. Our findings raise concerns about the specificity of existing behavioral profiles and highlight the need for caution, as well as further improvement, when using them for threat group attribution.
en
dc.description.sponsorship
WWTF Wiener Wissenschafts-, Forschu und Technologiefonds
-
dc.description.sponsorship
WWTF Wiener Wissenschafts-, Forschu und Technologiefonds
-
dc.language.iso
en
-
dc.rights.uri
http://creativecommons.org/licenses/by/4.0/
-
dc.subject
Behavioral Profile
en
dc.subject
CTI
en
dc.subject
Malpedia
en
dc.subject
MITRE ATT&CK
en
dc.subject
Threat Actor
en
dc.subject
Threat Group
en
dc.subject
Threat Intelligence
en
dc.subject
TTP
en
dc.subject
Malware
en
dc.subject
Advanced Persistent Threats
en
dc.title
Kitten or Panda? Measuring the Specificity of Threat Group Behaviors in Public CTI Knowledge Bases