Böge, Emirhan and Ertan, Murat Bilgehan and Alptekin, Halit and Çetin, Orçun (2025) Unveiling cyber threat actors: a hybrid deep learning approach for behavior-based attribution. Digital Threats: Research and Practice, 6 (1). ISSN 2692-1626 (Print) 2576-5337 (Online)
This is the latest version of this item.
Official URL: https://dx.doi.org/10.1145/3676284
Abstract
In this article, we leverage natural language processing and machine learning algorithms to profile threat actors based on their behavioral signatures to establish identification for soft attribution. Our unique dataset comprises various actors and the commands they have executed, with a significant proportion using the Cobalt Strike framework in August 2020-October 2022. We implemented a hybrid deep learning structure combining transformers and convolutional neural networks to benefit global and local contextual information within the sequence of commands, which provides a detailed view of the behavioral patterns of threat actors. We evaluated our hybrid architecture against pre-trained transformer-based models such as BERT, RoBERTa, SecureBERT, and DarkBERT with our high-count, medium-count, and low-count datasets. Hybrid architecture has achieved F1-score of 95.11% and an accuracy score of 95.13% on the high-count dataset, F1-score of 93.60% and accuracy score of 93.77% on the medium-count dataset, and F1-score of 88.95% and accuracy score of 89.25% on the low-count dataset. Our approach has the potential to substantially reduce the workload of incident response experts who are processing the collected cybersecurity data to identify patterns.
Item Type: | Article |
---|---|
Uncontrolled Keywords: | deep learning; Digital forensics; machine learning; natural language processing; threat actor attribution; threat intelligence |
Divisions: | Faculty of Engineering and Natural Sciences |
Depositing User: | Orçun Çetin |
Date Deposited: | 04 Aug 2025 15:21 |
Last Modified: | 04 Aug 2025 15:21 |
URI: | https://research.sabanciuniv.edu/id/eprint/51797 |
Available Versions of this Item
-
Unveiling cyber threat actors: a hybrid deep learning approach for behavior-based attribution. (deposited 20 Sep 2024 15:11)
- Unveiling cyber threat actors: a hybrid deep learning approach for behavior-based attribution. (deposited 04 Aug 2025 15:21) [Currently Displayed]