Please use this identifier to cite or link to this item:
https://hdl.handle.net/10356/184091
Title: | TTP identification from unstructured text | Authors: | Yu, Ryan Yao Ming | Keywords: | Computer and Information Science | Issue Date: | 2025 | Publisher: | Nanyang Technological University | Source: | Yu, R. Y. M. (2025). TTP identification from unstructured text. Final Year Project (FYP), Nanyang Technological University, Singapore. https://hdl.handle.net/10356/184091 | Project: | CCDS24-0360 | Abstract: | This project aims to study and compare the efficiency of different Large Language Models (LLMs) for the identification of Tactics, Threats, Procedures (TTPs). Accurate identification of TTPs from Cyber Threat Intelligence reports and documentation is vital for threat analysis, proactive defense, and understanding adversarial behavior. Traditional approaches for TTP extraction rely heavily on manual analysis, often requiring extensive expertise and resources. In this study, we investigate both encoder-only models, specifically BERT variants, and decoder-only models such as GPT and LLAMA. Additionally, we evaluate prompt engineering techniques and Retrieval-Augmented Generation (RAG) to enhance TTP extraction. To mitigate limitations posed by sparsely available annotated cybersecurity datasets, we explore various data augmentation methods. We performed comparative experiments, evaluating each model type and enhancement technique. Based on our results, encoder-only models perform much better than decoder-only models for TTP extraction tasks with big gains in accuracy and dependability. Lastly, to make practical use and operational integration easier, we created a web-based application that includes our best-performing model along with Nautral Langauge Processing (NLP) preprocessing pipelines that allow the model to be improved over time. Overall, our findings suggest that encoder-only models such as BERT with data augmentation and fine-tuning represent the most effective approach for reliably extracting TTPs from unstructured cybersecurity texts. | URI: | https://hdl.handle.net/10356/184091 | Schools: | College of Computing and Data Science | Fulltext Permission: | restricted | Fulltext Availability: | With Fulltext |
Appears in Collections: | CCDS Student Reports (FYP/IA/PA/PI) |
Files in This Item:
File | Description | Size | Format | |
---|---|---|---|---|
Yu Yao Ming Ryan_FYP_Report_Final.pdf Restricted Access | 5.22 MB | Adobe PDF | View/Open |
Items in DR-NTU are protected by copyright, with all rights reserved, unless otherwise indicated.