Price TAG: Towards Semi-Automatically Discovery Tactics, Techniques and Procedures OF E-Commerce Cyber Threat Intelligence

Yiming Wu,Qianjun Liu,Xiaojing Liao,Shouling Ji,Peng Wang,Xiaofeng Wang,Chunming Wu,Zhao Li
DOI: https://doi.org/10.1109/tdsc.2021.3120415
2024-01-01
IEEE Transactions on Dependable and Secure Computing
Abstract:Tactics, Techniques and Procedures (TTP) is a type of Cyber Threat Intelligence (CTI) that characterizes attack patterns (e.g., order scalping), infrastructures (e.g., bulletproof hosting platform) and victim targeting (e.g., bank users) associated with specific threat actors. Collecting such information helps organizations effectively identify, mitigate and respond to cyber threats. In this paper, we make the first step towards semi-automatically extracting TTPs from e-commerce threat intelligence corpora. We build a system called TTP Semi-Automatic Generator (TAG) which tailors natural language processing techniques, such as topic term extraction and name entity recognition, for e-commerce TTP recognition. Running on 229,729 e-commerce threat corpora across 39 months, TAG successfully identified 6,042 TTPs with a precision of 80%, which is way beyond what the state-of-the-art NLP techniques can achieve. Further, by analyzing the newly-identified TTPs, our study sheds new light on the trending yet previously-unknown e-commerce CTI.
What problem does this paper attempt to address?