首页 / 资料库 / 文献详情

DroidTTP: Mapping android applications with TTP for Cyber Threat Intelligence

Dincy R. ArikkatP. K. VinodRafidha Rehiman K. A.Serena NicolazzoMarco ArazziAntonino NoceraMauro Conti

2025Journal of Information Security and ApplicationsComputer Science被引 8开放获取

出版方页面 →

摘要

The widespread use of Android devices for sensitive operations has made them prime targets for sophisticated cyber threats, including Advanced Persistent Threats (APT). Traditional malware detection methods focus primarily on malware classification, often failing to reveal the Tactics, Techniques, and Procedures (TTPs) used by attackers. To address this issue, we propose DroidTTP, a novel system for mapping Android malware to attack behaviors. We curated a dataset linking Android applications to Tactics and Techniques and developed an automated mapping approach using the Problem Transformation Approach and Large Language Models (LLMs). Our pipeline includes dataset construction, feature selection, data augmentation, model training, and explainability via SHAP. Furthermore, we explored the use of LLMs for TTP prediction using both Retrieval Augmented Generation and fine-tuning strategies. The Label Powerset XGBoost model achieved the best performance, with Jaccard Similarity scores of 0.9893 for Tactic classification and 0.9753 for Technique classification. The fine-tuned LLaMa model also performed competitively, achieving 0.9583 for Tactics and 0.9348 for Techniques. Although XGBoost slightly outperformed LLMs, the narrow performance gap highlights the potential of LLM-based approaches for Tactic and Technique prediction.

引用本文(GB/T 7714)

Dincy R. Arikkat, P. K. Vinod, Rafidha Rehiman K. A., 等. DroidTTP: Mapping android applications with TTP for Cyber Threat Intelligence[J]. Journal of Information Security and Applications, 2025.

引文网络

参考文献与被引分析加载中…

DOI:https://doi.org/10.1016/j.jisa.2025.104162

本站仅收录题录与摘要供学习参考,全文版权归属出版方;如有侵权请联系我们删除。