Survey of technique association analysis methods based on the ATT&CK framework
Online published: 2026-04-01
Copyright
As cyber offense and defense grows increasingly sophisticated, understanding adversary behaviors is essential for proactive defense. Based on the MITRE ATT&CK framework, we systematically define the paradigm of "Technique Association Analysis," which aims to transform discrete behavioral observations into continuous intent reasoning. Using the core modeling depth of contextual and temporal dependencies as a classification criterion, we categorize current technique association mining methods into three progressive levels: static pattern mining based on statistical co-occurrence and association rules, dynamic evolution analysis using probabilistic graphs and time-series models, and high-level semantic mining that integrates graph computing with large language models. Furthermore, we provide a systematic horizontal comparison and analyze the applicability of these methods in key downstream tasks, including attack chain completion, intent prediction, and defense and detection optimization. Finally, we discuss the limitations of existing methods in dynamic context awareness and cross-modal data alignment, and outline future directions. In particular, we highlight the in-depth integration between large language models and knowledge graphs as a promising avenue, aiming to provide a comprehensive reference for research in automated threat hunting and network security operations.
Zhong Rui , Feng Wenying , Li Ruonan , Gan Longgang , Yu Haoze , Gu Zhaoquan . Survey of technique association analysis methods based on the ATT&CK framework[J]. Journal of Cybersecurity, 2025 , 3(5) : 2 -13 . DOI: 10.20172/j.issn.2097-3136.250501
表 1 基于静态模式挖掘的技术关联方法总结Table 1 Methods for technique association research using statistical co-occurrence ID clustering |
| 方法 | 年份 | 方法描述 | 输出形式 | 使用数据 | 评估策略 | 优点 | 局限性 |
| 分区聚类、层次聚类[3] | 2020 | 使用分区聚类与层次聚类发掘技术关联 | 聚类层次树、技术转移关系图 | MITRE ATT&CK | 信息论方法[4]、专家评估 | 方法简单,能分级排列技术间的关联 | 对上下文内容综合较少,处理复杂APT攻击的能力较弱 |
| Girvan-Newman[5] | 2020 | 提出一个三层模型量化 APT 群组的相似性 | 共现表、技术关联网络 | MITRE ATT&CK | 观察网络图与专家经验 | 分离出了不同组织偏好使用的技术群组 | 数据量较少,且评估方式过于主观 |
| Ward 联结法[6] | 2021 | 从已有的网络安全知识图中提取“技术–组织” 关系 | 聚类层次树 | 已有网络安全知识图 | 观察 ESS 增量和例子验证隐含模式 | 仅依赖已有的 “技术–组织” 关联,无需额外特征工程 | 不考虑技术之间更细粒度的上下文或语义关系;缺乏定量评价指标,无法客观评估聚类效果 |
| Apriori 算法[7] | 2020 | 基于关联规则挖掘进行网络攻击归因 | 挖掘出的关联规则集、散点图、分组矩阵图、规则统计表 | Shadowserver 抓取数据 | 无量化指标,仅提取支持度与置信度排名靠前的关联规则 | 使用真实 CTI 数据;Apriori 算法实现简单、规则可视化 | 缺乏时序或流量上下文分析、阈值需人工调节、缺乏定量评价指标 |
| AGC[8] | 2023 | 提出 AGC活动组,以此为基础进行关联规则挖掘 | 活动组关联、攻击路径 | 部分公开数据集 | 结合真实 APT 攻击场景分析 | 多层次粒度,支持子技术级与父级技术抽象;有一定的上下文关联 | 阈值选择主观、无时序因果关系、对上下文关系的提取过于简单 |
| PDFP-Growth[9] | 2024 | 基于改进 PDFP-Growth算法挖掘关联规则 | PDFP-Growth 规则集、复杂攻击路径 | MITRE ATT&CK、模拟安全事件数据 | 真实攻击场景测试、对比分析 | 支持多维度攻击路径挖掘,规则提取高效 | 缺乏灵活的上下文适配能力,处理大规模数据时效率受限 |
| 语义关联图、Leiden[10] | 2025 | 构建语义关联图,并将其视为社交网络挖掘攻击场景 | 语义关联图、关联规则集、攻击场景子图 | DARPA 2000、CICIDS 2017 | 攻击路径对比、指标计算 | 使用序列模式挖掘语义捕获关联,无需依赖位置或时序模板 | 关联权重设置较为主观、不同攻击场景下社区规模与连通性差异大,可能产生过大或过小子图 |
| FIM、ARM[11] | 2022 | 频繁项集挖掘、关联规则挖掘、构建共现网络 | 频繁个体技术、频繁共现技术组合、关联规则、共现网络 | MITRE ATT&CK | 中心性度量、介数中心度 | 结合频繁项集挖掘、关联规则挖掘和图网络分析揭示技术共现与相互依赖 | 不考虑时序、忽略上下文深度、阈值选择主观、中心性解释有局限 |
表 2 基于动态时序演进的技术关联方法总结Table 2 Summary of technique association methods based on dynamic time-series evolution |
| 方法 | 年份 | 方法描述 | 输出形式 | 使用数据 | 评估策略 | 优点 | 局限性 |
| HMM[15] | 2021 | 假设ATT&CK框架中的战术遵循严格顺序,通过战术映射技术生成攻击序列 | 生成的技术序列列表、序列概率分数 | MITRE ATT&CK、HAI 测试平台 | 前向算法评估、在 HAI测试台执行测试 | 能够快速生成大量的攻击序列 | 模型过于简化,且带有较强假设;转移与发射概率基于有限公开报告计算,生成序列可能失真 |
| 马尔可夫链[14] | 2024 | 基于 ATT&CK 威胁度量体系构建战术转换图,建模 APT 威胁风险模型 | 技术转移图、战术转移图、单技术威胁值表、战术转移矩阵 | MITRE ATT&CK、Mandiant 情报数据 | 攻击路径对比、指标计算 | 在技术转移图基础上提升至战术转移图,构建马尔可夫链预测攻击意图 | 忽略上下文,仅以技术序列与频率驱动;威胁系数依赖专家打分,偏主观 |
| 贝叶斯统计[16] | 2025 | 将系统危害映射至 ATT&CK 战术,利用贝叶斯方法挖掘技术关联 | 动态风险评估结果、攻击路径预测 | 开源 ATT&CK 数据、CVSS 评分数据 | 真实攻击场景测试、对比分析 | 融合多种攻击路径分析方法,精准定位技术关联点 | 依赖大量 ATT&CK 标准数据,小数据集场景下泛化能力弱 |
| LSTM 时序预测[17] | 2025 | 集成 ATT&CK 与 LSTM 时序预测算法,构建高并发企业内网资产暴露面检测系统 | 潜在攻击路径预测、风险警报 | 企业内网环境资产与时序日志 | 真实内网环境(万级IP)实测,对比扫描效率与响应时间 | 工程落地能力极强,利用深度模型精准预测攻击路径 | 主要针对结构化日志定制,非结构化情报自动处理能力不足 |
| Markov 与 LSTM 混合模型[18] | 2025 | 结合一阶马尔可夫链与 LSTM 进行多路径攻击预测,引入链收缩算法降噪 | 攻击路径预测结果、风险评分、概率表与图 | MITRE ATT&CK、STIX 结构化数据 | 与真实 APT 攻击路径比对计算 | 融合时序与语义分析优势,攻击路径预测准确率高 | 依赖 STIX 结构化数据输入,非结构化数据解析能力有限 |
表 3 基于高阶语义挖掘的技术关联方法总结Table 3 Summary of technique association methods based on high-level semantic mining |
| 方法 | 年份 | 方法描述 | 输出的形式 | 使用数据 | 评估策略 | 优点 | 局限性 |
| Bhadra威胁 建模[19] | 2021 | 将技术作为节点,相邻技术间若共现则连边,边权为出现次数; | 高频技术子序列、可视化攻击图 | 60个手工建模的移动通信多阶段攻击案例、Bhadra框架中定义的战术与技术 | 定性与定量图论分析 | 利用Bhadra框架将多源攻击系统化建模、通过图论提取共子路径、重要性与多样性 | 攻击图无环境上下文,忽略实际网络影响;建模过程高度依赖专家判断 |
| 基于知识图谱的攻击链检测与补全系统[20] | 2023 | 基于五元组与MDATA模型构建网络安全知识图谱,实现攻击链检测、补全与剪枝 | 攻击知识图谱 | 流式攻击日志数据 | 实验模拟、攻击链覆盖率与错误状态识别精度 | 将技术关联构建成高度结构化的图谱,具有较高的攻击链识别的准确性与实时性 | 构建与维护知识图谱与规则库成本高,攻击规则泛化能力有限 |
| EFI:端点攻击预测与解释系统[21] | 2024 | 提出EFI系统,通过图结构方法实现对EDR告警的实时后渗透攻击预测与解释 | 攻击场景图、攻击溯源图 | DARPA Engagement数据集 | 图预测准确率、AFG与真实攻击图对齐得分、预测时间 | 对潜在攻击行为有较精准的预测与解释 | 模型训练复杂;对EDR系统能力有前置依赖 |
| MAMBA[24] | 2022 | 构建MLP学习ATT&CK中(资产,技术)对的隐向量、计算资源嵌入与当前API隐向量的相关度 | TTP预测列表 | MITRE ATT&CK、MalShare数据集 | P/R/F1/FPR/FNR评估、消融实验 | 适配大规模样本,远优于传统机器学习与规则方法;多标签输出,同一样本可识别多个并发TTP | 注意力解释非严格推理、稀有TTP标签样本不足时,模型Recall下降 |
| Transformer[25] | 2024 | 基于MITRE ATT&CK战术框架对网络流量按战术阶段建模,并利用Transformer提取时序相关性,实现网络安全态势分类评估 | 安全态势等级 | UNSW‑NB15、NSL‑KDD | Precision、Recall、F1、Accuracy | 利用ATT&CK精细分类,Transformer并行效率高 | 依赖ATT&CK标签映射质量;对新兴攻击技术泛化能力有限 |
| DeepOP混合 框架[22] | 2025 | 结合本体推理提取因果事件,并嵌入Transformer架构进行多步预测 | 攻击序列预测、结构化事件图 | CTI报告、MITRE ATT&CK | 在真实APT数据集上的多步攻击预测精度对比 | 本体论有效缓解了数据稀疏问题,Transformer捕捉了全局时序依赖 | 框架的本体构建阶段仍有一定的人工开销,未完全实现端到端自动化 |
| KillChainGraph[23] | 2025 | 将ATT&CK映射至攻击链,利用有向图与多模型集成学习 | 攻击路径预测、可解释关系图 | MITRE数据集 | 对比多模型及其集成框架在各攻击阶段的F1 | 融合了攻击链的宏观约束,预测结果具备极高的可解释性与准确率 | 预训练语言模型与图神经网络的集成计算开销较大,实时性可能受限 |
| Snort RAG映射[26] | 2025 | 整合LLM与RAG技术,将底层Snort入侵规则翻译并多标签映射至ATT&CK技术 | 威胁摘要、ATT&CK多标签映射表 | Snort规则、CISA咨询报告 | 专家评分(准确度/清晰度),单标签分类准确率达80% | 极大降低了一线安全运营的认知负担,实现底层告警到高层语义的转译 | LLM的上下文窗口限制可能影响超长规则的解析,且存在轻微的“幻觉”风险 |
| TTParser框架[27] | 结合深度网络与LLM验证器,利用少样本提示重构孤立技术为连贯攻击链 | TTP识别结果、分步攻击叙事 | 非结构化CTI报告 | 与现有主流NLP模型对比TTP提取和攻击链重建的准确性 | 突破了孤立节点预测的局限,显式建模了程序化关系,填补了语义鸿沟 | 对LLM提示词的质量和少样本设计高度敏感;大模型调用成本较高 |
表 4 各类技术关联分析方法的横向对比与适用边界Table 4 Comparative analysis of different technique association analysis methods |
| 方法子类 | 时序感知能力 | 上下文建模 深度 | 数据依赖与适用边界条件 | 可解释性 | 典型性能瓶颈、局限性 | 优势适配的下游任务 |
| 统计共现与 聚类 | 无 | 浅层 | 适用于具有大量历史结构化标签的数据集,对数据维度要求低 | 高 | 数据稀疏时聚类边界模糊;无法识别攻击步骤先后顺序 | 基础技术概览、初始预筛选 |
| 关联规则挖掘 | 极弱 | 浅层 | 适用于特征明确、频率分布相对集中的底层日志与告警数据 | 极高 | 受制于最低支持度阈值,极易漏检低频但高危的“长尾”技术 | 静态防御规则生成 |
| 概率图与 贝叶斯 | 中 | 中层 | 适用于状态转移定义清晰且能持续摄入量化情报(如CVSS)的场景 | 高 | 强马尔可夫假设难以处理长距离跨阶段依赖;先验概率高度依赖人工专家 | 动态风险量化、基础意图预测 |
| 深度时序网络 | 极强 | 中层 | 适用于万级IP等高并发、海量序列化日志的内网端点检测场景 | 极低 | 缺乏宏观拓扑感知;对非结构化文本情报毫无处理能力 | 自动化高速链路补全、实时阻断 |
| 图谱与图神经网络 | 强 | 深层 | 适用于多源异构数据(资产、漏洞、用户)交织的复杂APT捕获场景 | 高 | 知识图谱构建的人工成本极高;大规模图卷积运算实时性较差 | 复杂APT溯源补全、可解释性预测 |
| 大语言模型 | 强 | 深层 | 专精于顶层非结构化CTI文本解析、以及晦涩底层规则的语义转译 | 较高 | 上下文窗口限制影响超长报告处理;大模型固有“幻觉”导致校验成本增加 | 自动化情报解析、防御策略转译 |
| 1 |
MITRE. Corporate overview of the MITRE corporation[EB/OL]. [2025-05-29] https://www.mitre.org/about/corporate-overview.
|
| 2 |
MITRE. ATT&CK. [EB/OL]. [2025-05-29]. https://attack.mitre.org.
|
| 3 |
Al-shaer R, Spring J M, Christou E. Learning the associations of MITRE ATT & CK adversarial techniques[C]//Proceedings of the 2020 IEEE Conference on Communications and Network Security (CNS). Piscataway: IEEE Press, 2020: 1-9.
|
| 4 |
Shannon C E. A mathematical theory of communication[J]. Bell System Technical Journal, 1948, 27 (3): 379- 423.
|
| 5 |
Wang W H, Tang B F, Zhu C, et al. Clustering using a similarity measure approach based on semantic analysis of adversary behaviors[C]//Proceedings of the 2020 IEEE Fifth International Conference on Data Science in Cyberspace (DSC). Piscataway: IEEE Press, 2020: 1-7.
|
| 6 |
Ding Z Y, Cao D Q, Liu L N, et al. A method for discovering hidden patterns of cybersecurity knowledge based on hierarchical clustering[C]//Proceedings of the 2021 IEEE Sixth International Conference on Data Science in Cyberspace (DSC). Piscataway: IEEE Press, 2021: 334-338.
|
| 7 |
Abu M S, Rahayu S, Yusof R, et al. An attribution of cyberattack using association rule mining (ARM)[J]. International Journal of Advanced Computer Science and Applications, 2020, 11(2).
|
| 8 |
McKee C, Edie K, Duby A. Activity-attack graphs for intelligence-informed threat COA development[C]//Proceedings of the 2023 IEEE 13th Annual Computing and Communication Workshop and Conference (CCWC). Piscataway: IEEE Press, 2023: 598-604.
|
| 9 |
Wang X Y, Li R L, Luo L, et al. Construction and application of attack tactics and tactics system for intelligent connected vehicles[M]//Cyberspace Simulation and Evaluation. SingaporeSpringer Nature Singapore2025: 444-460.
|
| 10 |
Zang X D, Gong J, Zhang X C, et al. Attack scenario reconstruction via fusing heterogeneous threat intelligence[J]. Computers & Security, 2023, 133, 103420.
|
| 11 |
Rahman M R, Williams L. Investigating co-occurrences of MITRE ATT\&CK techniques[PP/OL]. V1. arXiv (2022-11-11)[2025-05-29]. https://doi.org/10.48550/arXiv.2211.06495.
|
| 12 |
Luna J M, Fournier-viger P, Ventura S. Frequent itemset mining: a 25 years review[J]. WIREs Data Mining and Knowledge Discovery, 2019, 9 (6): e1329.
|
| 13 |
Kumbhare T A, CHOBE S V. An overview of association rule mining algorithms[J]. International Journal of Computer Science and Information Technologies, 2014, 5 (1): 927- 930.
|
| 14 |
Zhang J C, Zheng J, Zhang Z, et al. ATT&CK-based advanced persistent threat attacks risk propagation assessment model for zero trust networks[J]. Computer Networks, 2024, 245, 110376.
|
| 15 |
Choi S, Yun J H, Min B G. Probabilistic attack sequence generation and execution based on MITRE ATT&CK for ICS datasets[C]//Proceedings of the Cyber Security Experimentation and Test Workshop. New York: ACM, 2021: 41-48
|
| 16 |
Maccarone L T, Valme R, Anaya T R. Bayesian attack model (BAM) user story[R]. Sandia National Laboratories (SNL-NM), Albuquerque, NM (United States), 2025.
|
| 17 |
Cai W X, Shi R J, Ye J X, et al. Enterprise internal network asset exposure risk detection system based on go language, ATT&CK framework and LSTM time-series prediction[C]//Proceedings of the 2025 10th International Conference on Cyber Security and Information Engineering (ICCSIE). Piscataway: IEEE Press, 2025: 28-35.
|
| 18 |
Lukade R R. Attack chain contraction and prediction using Markov model and LSTM on MITRE ATT&CK data: a thesis in data science[D]. University of Massachusetts Dartmouth, 2025.
|
| 19 |
Chen H Y, Rao S P. Adversarial trends in mobile communication systems: from attack patterns to potential defenses strategies[M]//Secure IT Systems. Cham: Springer International Publishing, 2021: 153-171
|
| 20 |
Qi Y L, Gu Z Q, Li A P, et al. RETRACTED: Cybersecurity knowledge graph enabled attack chain detection for cyber-physical systems[J]. Computers and Electrical Engineering, 2023, 108, 108660.
|
| 21 |
Zhu T T, Ying J, Chen T M, et al. Nip in the bud: forecasting and interpreting post-exploitation attacks in real-time through cyber threat intelligence reports[J]. IEEE Transactions on Dependable and Secure Computing, 2025, 22 (2): 1431- 1447.
|
| 22 |
Zhang S Q, Xue X H, Su X Y. DeepOP: a hybrid framework for MITRE ATT&CK sequence prediction via deep learning and ontology[J]. Electronics, 2025, 14 (2): 257.
|
| 23 |
Singh C, Dhanraj M, Huang K. KillChainGraph: ML framework for predicting and mapping ATT&CK techniques[PP/OL]. V1. arXiv [2025-08-19]. https://doi.org/10.48550/arXiv.2508.18230.
|
| 24 |
Huang Y T, Lin C Y, Guo Y R, et al. Open source intelligence for malicious behavior discovery and interpretation[J]. IEEE Transactions on Dependable and Secure Computing, 2022, 19 (2): 776- 789.
|
| 25 |
Zhu Z F, An Q, Li S D, et al. Network security situational assessment based on the ATT&CK tactics framework and transformer model[C]//Network Simulation and Evaluation. Singapore: Springer, 2024: 106-119.
|
| 26 |
Lee Y H, Han C S, Peng M C, et al. LLM-based multi-label mapping of snort rules to ATT&CK[C]//Proceedings of the 2025 IEEE Conference on Dependable and Secure Computing (DSC). Piscataway: IEEE Press, 2025: 1-6.
|
| 27 |
Cai Y X, Zhou H C, Wang Z Y, et al. TTParser: leveraging LLM for enhanced mapping of ATT&CK tactics, techniques, and procedures in unstructured cyber threat intelligence[C]//Proceedings of the IEEE International Conference on Big Data and Smart Computing (BigComp). Piscataway: IEEE Press.
|
| 28 |
Skjøtskift G, Eian M, Bromander S. Automated ATT&CK technique chaining[J]. Digital Threats: Research and Practice, 2025, 6 (1): 1- 11.
|
/
| 〈 |
|
〉 |