Key points are not available for this paper at this time.
Understanding cyber attacker behavior is a fundamental requirement for advancing effective threat detection and response mechanisms. Nevertheless, existing cyber attacker profiling techniques often lack sufficient behavioral granularity to reliably distinguish adversaries, particularly when analyzing highly variable, noisy, and chained command sequences. To capture true operational semantics, this paper presents a novel behavior-driven profiling framework based on empirical data collected from SSH honeypot deployments. The proposed methodology systematically parses these complex command chains to identify distinct behavioral patterns and categorize attackers accordingly. A total of 176 unique attack patterns were extracted and organized into 18 behavioral clusters, which were subsequently mapped to the MITRE ATT&CK framework for structured interpretation. Cluster validity and reliability were evaluated using Indicators of Compromise (IoCs) and statistical validation methods. The evaluation confirmed seven robust behavioral clusters, while five additional clusters exhibited strong alignment with known IoCs, demonstrating the effectiveness, robustness, and practical applicability of the proposed profiling approach for real-world cyber threat analysis.
Lim et al. (Thu,) studied this question.