Abstract
Cyber Threat Intelligence (CTI) serves as a critical component in modern cybersecurity. Nevertheless, the different writing styles and lack of standardization in CTI documentation impose significant interpretation overhead on security analysts. To mitigate this challenge, we present a structured methodology for automated extraction and contextual mapping of adversarial tactics and techniques from unstructured threat reports to the ATT&CK framework. Our architecture comprises two core components: a BERT-TextCNN hybrid classifier for feature extraction, and a result correction module that corrects classification results based on the tactics and technique dependencies in the ATT&CK matrix, thereby eliminating errors caused by independent predictions. The model is trained and evaluated on a composite dataset, constructed from the canonical descriptions in the MITRE ATT&CK knowledge base and supplemented with annotated real-world reports from the TRAM (Threat Report ATT&CK Mapping) dataset to enhance generalization. Evaluation results demonstrate classification accuracy of 83.80% for tactics and 71.74% for techniques, with the latter outperforming existing baseline approaches. The proposed method effectively converts unstructured CTI into structured knowledge aligned with ATT&CK, providing a tool to assist security analysts in the intelligence processing pipeline.
Author supplied keywords
Cite
CITATION STYLE
Zhang, S., Li, D., & Li, J. (2026). Research on Discovery and Mapping of ATT&CK Tactics and Techniques by Cyber Threat Intelligence Based on BERT-TextCNN. IEEE Access, 14, 5984–5992. https://doi.org/10.1109/ACCESS.2026.3653548
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.