{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,17]],"date-time":"2026-07-17T14:28:25Z","timestamp":1784298505541,"version":"3.55.0"},"reference-count":43,"publisher":"MDPI AG","issue":"4","license":[{"start":{"date-parts":[[2023,2,10]],"date-time":"2023-02-10T00:00:00Z","timestamp":1675987200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"RSF","award":["21-71-20078"],"award-info":[{"award-number":["21-71-20078"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>The notion of the attacker profile is often used in risk analysis tasks such as cyber attack forecasting, security incident investigations and security decision support. The attacker profile is a set of attributes characterising an attacker and their behaviour. This paper analyzes the research in the area of attacker modelling and presents the analysis results as a classification of attacker models, attributes and risk analysis techniques that are used to construct the attacker models. The authors introduce a formal two-level attacker model that consists of high-level attributes calculated using low-level attributes that are in turn calculated on the basis of the raw security data. To specify the low-level attributes, the authors performed a series of experiments with datasets of attacks. Firstly, the requirements of the datasets for the experiments were specified in order to select the appropriate datasets, and, afterwards, the applicability of the attributes formed on the basis of such nominal parameters as bash commands and event logs to calculate high-level attributes was evaluated. The results allow us to conclude that attack team profiles can be differentiated using nominal parameters such as bash history logs. At the same time, accurate attacker profiling requires the extension of the low-level attributes list.<\/jats:p>","DOI":"10.3390\/s23042028","type":"journal-article","created":{"date-parts":[[2023,2,13]],"date-time":"2023-02-13T02:14:11Z","timestamp":1676254451000},"page":"2028","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":11,"title":["Cyber Attacker Profiling for Risk Analysis Based on Machine Learning"],"prefix":"10.3390","volume":"23","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-6859-7120","authenticated-orcid":false,"given":"Igor","family":"Kotenko","sequence":"first","affiliation":[{"name":"Computer Security Problems Laboratory, St. Petersburg Federal Research Center of the Russian Academy of Sciences, 199178 Saint-Petersburg, Russia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6707-9153","authenticated-orcid":false,"given":"Elena","family":"Fedorchenko","sequence":"additional","affiliation":[{"name":"Computer Security Problems Laboratory, St. Petersburg Federal Research Center of the Russian Academy of Sciences, 199178 Saint-Petersburg, Russia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2923-4954","authenticated-orcid":false,"given":"Evgenia","family":"Novikova","sequence":"additional","affiliation":[{"name":"Computer Security Problems Laboratory, St. Petersburg Federal Research Center of the Russian Academy of Sciences, 199178 Saint-Petersburg, Russia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9303-0230","authenticated-orcid":false,"given":"Ashish","family":"Jha","sequence":"additional","affiliation":[{"name":"Computer Security Problems Laboratory, St. Petersburg Federal Research Center of the Russian Academy of Sciences, 199178 Saint-Petersburg, Russia"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2023,2,10]]},"reference":[{"key":"ref_1","first-page":"244","article-title":"Attack Intention Recognition: A Review","volume":"19","author":"Ahmed","year":"2017","journal-title":"Int. J. Netw. Secur."},{"key":"ref_2","unstructured":"Abdlhamed, M., Kifayat, K., Shi, Q., and Hurst, W. (2017). Information Fusion for Cyber-Security Analytics, Springer."},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Kheir, N., Cuppens-Boulahia, N., Cuppens, F., and Debar, H. (2010, January 20\u201322). A service dependency model for cost-sensitive intrusion response. Proceedings of the European Symposium on Research in Computer Security, Athens, Greece.","DOI":"10.1007\/978-3-642-15497-3_38"},{"key":"ref_4","first-page":"1","article-title":"Threat agent library helps identify information security risks","volume":"2","author":"Casey","year":"2007","journal-title":"Intel White Pap."},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Bar, A., Shapira, B., Rokach, L., and Unger, M. (2016, January 23\u201324). Identifying attack propagation patterns in honeypots using Markov chains modeling and complex networks analysis. Proceedings of the 2016 IEEE International Conference on Software Science, Technology and Engineering (SWSTE), Beer Sheva, Israel.","DOI":"10.1109\/SWSTE.2016.13"},{"key":"ref_6","unstructured":"Oosterhof, G.M. (2023, January 27). Cowrie. Available online: https:\/\/github.com\/cowrie\/cowrie."},{"key":"ref_7","first-page":"1626","article-title":"Cloud security: LKM and optimal fuzzy system for intrusion detection in cloud environment","volume":"29","author":"Shyla","year":"2020","journal-title":"J. Intell. Syst."},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"4","DOI":"10.1080\/01402390.2014.977382","article-title":"Attributing cyber attacks","volume":"38","author":"Rid","year":"2015","journal-title":"J. Strateg. Stud."},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"31","DOI":"10.22619\/IJCSA.2017.100113","article-title":"YAAS-On the Attribution of Honeypot Data","volume":"2","author":"Fraunholz","year":"2017","journal-title":"Int. J. Cyber Situational Aware"},{"key":"ref_10","unstructured":"Howard, J.D., and Longstaff, T.A. (1998). A Common Language for Computer Security Incidents, Sandia National Lab. (SNL-NM). Technical Report."},{"key":"ref_11","doi-asserted-by":"crossref","first-page":"65","DOI":"10.13052\/jcsm2245-1439.414","article-title":"Cyber security and the internet of things: Vulnerabilities, threats, intruders and attacks","volume":"4","author":"Abomhara","year":"2015","journal-title":"J. Cyber Secur. Mobil."},{"key":"ref_12","unstructured":"Aliyev, V. (2010). Using Honeypots to Study Skill Level of Attackers Based on the Exploited Vulnerabilities in the Network. [Ph.D. Thesis, Chalmers University of Technology]."},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Jhawar, R., Lounis, K., and Mauw, S. (2016, January 26\u201327). A stochastic framework for quantitative analysis of attack-defense trees. Proceedings of the International Workshop on Security and Trust Management, Crete, Greece.","DOI":"10.1007\/978-3-319-46598-2_10"},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Pricop, E., and Mihalache, S.F. (2015, January 25\u201327). Fuzzy approach on modelling cyber attacks patterns on data transfer in industrial control systems. Proceedings of the 2015 7th International Conference on Electronics, Computers and Artificial Intelligence (ECAI), Bucharest, Romania.","DOI":"10.1109\/ECAI.2015.7301200"},{"key":"ref_15","first-page":"1567","article-title":"Real Time Attacker Behavior Pattern Discovery and Profiling Using Fuzzy Rules","volume":"19","author":"Mallikarjunan","year":"2018","journal-title":"J. Internet Technol."},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Perry, I., Li, L., Sweet, C., Su, S.H., Cheng, F.Y., Yang, S.J., and Okutan, A. (2018, January 10\u201313). Differentiating and predicting cyberattack behaviors using lstm. Proceedings of the 2018 IEEE Conference on Dependable and Secure Computing (DSC), Kaohsiung, Taiwan.","DOI":"10.1109\/DESEC.2018.8625145"},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Doynikova, E., Novikova, E., and Kotenko, I. (2020). Attacker behaviour forecasting using methods of intelligent data analysis: A comparative review and prospects. Information, 11.","DOI":"10.3390\/info11030168"},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Garcia-Alfaro, J., Leneutre, J., Cuppens, N., and Yaich, R. (2020, January 4\u20136). Towards Attacker Attribution for Risk Analysis. Proceedings of the Risks and Security of Internet and Systems, Paris, France.","DOI":"10.1007\/978-3-030-68887-5"},{"key":"ref_19","unstructured":"(2021, November 26). CPTC 2019 Dataset. Available online: http:\/\/mirrors.rit.edu\/cptc\/2019\/mirrors\/."},{"key":"ref_20","first-page":"21","article-title":"Attack Trees: Modeling security threats","volume":"24","author":"Schneier","year":"1999","journal-title":"Dr. Dobb\u2019s J. Softw. Tools"},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"49","DOI":"10.1109\/MSECP.2003.1236235","article-title":"Impact analysis of faults and attacks in large-scale networks","volume":"1","author":"Hariri","year":"2003","journal-title":"IEEE Secur. Priv."},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Ingols, K., Chu, M., Lippmann, R., Webster, S., and Boyer, S. (2009, January 7\u201311). Modeling modern network attacks and countermeasures using attack graphs. Proceedings of the 2009 Annual Computer Security Applications Conference, Honolulu, HI, USA.","DOI":"10.1109\/ACSAC.2009.21"},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Kotenko, I., and Stepashkin, M. (2006, January 19\u201321). Attack graph based evaluation of network security. Proceedings of the IFIP International Conference on Communications and Multimedia Security, Heraklion Crete, Greece.","DOI":"10.1007\/11909033_20"},{"key":"ref_24","doi-asserted-by":"crossref","first-page":"83","DOI":"10.1016\/j.cose.2015.11.005","article-title":"A comprehensive approach for network attack forecasting","volume":"58","author":"GhasemiGol","year":"2016","journal-title":"Comput. Secur."},{"key":"ref_25","doi-asserted-by":"crossref","unstructured":"Doynikova, E., and Kotenko, I. (2015, January 20\u201322). Countermeasure selection based on the attack and service dependency graphs for security incident management. Proceedings of the International Conference on Risks and Security of Internet and Systems, Lesbos Island, Greece.","DOI":"10.1007\/978-3-319-31811-0_7"},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"An, S., Eom, T., Park, J.S., Hong, J.B., Nhlabatsi, A., Fetais, N., Khan, K.M., and Kim, D.S. (2019, January 5\u20138). Cloudsafe: A tool for an automated security analysis for cloud computing. Proceedings of the 2019 18th IEEE International Conference On Trust, Security And Privacy In Computing And Communications\/13th IEEE International Conference On Big Data Science And Engineering (TrustCom\/BigDataSE), Rotorua, New Zealand.","DOI":"10.1109\/TrustCom\/BigDataSE.2019.00086"},{"key":"ref_27","unstructured":"Deshmukh, S., Rade, R., and Kazi, D. (2019). Attacker behaviour profiling using stochastic ensemble of hidden markov models. arXiv."},{"key":"ref_28","doi-asserted-by":"crossref","unstructured":"Katipally, R., Yang, L., and Liu, A. (2011, January 12\u201314). Attacker behavior analysis in multi-stage attack detection system. Proceedings of the Seventh Annual Workshop on Cyber Security and Information Intelligence Research, Oak Ridge, TN, USA.","DOI":"10.1145\/2179298.2179369"},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Shanmugam, B., and Idris, N.B. (2011). Hybrid intrusion detection systems (HIDS) using Fuzzy logic. Intrusion Detect. Syst., 135\u2013155.","DOI":"10.5772\/14130"},{"key":"ref_30","unstructured":"Dickerson, J.E., and Dickerson, J.A. (2000, January 13\u201315). Fuzzy network profiling for intrusion detection. Proceedings of the PeachFuzz 2000. 19th International Conference of the North American Fuzzy Information Processing Society-NAFIPS (Cat. No. 00TH8500), Atlanta, GA, USA."},{"key":"ref_31","doi-asserted-by":"crossref","unstructured":"Shanmugam, B., and Idris, N.B. (2009, January 4\u20137). Improved intrusion detection system using fuzzy logic for detecting anamoly and misuse type of attacks. Proceedings of the 2009 International Conference of Soft Computing and Pattern Recognition, Malacca, Malaysia.","DOI":"10.1109\/SoCPaR.2009.51"},{"key":"ref_32","doi-asserted-by":"crossref","first-page":"2705","DOI":"10.1007\/s00500-015-1669-6","article-title":"Fuzzy approach for intrusion detection based on user\u2019s commands","volume":"20","author":"Porwik","year":"2016","journal-title":"Soft Comput."},{"key":"ref_33","doi-asserted-by":"crossref","first-page":"6111","DOI":"10.1002\/sec.1761","article-title":"Predicting the behavior of attackers and the consequences of attacks against cyber-physical systems","volume":"9","author":"Orojloo","year":"2016","journal-title":"Secur. Commun. Netw."},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"430","DOI":"10.1108\/13685201211266015","article-title":"Characterising and predicting cyber attacks using the Cyber Attacker Model Profile (CAMP)","volume":"15","author":"Watters","year":"2012","journal-title":"J. Money Laund. Control."},{"key":"ref_35","doi-asserted-by":"crossref","unstructured":"Munaiah, N., Rahman, A., Pelletier, J., Williams, L., and Meneely, A. (2019, January 19\u201320). Characterizing Attacker Behavior in a Cybersecurity Penetration Testing Competition. Proceedings of the 2019 ACM\/IEEE International Symposium on Empirical Software Engineering and Measurement (ESEM), Porto de Galinhas, Brazil.","DOI":"10.1109\/ESEM.2019.8870147"},{"key":"ref_36","doi-asserted-by":"crossref","unstructured":"Wang, L., Islam, T., Long, T., Singhal, A., and Jajodia, S. (2008, January 13\u201316). An attack graph-based probabilistic security metric. Proceedings of the IFIP Annual Conference on Data and Applications Security and Privacy, London, UK.","DOI":"10.1007\/978-3-540-70567-3_22"},{"key":"ref_37","doi-asserted-by":"crossref","unstructured":"Kotenko, I., and Doynikova, E. (2016, January 7\u201319). Dynamical Calculation of Security Metrics for Countermeasure Selection in Computer Networks. Proceedings of the 24th Euromicro International Conference on Parallel, Distributed, and Network-Based Processing (PDP 2016), Heraklion, Greece.","DOI":"10.1109\/PDP.2016.96"},{"key":"ref_38","first-page":"211","article-title":"Improvement of attack graphs for cybersecurity monitoring: Handling of inaccuracies, processing of cycles, mapping of incidents and automatic countermeasure selection","volume":"57","author":"Doynikova","year":"2018","journal-title":"Inform. Autom."},{"key":"ref_39","doi-asserted-by":"crossref","unstructured":"Rashid, T., Agrafiotis, I., and Nurse, J.R. (2016, January 28). A new take on detecting insider threats: Exploring the use of hidden markov models. Proceedings of the 8th ACM CCS International Workshop on Managing Insider Security Threats, Vienna, Austria.","DOI":"10.1145\/2995959.2995964"},{"key":"ref_40","doi-asserted-by":"crossref","unstructured":"Cayirci, E., and Rong, C. (2008). Security in Wireless ad Hoc and Sensor Networks, John Wiley & Sons.","DOI":"10.1002\/9780470516782"},{"key":"ref_41","unstructured":"(2021, November 26). DEFCON 26 CTF Homepage. Available online: https:\/\/media.defcon.org\/DEF%20CON%2026\/."},{"key":"ref_42","unstructured":"(2021, November 26). Splunk Official Web Site. Available online: https:\/\/www.splunk.com\/."},{"key":"ref_43","doi-asserted-by":"crossref","unstructured":"Jha, A., Novikova, E.S., Tokarev, D., and Fedorchenko, E.V. (2021, January 21\u201323). Feature Selection for Attacker Attribution in Industrial Automation & Control Systems. Proceedings of the 2021 IV International Conference on Control in Technical Systems (CTS), Saint Petersburg, Russia.","DOI":"10.1109\/CTS53513.2021.9562879"}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/23\/4\/2028\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T18:31:02Z","timestamp":1760121062000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/23\/4\/2028"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,2,10]]},"references-count":43,"journal-issue":{"issue":"4","published-online":{"date-parts":[[2023,2]]}},"alternative-id":["s23042028"],"URL":"https:\/\/doi.org\/10.3390\/s23042028","relation":{},"ISSN":["1424-8220"],"issn-type":[{"value":"1424-8220","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,2,10]]}}}