Skip to content
InfoSec | Blockchain | Machine Learning | AI | Data Science
facebook
twitter
youtube
instagram
linkedin
FrondeurLabs
Call Support +91 812 3888 236
Email Support info@frondeurlabs.com
Location Bangalore
  • Company
    • About
    • Careers
      • Budding Engineers Program
        • Internship (Remote)
    • Contact Us
  • Products & Services
    • Products
      • FLS ORBIT ASM
      • PathVector
      • DeltaZero
    • Services
      • Security Essentials
        • Vulnerability Assessment and Penetration Testing
        • Security Awareness Training
      • Cyber Security Packages
        • Startup And SMB Security Package
        • Managed Security Services
      • Compliance Solutions
        • Compliance Solutions
      • Blockchain Security
        • Blockchain Security
      • C-Suite
        • vCISO
    • Courses
      • Introduction to Bitcoin and Blockchain
      • Certified Bitcoin and Blockchain Professional
      • Certified Blockchain Professional
      • Certified Professional Ethical Hacker
  • Pricing & Plans
    • FLS ORBIT Pricing
  • Partners
  • Research

Research Works

Home > Research > Research Works

Research Works

Posted on September 2, 2025May 9, 2026 by blockscouncil
0

KillChainGraph: ML Framework for Predicting and Mapping ATT&CK Techniques

Chitraksh Singh, Monisha Dhanraj, Ken Huang

Abstract: The escalating complexity and volume of cyberattacks demand proactive detection strategies that go beyond traditional rule-based systems. This paper presents a phase-aware, multi-model machine learning framework that emulates adversarial behavior across the seven phases of the Cyber Kill Chain using the MITRE ATT&CK Enterprise dataset. Techniques are semantically mapped to phases via ATTACK-BERT, producing seven phase-specific datasets. We evaluate LightGBM, a custom Transformer encoder, fine-tuned BERT, and a Graph Neural Network (GNN), integrating their outputs through a weighted soft voting ensemble. Inter-phase dependencies are modeled using directed graphs to capture attacker movement from reconnaissance to objectives. The ensemble consistently achieved the highest scores, with F1-scores ranging from 97.47% to 99.83%, surpassing GNN performance (97.36% to 99.81%) by 0.03%–0.20% across phases. This graph-driven, ensemble-based approach enables interpretable attack path forecasting and strengthens proactive cyber defense.

Read more about our KillChainGraph or download the paper from arXiv:

https://arxiv.org/abs/2508.18230

  • Share on LinkedIn (Opens in new window)LinkedIn
  • Share on Facebook (Opens in new window)Facebook
  • Share on WhatsApp (Opens in new window)WhatsApp
  • Share on Threads (Opens in new window)Threads

Policy-Value Guided MDP-MCTS Framework for Cyber Kill-Chain Inference

Chitraksh Singh, Monisha Dhanraj, Ken Huang

Abstract: Threat analysts routinely rely on natural-language reports that describe attacker actions without enumerating the full kill chain or the dependencies between phases, making automated reconstruction of ATT&CK consistent intrusion paths a difficult open problem. We propose a reasoning framework that infers complete seven-phase kill chains by coupling phase-conditioned semantic priors from Transformer models with a symbolic Markov Decision Process and an AlphaZero-style Monte Carlo Tree Search guided by a Policy-Value Network. The framework enforces semantic relevance, phase cohesion, and transition plausibility through a multi-objective reward function while allowing search to explore alternative interpretations of the CTI narrative. Applied to three real intrusions FIN6, APT24, and UNC1549 the approach yields kill chains that surpass Transformer baselines in semantic fidelity and operational coherence, and frequently align with expert-selected TTPs. Our results demonstrate that combining contextual embeddings with search-based decision-making offers a practical path toward automated, interpretable kill-chain reconstruction for cyber defense.

Read more about KillChain Inference or download the paper from arXiv:

https://arxiv.org/abs/2512.15150

  • Share on LinkedIn (Opens in new window)LinkedIn
  • Share on Facebook (Opens in new window)Facebook
  • Share on WhatsApp (Opens in new window)WhatsApp
  • Share on Threads (Opens in new window)Threads

Tags: AI, ATTACK MITRE, Graph Neural Network, Information Security, Kill Chain Graph

Frondeur Labs Private Limited
Bangalore
+91 8123888236
info@frondeurlabs.com

COMPANY

Contact Us
Support
Privacy Policy

Our Publications

Our Research

PARTNER WITH US

Partners

Connect With Us

Copyright, 2020 Frondeur Labs Private Limited | WordPress Theme: Enlighten