NORMA eResearch @NCI Library

Leveraging Threat Intelligence Feeds for Predictive Threat Modeling and Attack Simulation in Enterprise Networks

Sharma, Anushka (2025) Leveraging Threat Intelligence Feeds for Predictive Threat Modeling and Attack Simulation in Enterprise Networks. Masters thesis, Dublin, National College of Ireland.

[thumbnail of Master of Science]
Preview
PDF (Master of Science)
Download (1MB) | Preview
[thumbnail of Configuration Manual]
Preview
PDF (Configuration Manual)
Download (987kB) | Preview

Abstract

Organisations are overwhelmed with threat intelligence data and manually classifying threat data is not practical, and at the same time advanced cyberattacks are out of reach when using the conventional rule-based methods of detection. The study builds a predictive threat classification model that uses machine learning to use combined threat intelligence feeds to predict cyberattacks and test defences by simulating controlled attacks. The threat intelligence sources used are CTIMiner (11,116 events), PhishTank (10,000 URLs) and URLhaus (10,000 URLs) and the methodology results in the creation of a single corpus of 31,116 events over 17.9 years. Ensemble classification with the help of Random Forest, Extra Trees, and XGBoost algorithms was designed using 24 IOC-based features distributed in eight categories. To verify the models, actual world attack simulation was used in a VirtualBox Virtual environment, with 55 Ubuntu attacker to windows victim attacks. Random Forest achieved optimal performance with 83.69% accuracy and 0.8224 F1-score on threat classification. The simulation of attacks produced 252,866 Windows events based on Sysmon logging. Critical finding: validation revealed only 14.25% accuracy on network-based attack detection, exposing significant feature mismatch between IOC-based training data and deployment environment characteristics. The study adds a new multi-source threat intelligence integration model and an extensive MITRE ATT-CK-aligned defence solutions with 49 SIEM rules and 49 EDR configurations, as well as the key requirements of closing the gap between laboratory model operation and a real application.

Item Type: Thesis (Masters)
Supervisors:
Name
Email
Salahuddin, Jawad
UNSPECIFIED
Subjects: Q Science > QA Mathematics > Electronic computers. Computer science
T Technology > T Technology (General) > Information Technology > Electronic computers. Computer science
Q Science > QA Mathematics > Computer software > Computer Security
T Technology > T Technology (General) > Information Technology > Computer software > Computer Security
Divisions: School of Computing > Master of Science in Cyber Security
Depositing User: Ciara O'Brien
Date Deposited: 04 Sep 2026 10:53
Last Modified: 04 Sep 2026 10:53
URI: https://norma.ncirl.ie/id/eprint/9831

Actions (login required)

View Item View Item