Skip to content
Research Article Open access CC BY 4.0

Cybersecurity Risk Stratification Framework Using Multilevel Clustering: An Automated Threat Attribution and Categorization Approach for Cross-industry Cybersecurity

Temilade Oluwatoyin Adesokan-Imran, Anuoluwapo Deborah Popoola, Faith Hauwa Oluwapamilerin Kolo, Valerie Ojinika Ejiofor, Isaac Adinoyi Salami

Journal of Engineering Research and Reports · pp. 241–263 · Published 8 Apr 2025

10.9734/jerr/2025/v27i41469

Abstract

This study introduces a novel Multilevel Clustering Framework designed for automated threat attribution and categorization across various industries using a comprehensive dataset from the MITRE ATT&CK repository. The methodology integrates K-means Clustering, Hierarchical Clustering, and Fuzzy C-means to address key limitations of traditional models, including inadequate adaptability, scalability, and robustness to noise. By employing a three-stage clustering process, the framework ensures improved detection accuracy, robustness against noise, and cross-industry applicability. The concept of Generalized Attack Patterns refers to commonly occurring attack vectors and techniques that transcend specific industries, allowing for a unified approach to threat detection. Unlike traditional clustering models that are constrained by sector-specific characteristics, the proposed framework effectively identifies and categorizes both industry-specific and generalized threats with high accuracy. Quantitative evaluation across healthcare, finance, telecommunications, manufacturing, and critical infrastructure demonstrates the framework’s effectiveness, achieving a Classification Accuracy of 0.90, Robustness to Noise of 0.83, Adaptability Index of 0.87, and Cross-Industry Applicability of 0.85. However, the Telecommunications sector showed comparatively lower performance, with a Jaccard Index of 0.74, indicating challenges in clustering highly dynamic datasets. Recommendations include implementing customized pre-processing techniques for telecommunications, incorporating hybrid models in finance, refining algorithms for critical infrastructure, and integrating real-time data for cross-industry applications.

Multilevel clustering MITRE ATT&CK threat attribution cross-industry applicability cybersecurity framework

Cited by 2

2 citations reported by external sources — individual citing-article records aren't available to list yet.

Article metrics

Real usage data collected on this platform.

0

Page views

0

PDF downloads

0

Outbound clicks

2

Citations

Views by country

Approximate, from request IP at view time — not citizenship or institution. Countries with fewer than 5 views are grouped as "Other".

No views recorded yet.

Traffic sources

Referring site, by host.

No traffic recorded yet.

Views and downloads exclude known bots/crawlers. Citations combines this platform's own DOI-resolved index with each external source's own reported total — see Cited by above for individually listed citing works. Last refreshed 0 seconds ago.