Research Article

GroupTracer: Automatic Attacker TTP Profile Extraction and Group Cluster in Internet of Things

Table 2

Features related to IP & URL feature groups.

#Feature nameDescription

1CountryDescribes the country to which the IP/URL belongs.
2Malicious indexLeverages the VirusTotal API to determine the maliciousness of the IP/URL.
3IP address typeUtilizes the RTBAsia API to classify IP/URL type.
4Download (optional)The file that the attack actor downloaded by executing the command.