TRACE-CTI: A Framework for Auditable TTP Claim Governance
A new framework called TRACE-CTI addresses the challenge of trusting automated mappings of Cyber Threat Intelligence reports to MITRE ATT&CK. It preserves run-level predictions, aggregates them into configuration-level GraphAssertions, materializes corroboration as ConsensusAssertions, and exposes only policy-compliant GraphAssertions. The framework retains evidence granularity, extraction provenance, versioned trust decisions, and non-destructive revocation history. Evaluated on two public CTI corpora with 65 reports and 5,303 sentences using a controlled 2x3 matrix of retrievers and generator families.
Key facts
- TRACE-CTI is a post-extraction claim-governance framework for CTI reports mapped to MITRE ATT&CK.
- It preserves run-level predictions and aggregates them into GraphAssertions.
- Corroboration is materialized as ConsensusAssertions.
- Only policy-compliant GraphAssertions are exposed.
- Framework retains evidence granularity, extraction provenance, versioned trust decisions, and non-destructive revocation history.
- Evaluated on two public CTI corpora with 65 reports and 5,303 sentences.
- Used a controlled 2x3 matrix of retrievers and generator families.
- Addresses the need for auditable governance of TTP claims.
Entities
Institutions
- MITRE
- Security Operations Centers