Published August 3, 2026 | Version 2.4

A Cause-Oriented Cyber Threat Taxonomy: The Top Level Cyber Threat Clusters Framework

Authors/Creators

  • 1. Barnes Projects

Description

Cybersecurity discourse routinely uses the term "cyber threat" to denote several distinct concepts at once: the cause of a compromise, its outcome, the actor responsible, and the technique employed.
This conflation impedes consistent classification, comparable incident documentation, and clear communication of cyber risk between leadership, risk functions, and technical teams.
Established frameworks address adjacent layers — control objectives, adversary techniques, software weaknesses, and quantitative risk — but none provides a compact, non-overlapping taxonomy on the cause side that holds stable across system types.
 
The Top Level Cyber Threat Clusters (TLCTC) framework proposes ten top-level threat clusters, each defined by the single generic vulnerability it initially targets.
The taxonomy separates threats (causes) from system events, data risk events, business consequences, and actor identity.
This paper presents the framework's derivation logic, its design principles and threat topology, the ten cluster definitions, the ten axioms that constrain interpretation, and the classification rules that keep assignment reproducible, together with example mappings expressed in an attack-path notation.
 
By distinguishing a stable strategic management view from a concrete operational security view, TLCTC functions as a translation layer linking strategic risk governance, security operations, and secure software development.

Notes

v2.4 (2026-07-28). This deposit supersedes v2.3.1 and carries two changes; v2.3.2 was released in the repository but never deposited separately, so its correction is included here.

v2.3.2 (erratum, 2026-07-26) — a single axiom-conformance correction to cluster #5 Man in the Middle. The generic-vulnerability field is retightened from "The lack of sufficient control, integrity protection, or confidentiality over the communication channel/path" to "The lack of sufficient control over the communication path", removing consequence-side (confidentiality/integrity) and control-side vocabulary from a cause-side field per Axiom III (threats are causes, not outcomes) and Axiom V (control failure is not a threat). Cluster identity, identifiers (#5 / TLCTC-05.00), definition, attacker's view, topology, and all boundary tests are unchanged.

v2.4 (clarification, 2026-07-28) — a single clarifying, backward-compatible change to the interaction model. Axiom II is restated from "All networked systems can be abstracted as client-server interaction" to "All system interactions, networked or intra-system, can be abstracted as client-server interaction", removing a reading in which a network was taken as a precondition and intra-system privilege interfaces fell outside the model. R-ROLE gains a matching sentence: roles are established by call direction at any interface, including intra-system privilege interfaces (syscall, hypercall, IPC, driver IOCTL). A kernel handling a crafted syscall from a lower-privileged process is in server-role (#2). Per R-INTRA-7 the boundary crossing itself remains an observability annotation and is not a classification input. No cluster identity, ID, definition, attacker's view, generic vulnerability, or topology changed; the axiom set is unchanged in count and numbering; no rule was added or removed. Classifications valid under v2.3.2 remain valid under v2.4.

Canonical dictionary: json-schemas/layer-1/tlctc-framework.v2.4.json. The v2.3 dictionary is retained unchanged as the frozen record for classifications made under 2.3.x. Full rationale and before/after tables: documentation/tlctc-v2.3-traceability.md.

Note on files: the initial 3 August 2026 deposit of version 2.4 (10.5281/zenodo.21772058) inadvertently carried the TLCTC application paper PDF instead of the core paper. This deposit carries the correct core paper; all other metadata is unchanged.

Files

tlctc-v2.3-core.pdf

Files (702.5 kB)

Name Size Download all
md5:141ea302056b4135fe5c4a57c4a4f439
702.5 kB Preview Download

Additional details

Related works

Is described by
Project milestone: https://www.tlctc.net (URL)
Is supplemented by
Dataset: https://github.com/Barnes70/TLCTC (URL)

Software

Repository URL
https://github.com/Barnes70/TLCTC
Development Status
Active