paper-with-me

Papers

AnnoCTR: A Dataset for Detecting and Linking Entities, Tactics, and Techniques in Cyber Threat Reports

2024-04-11 · Lukas Lange, Marc Müller, Ghazaleh Haratinezhad Torbati, Dragan Milchevski, Patrick Grau, Subhash Pujari, Annemarie Friedrich

Monitoring the threat landscape to be aware of actual or potential attacks is of utmost importance to cybersecurity professionals. Information about cyber threats is typically distributed using natural language reports. Natural language processing can help with managing this large amount of unstructured information, yet to date, the topic has received little attention. With this paper, we present AnnoCTR, a new CC-BY-SA-licensed dataset of cyber threat reports. The reports have been annotated by a domain expert with named entities, temporal expressions, and cybersecurity-specific concepts including implicitly mentioned techniques and tactics. Entities and concepts are linked to Wikipedia and the MITRE ATT&CK knowledge base, the most widely-used taxonomy for classifying types of attacks. Prior datasets linking to MITRE ATT&CK either provide a single label per document or annotate sentences out-of-context; our dataset annotates entire documents in a much finer-grained way. In an experimental study, we model the annotations of our dataset using state-of-the-art neural models. In our few-shot scenario, we find that for identifying the MITRE ATT&CK concepts that are mentioned explicitly or implicitly in a text, concept descriptions from MITRE ATT&CK are an effective source for training data augmentation.

📄 PDF Abstract BibTeX arXiv:2404.07765

Code (1)

boschresearch/anno-ctr-lrec-coling-2024 공식 구현

Tasks

Data Augmentation

Methods 이 논문이 사용한 방법론

AWARE We propose to theoretically and empirically examine the effect of incorporating weighting schemes into walk-aggregating GNNs. To this end, we propose a simple, interpretable, and…

Similar Papers 제목 키워드 기반

CVE-TTP KG: Knowledge Graph Linking Software Vulnerabilities to Attack Behaviors

2026-06-30 · Swati Yadav, Dincy R. Arikkat, Basant Agarwal, Serena Nicolazzo 외 arxiv

In the evolving threat landscape, adversaries exploit software vulnerabilities to launch sophisticated attacks, challenging traditional defenses. Although databases like CVE and NVD provide detailed technical information…

Relation Extraction

NASTyLinker: NIL-Aware Scalable Transformer-based Entity Linker

2023-03-08 · Nicolas Heist, Heiko Paulheim

Entity Linking (EL) is the task of detecting mentions of entities in text and disambiguating them to a reference knowledge base. Most prevalent EL approaches assume that the reference knowledge base is complete. In pract…

Entity Linking

Benchmarking the Extraction and Disambiguation of Named Entities on the Semantic Web

2014-05-01 · LREC 2014 5 · Giuseppe Rizzo, Marieke van Erp, Rapha{\"e}l Troncy

Named entity recognition and disambiguation are of primary importance for extracting information and for populating knowledge bases. Detecting and classifying named entities has traditionally been taken on by the natural…

BenchmarkingEntity Linkingnamed-entity-recognitionNamed Entity Recognition+1

TREC: APT Tactic / Technique Recognition via Few-Shot Provenance Subgraph Learning

2024-02-23 · Mingqi Lv, HongZhe Gao, Xuebo Qiu, Tieming Chen 외

APT (Advanced Persistent Threat) with the characteristics of persistence, stealth, and diversity is one of the greatest threats against cyber-infrastructure. As a countermeasure, existing studies leverage provenance grap…

Few-Shot Learning

An Unsupervised Domain-Independent Framework for Automated Detection of Persuasion Tactics in Text

2019-12-13 · Rahul Radhakrishnan Iyer, Katia Sycara

With the increasing growth of social media, people have started relying heavily on the information shared therein to form opinions and make decisions. While such a reliance is motivation for a variety of parties to promo…

MisinformationMulti-class ClassificationSentence