paper-with-me

Papers

TINKER: A framework for Open source Cyberthreat Intelligence

2021-02-10 · Nidhi Rastogi, Sharmishtha Dutta, Mohammed J. Zaki, Alex Gittens, Charu Aggarwal

Threat intelligence on malware attacks and campaigns is increasingly being shared with other security experts for a cost or for free. Other security analysts use this intelligence to inform them of indicators of compromise, attack techniques, and preventative actions. Security analysts prepare threat analysis reports after investigating an attack, an emerging cyber threat, or a recently discovered vulnerability. Collectively known as cyber threat intelligence (CTI), the reports are typically in an unstructured format and, therefore, challenging to integrate seamlessly into existing intrusion detection systems. This paper proposes a framework that uses the aggregated CTI for analysis and defense at scale. The information is extracted and stored in a structured format using knowledge graphs such that the semantics of the threat intelligence can be preserved and shared at scale with other security analysts. Specifically, we propose the first semi-supervised open-source knowledge graph-based framework, TINKER, to capture cyber threat information and its context. Following TINKER, we generate a Cyberthreat Intelligence Knowledge Graph (CTI-KG) and demonstrate the usage using different use cases.

📄 PDF Abstract BibTeX arXiv:2102.05571

Code (0)

등록된 구현이 없습니다.

Tasks

Information RetrievalIntrusion DetectionKnowledge GraphsNamed Entity Recognition (NER)Relation Extraction

Similar Papers 제목 키워드 기반

Malware Knowledge Graph Generation

2021-02-10 · Sharmishtha Dutta, Nidhi Rastogi, Destin Yee, Chuqiao Gu 외

Cyber threat and attack intelligence information are available in non-standard format from heterogeneous sources. Comprehending them and utilizing them for threat intelligence extraction requires engaging security expert…

Graph GenerationKnowledge Graphs

Looking Beyond IoCs: Automatically Extracting Attack Patterns from External CTI

2022-11-01 · Md Tanvirul Alam, Dipkamal Bhusal, Youngja Park, Nidhi Rastogi

Public and commercial organizations extensively share cyberthreat intelligence (CTI) to prepare systems to defend against existing and emerging cyberattacks. However, traditional CTI has primarily focused on tracking kno…

Cyberthreat Detection from Twitter using Deep Neural Networks

2019-04-01 · Nuno Dionísio, Fernando Alves, Pedro M. Ferreira, Alysson Bessani

To be prepared against cyberattacks, most organizations resort to security information and event management systems to monitor their infrastructures. These systems depend on the timeliness and relevance of the latest upd…

Managementnamed-entity-recognitionNamed Entity RecognitionNamed Entity Recognition (NER)

CyberThreat-Eval: Can Large Language Models Automate Real-World Threat Research?

2026-03-10 · Xiangsen Chen, Xuan Feng, Shuo Chen, Matthieu Maitre 외 arxiv

Analyzing Open Source Intelligence (OSINT) from large volumes of data is critical for drafting and publishing comprehensive CTI reports. This process usually follows a three-stage workflow -- triage, deep search and TI d…

Mining Temporal Attack Patterns from Cyberthreat Intelligence Reports

2024-01-03 · Md Rayhanur Rahman, Brandon Wroblewski, Quinn Matthews, Brantley Morgan 외

Defending from cyberattacks requires practitioners to operate on high-level adversary behavior. Cyberthreat intelligence (CTI) reports on past cyberattack incidents describe the chain of malicious actions with respect to…