LOCALINTEL:从全球与本地网络知识生成组织化威胁情报
LOCALINTEL: Generating Organizational Threat Intelligence from Global and Local Cyber Knowledge
- Mississippi State University(密西西比州立大学)
- The University of Texas at El Paso(德克萨斯大学埃尔帕索分校)
- University of Maryland Baltimore County(马里兰大学巴尔的摩县分校)
机构由 AI 辅助整理,请以论文原文为准。
AI总结:
LocalIntel 框架利用 LLM 结合全球零日漏洞报告与组织本地知识库,自动生成组织特定威胁情报和缓解策略,准确率达 93%。
AI中文摘要:
安全运营中心(SoC)分析师从公开可访问的全球威胁存储库中收集威胁报告,并根据其组织的需求定制信息,例如制定威胁情报和安全策略。他们还依赖组织内部存储库,这些存储库充当私有的本地知识数据库。这些本地知识数据库存储可信的网络情报、关键运营和基础设施细节。SoC 承担着一项劳动密集型的手动任务,即利用这些全球威胁存储库和本地知识数据库来创建组织特定的威胁情报和缓解策略。最近,大型语言模型(LLMs)已展现出高效处理多样化知识来源的能力。我们利用这一能力来自动化这种组织特定的威胁情报生成。我们提出 LocalIntel,一个新颖的自动化威胁情报情境化框架,该框架从全球威胁存储库中检索零日漏洞报告,并利用其本地知识数据库来确定影响和缓解策略,以提醒并协助 SoC 分析师。LocalIntel 包含两个关键阶段:知识检索和情境化。定量和定性评估表明,其在生成组织威胁情报方面有效性高达 93% 的准确率,评估者间一致性为 64%。
英文摘要:
Security Operations Center (SoC) analysts gather threat reports from openly accessible global threat repositories and tailor the information to their organization's needs, such as developing threat intelligence and security policies. They also depend on organizational internal repositories, which act as private local knowledge database. These local knowledge databases store credible cyber intelligence, critical operational and infrastructure details. SoCs undertake a manual labor-intensive task of utilizing these global threat repositories and local knowledge databases to create both organization-specific threat intelligence and mitigation policies. Recently, Large Language Models (LLMs) have shown the capability to process diverse knowledge sources efficiently. We leverage this ability to automate this organization-specific threat intelligence generation. We present LocalIntel, a novel automated threat intelligence contextualization framework that retrieves zero-day vulnerability reports from the global threat repositories and uses its local knowledge database to determine implications and mitigation strategies to alert and assist the SoC analyst. LocalIntel comprises two key phases: knowledge retrieval and contextualization. Quantitative and qualitative assessment has shown effectiveness in generating up to 93% accurate organizational threat intelligence with 64% inter-rater agreement.