TRACE-CTI:利用知识图谱对TTP声明进行可审计的提取后治理
TRACE-CTI: Auditable Post-Extraction Governance of TTP Claims with Knowledge Graphs
浏览论文内容
中文总结 AI 辅助
研究针对网络威胁情报报告提取器输出不可靠且缺乏相关依据的问题,提出TRACE-CTI框架,通过保留预测、聚合断言等操作进行治理。经实验评估,该框架能提升精度,还能直接回答多个相关问题,支持对TTP声明的可审计治理。
中文摘要 AI 辅助
安全运营中心越来越依赖于将网络威胁情报报告自动映射到MITRE ATT&CK,但提取器输出仍可能出错,且存储时往往缺少判断单个映射是否可信所需的证据、出处和验证历史。我们提出了TRACE-CTI,这是一个提取后声明治理框架,它保留运行级预测,将其聚合为配置级图断言,将设置去重后的确证具体化为共识断言,只公开有合规政策验证依据支持的图断言。该框架保留了原生证据粒度、完整提取出处、版本化信任决策和无损撤销历史。我们在两个包含65份报告和5303个句子的公共CTI语料库上评估TRACE-CTI,使用检索器和生成器家族的2×3受控矩阵,跨六个图版本逐步摄入。所有设置都无需修改模式即可合并;出处路径保持完整,操作范围保持不相交,每个可信图断言都有有效的合格验证依据。跨生成器家族设置对的输出多样性比同家族对更大。在最终图状态下,将设置支持从k≥1增加到六个设置一致,使与黄金标准对齐的精度从25.3%提高到90.6%,而召回率从88.2%降至16.3%。该图还直接回答了关于出处、信任、版本控制、依赖、分歧和审查队列的七个问题,而评估的最小扁平输出在不进行丰富或重新处理的情况下无法完全回答这些问题。这些结果支持对提取的TTP声明进行明确、可审计的治理;观察到的确证轨迹具有描述性,但未建立统计独立性或因果模型家族效应。
英文摘要
Security Operations Centers increasingly rely on automated mapping of Cyber Threat Intelligence reports to MITRE ATT&CK, yet extractor outputs remain fallible and are often stored without the evidence, provenance, and validation history needed to decide whether an individual mapping should be trusted. We present TRACE- CTI, a post-extraction claim-governance framework that preserves run-level Predictions, aggregates them into configuration-level GraphAssertions, materializes setup-deduplicated corroboration as ConsensusAssertions, and exposes only GraphAssertions backed by policy-compliant validation grounds. The framework retains native evidence granularity, complete extraction provenance, versioned trust decisions, and non-destructive revocation history. We evaluate TRACE-CTI on two public CTI corpora comprising 65 reports and 5,303 sentences, using a controlled 2 x 3 matrix of retrievers and generator families, incrementally ingested across six GraphVersions. All setups are incorporated without schema modification; provenance paths remain complete, operational scopes remain disjoint, and every trusted GraphAssertion has an active qualifying validation ground. Cross-generator-family setup pairs exhibit greater output diversity than same-family pairs. At the final graph state, increasing setup support from k >= 1 to six-setup unanimity raises gold-aligned precision from 25.3% to 90.6%, while recall decreases from 88.2% to 16.3%. The graph also directly answers seven questions about provenance, trust, versioning, dependency, disagreement, and review-queue that the evaluated minimal flat output cannot fully answer without enrichment or reprocessing. These results support explicit, auditable governance of extracted TTP claims; the observed corroboration trajectory is descriptive and does not establish statistical independence or a causal model-family effect.
发表机构
- CASD – School of Advanced Defense Studies(高级国防研究学院)
机构由 AI 辅助整理,请以论文原文为准。