arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

用GraphRAG实现网络威胁情报的操作化

Operationalizing Cyber Threat Intelligence with GraphRAG

Atul Kabra, Prakhar Paliwal, Manjesh K. Hanawal

arXiv 2608.13050首次发表:更新:

发表机构

Indian Institute of Technology Bombay; IIT Bombay; MLiONS(印度孟买印度理工学院; 印度理工学院孟买分校; MLiONS)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本研究对比微软GraphRAG与Naive RAG,发现GraphRAG生成的网络威胁情报检测方案,在攻击线索轮换后保持率远高于后者,能依赖更难规避的持久线索,为自动生成SOC狩猎方案提供了架构基础。

AI 中文摘要

当安全研究人员发布一份网络攻击报告时,检测工程师需要将其转化为可执行的检测规则。实际上,大多数自动化尝试仅从报告中提取最简单的线索——恶意IP地址、域名和文件哈希值——并将其转化为阻止列表。这是一种薄弱的策略,因为攻击者可以在几小时或几天内更改这些简单线索,导致生成的检测规则几乎在部署后立即失效。安全团队用“痛苦金字塔”(Pyramid of Pain)来描述这一思路。本项目探究将报告输入知识图谱检索系统(微软GraphRAG)而非标准向量相似度检索系统(Naive RAG),是否能生成更多依赖该金字塔顶层持久线索的检测方案。两个系统获得相同的报告、相同的生成指令和相同的语言模型来撰写最终方案,仅检索步骤不同。在对一份APT28报告的详细案例研究中,当报告中的所有IP地址、域名和文件哈希值都被轮换后,GraphRAG方案的检测保持率为100%,而Naive RAG方案的检测保持率仅为29%。在来自四个供应商的九份真实CTI报告中重复对比,也证实了相同模式:即使两个系统的总得分接近,GraphRAG方案始终能达到痛苦金字塔中更高、更难规避的层级。研究结果支持将感知知识图谱的检索作为自动生成可部署于安全运营中心(SOC)的狩猎方案的正确架构基础,同时表明生成提示的措辞与检索后端本身几乎同等重要。

英文摘要

When a security researcher publishes a report on a cyberattack, detection engineers are supposed to turn it into working detection rules. In practice, most automated attempts at this only extract the simplest clues from the report --- bad IP addresses, domain names, and file hashes --- and turn them into block lists. This is a weak strategy, because attackers can change these simple clues within hours or days, so the resulting detections stop working almost as soon as they are deployed. Security teams describe this idea with the Pyramid of Pain. This project asks whether feeding a report into a knowledge-graph retrieval system, Microsoft GraphRAG, rather than a standard vector-similarity retrieval system (Naive RAG), produces detection plans that rely more on these durable, top-of-pyramid clues. Both systems are given the same report, the same generation instructions, and the same language model to write the final plan; only the retrieval step differs. In a detailed case study of one APT28 report, the GraphRAG plan kept firing at 100\% of its detections after every IP address, domain, and file hash in the report was rotated, while the Naive RAG plan kept firing at only 29\%. Repeating the comparison across nine real CTI reports from four vendors confirms the same pattern: GraphRAG plans consistently reach higher, harder-to-evade levels of the pyramid, even when the two systems end up close on total score. The results support treating knowledge-graph-aware retrieval as the architecturally correct foundation for automatically generating SOC-deployable hunting plans, while showing that the wording of the generation prompt matters almost as much as the retrieval back-end itself.

Comments12 pages

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑