STINER:从X平台自动提取战略网络威胁情报
STINER: Automated Extraction of Strategic Cyber Threat Intelligence from X
AI总结:
该研究针对社交媒体CTI提取难题,提出STINER分类体系与语料库,经测试DarkBERT等领域适配编码器表现最优,还利用STINER-DarkBERT完成了2025年上半年欧洲威胁态势分析。
AI中文摘要:
战略网络威胁情报(CTI)聚焦于高层级洞察,例如识别受攻击的目标行业、将攻击归因于特定勒索软件组织、评估数据泄露规模。当前,X(前身为Twitter)已成为此类情报的最快来源,往往在官方供应商报告发布前数天就会发布实时泄露公告。将这些原始信息转化为可操作的情报需要应对复杂的语言环境。传统命名实体识别(NER)模型难以解析社交媒体中非正式且高度不规则的方言,这为自动化防御系统造成了盲区。为解决这一挑战,我们提出STINER,即用于从社交媒体流中提取战略情报的分类体系和专家标注语料库。我们构建了包含2100条真实告警的高质量专家标注数据集,并提出以威胁行为者、行业、位置等战略枢轴为核心的8类实体细粒度分类体系。我们在12种评估配置下对9种模型进行了基准测试,涵盖通用编码器、领域适配编码器、开放模式提取模型以及零样本和微调设置下的生成式大语言模型。DarkBERT等领域适配编码器达到了89.33%的严格F1值,其性能优于通用基线模型和微调大语言模型,且推理延迟显著更低。借助STINER-DarkBERT,我们对2025年上半年欧洲威胁态势开展了分析,结果与官方关于主要目标的报告一致,同时凸显了西班牙攻击的独特可见性特征,还展示了社交媒体驱动的提取如何在SafePay勒索软件活动被供应商威胁态势报告回溯定性前,揭示其早期信号。
英文摘要:
Strategic Cyber Threat Intelligence (CTI) focuses on high-level insights, such as identifying targeted industries, attributing attacks to specific ransomware groups, and assessing the scale of data loss. Today, X (formerly Twitter) has become the fastest source for this intelligence, often hosting real-time breach announcements days before formal vendor reports. Converting this raw chatter into actionable intelligence requires navigating a complex linguistic landscape. Conventional Named Entity Recognition (NER) models struggle to parse the informal and highly irregular dialect of social media, creating a blind spot for automated defense systems. To address this challenge, we introduce STINER, a taxonomy and expert-annotated corpus for extracting strategic intelligence from social media streams. We construct a high-quality, expert-annotated dataset of 2,100 real-world alerts and propose a granular taxonomy of eight entity types centered on strategic pivots such as Threat Actor, Sector, and Location. We benchmark nine models across 12 evaluated configurations, spanning general-purpose and domain-adapted encoders, open-schema extraction, and generative LLMs in both zero-shot and fine-tuned settings. Domain-adapted encoders such as DarkBERT reach a strict F1-score of 89.33%, outperforming both general-purpose baselines and fine-tuned Large Language Models, which additionally incur substantially higher inference latency. Leveraging STINER-DarkBERT, we conduct a European threat landscape analysis for H1 2025. Our results align with official reporting on major targets while highlighting the distinct visibility profile of attacks in Spain, and illustrate how social-media-driven extraction can surface early signals of the SafePay ransomware campaign prior to its retrospective characterization in vendor threat landscape reports.