arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

DisCTI:谁需要及时了解?面向特定行业的网络威胁情报自动分发

DisCTI: Who Needs to Know Timely? Automated Sector-Aware Cyber Threat Intelligence Dissemination

Fajar Wijitrisnanto, Alsharif Abuadbba, Yansong Gao, Nan Wu

arXiv 2608.27967首次发表:更新:

AI 中文总结

本研究针对CTI行业映射缺失问题,构建872条带标签CTI数据集,用BERT实现CTI到行业的自动映射,在自定义数据集上获宏平均F1=0.89、汉明损失0.055,提升CTI分发的时效性与针对性。

AI 中文摘要

及时分发网络威胁情报(CTI)对组织发起快速有效的事件响应至关重要。当有效的CTI在正确的时间传递给正确的行业时,通常可以遏制或减轻相同的攻击。然而,当今快速扩张的CTI格局让分析人员不堪重负,他们必须筛选大量异构的信息流。现有平台如恶意软件信息共享平台(MISP)提供行业标签功能(例如能源、金融、政府),但实际上这些功能大多未被映射(98%的事件未被分类)。这种缺乏自动化和及时的行业映射的情况严重限制了共享情报的操作价值,使得关键信息基础设施行业的组织尤其面临风险。为解决这一差距,我们将面向行业的CTI分制定义为多标签分类问题。利用CTI结构和特定行业威胁模式的深度领域知识,我们从威胁情报平台(TIP)构建了一个包含872个带行业标签的CTI事件的新型数据集。随后我们应用基于Transformer的模型BERT,将CTI事件自动映射到对应行业。利用结构化威胁信息表达式(STIX)格式实现跨平台互操作性,我们的方法在自定义数据集上达到了宏平均F1分数0.89,汉明损失0.055,即94.5%的单个行业标签分配是正确的。这些结果不仅证明了面向行业的自动化CTI分发的可行性,还强调了将专家领域知识嵌入机器学习设计如何填补威胁情报流程中的关键空白,从而实现更快速、与情境相关的防御行动。

英文摘要

The timely dissemination of cyber threat intelligence (CTI) is critical for organizations to mount swift and effective incident response. When valid CTI is delivered to the right sector at the right time, identical attacks can often be contained or mitigated. However, today's rapidly expanding CTI landscape overwhelms analysts, who must sift through massive and heterogeneous feeds. Existing platforms such as the Malware Information Sharing Platform (MISP) provide sector tagging features (e.g., energy, finance, government), but in practice, these remain largely unmapped (98% of events are left uncategorized). This lack of automated and timely sector mapping severely limits the operational value of shared intelligence, leaving organizations that belong especially to the critical information infrastructure sector exposed. To address this gap, we formulate sector-targeted CTI dissemination as a multilabel classification problem. Leveraging deep field knowledge of CTI structures and sector-specific threat patterns, we construct a novel data set of 872 sector-labelled CTI events from a threat intelligence platform (TIP). We then apply BERT, a transformer-based model, to automate the mapping of CTI events to sectors. Using the structured threat information expression (STIX) format for cross-platform interoperability, our approach achieves a macro-averaged F1-score of 0.89 at a Hamming loss of 0.055 on the custom dataset, i.e. 94.5% of individual sector-label assignments are correct. These results not only demonstrate the feasibility of sector-aware, automated CTI dissemination but also highlight how embedding expert field knowledge into machine learning design fills a crucial gap in the threat intelligence pipeline, enabling faster and context-relevant defensive action.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑