BEACON:面向网络威胁情报的行为锚定跨源知识图谱构建
BEACON: Behavior-Anchored Cross-Source Knowledge Graph Construction for Cyber Threat Intelligence
浏览论文内容
中文总结 AI 辅助
该研究提出BEACON框架,基于LLM结合MITRE ATT&CK实现跨源CTI知识图谱构建,构建了两个标注数据集,性能优于基线方法至少9%至23%。
中文摘要 AI 辅助
网络威胁情报(CTI)是现代网络防御的基础,但大部分CTI存在于非结构化报告中,其规模和异质性远超人工分析能力,因此研究如何从CTI报告自动构建知识图谱成为重要方向。然而现有方法主要提取单份报告内的部分信息,未探索跨源场景——同一威胁在不同来源中被赋予不相关名称。本文的核心见解是:攻击行为一旦映射到MITRE ATT&CK(标准化攻击技术目录),即可作为报告其余内容的锚点;攻击行为是报告描述的对抗行动,而上下文实体(如威胁行为者、攻击活动、受影响产品)和入侵指标(IoCs,如IP地址)是攻击行为的参与者与痕迹,将它们锚定到这些攻击行为后,每份报告的知识图谱可置于同一规范空间。我们将该见解实现为BEACON,一种基于大语言模型(LLM)的跨源CTI知识图谱构建框架。该框架第一阶段采用“先提议再验证”范式,将每份报告提取为知识图谱,将候选内容锚定到报告证据和官方ATT&CK定义,以抑制LLM的错误分类和幻觉;第二阶段采用分层对齐策略合并这些图谱,按确定性递减顺序应用信号,从字符级、语义相似度到重叠技术邻域,随着合并操作汇聚邻域不断迭代。由于现有基准未将实体与技术锚点关联,也未提供跨源对齐的真实标注,我们从34个来源构建并发布了两个人工标注数据集:据我们所知,这是最大的报告级CTI提取数据集(含8395个元素),也是首个跨源整合数据集(含3487个元素)。在这些数据集上,BEACON的性能分别优于所有基线方法至少23%和9%。
英文摘要
Cyber threat intelligence (CTI) is foundational to modern cyber defense, yet much of it resides in unstructured reports whose volume and heterogeneity far exceed manual analysis, motivating research on automatically constructing knowledge graphs from CTI reports. However, existing approaches mainly extract partial information within a single report, leaving the cross-source setting unexplored, where the same threat is given unrelated names. Our key insight is that attack behaviors, once mapped to MITRE ATT&CK (a standardized catalog of attack techniques), can anchor the rest of a report. Attack behaviors are the adversarial actions a report describes, while contextual entities (e.g., threat actors, campaigns, and affected products) and Indicators of Compromise (IoCs; e.g., IP addresses) are their participants and traces. Attaching them to these anchors places every per-report graph in one canonical space. We realize this insight in BEACON, an LLM-driven framework for cross-source CTI knowledge graph construction. Its first stage extracts each report into a graph under a propose-then-verify paradigm, grounding candidates in report evidence and official ATT&CK definitions, to suppress LLM misclassification and hallucination. Its second stage merges these graphs with a hierarchical alignment strategy that applies signals in decreasing order of determinism, from character-level and semantic similarity to overlapping technique neighborhoods, iterating as merges pool neighborhoods. No existing benchmark links entities to technique anchors or provides cross-source alignment ground truth. We therefore construct and release two human-annotated datasets from 34 sources: to our knowledge the largest for report-level CTI extraction (8,395 elements) and the first for cross-source consolidation (3,487). On them, BEACON outperforms all baselines by at least 23% and 9%, respectively.