发表机构
UC Santa Barbara; UIUC; Georgia Tech; Purdue University; University of Chicago; Broadcom; University of Virginia(加州大学圣塔芭芭拉分校; 伊利诺伊大学厄巴纳-香槟分校; 佐治亚理工学院; 普渡大学; 芝加哥大学; 博通; 弗吉尼亚大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
该研究通过文献调查和从业者调研梳理CTI生成与共享的阶段与挑战,探究LLM在各步骤的可行性,发现其需专家监督并提出自动化研究方向。
AI 中文摘要
网络威胁情报(CTI)对于保护关键任务基础设施至关重要,但将原始攻击证据转化为可共享CTI的过程仍呈碎片化且研究不足。我们对学术论文进行了文献调查,将CTI生命周期划分为三个阶段:威胁数据收集、CTI生成与共享、CTI消费。第一和第三阶段在文献中已有充分体现,而仅有少量论文关注CTI生成与共享。为了解该阶段的实际实施情况,我们对多个经常生成和共享CTI的组织的从业者进行了调查。他们描述了一个主要为手动的流程,存在四个反复出现的挑战:防止敏感信息暴露、从嘈杂的攻击数据中提取指标、将观察到的行为与标准化战术、技术与流程(TTPs)相关联,以及将CTI转换为共享平台所需的格式。基于从业者调查的见解,我们将CTI生成与共享阶段划分为四个步骤:情报提取、归一化与丰富、编码、分发。随后,我们开展了试点研究,探究当前大型语言模型(LLMs)在每个步骤中的可行性。试点研究表明,LLMs可在四个步骤中为分析师提供协助,但模型仅能恢复证据中包含的一小部分指标,难以将每个主张与提供的证据挂钩,且无法判断哪些内容能保持共享情报对接收者的实用性。因此,每个步骤都需要专家监督。基于这些观察,我们提出了自动化可共享情报生成的三个研究方向。
英文摘要
Cyber Threat Intelligence (CTI) is essential for defending mission-critical infrastructure, yet the process of transforming raw attack evidence into shareable CTI remains fragmented and understudied. We conduct a literature survey of academic papers, organizing the CTI lifecycle into three stages: Threat Data Collection, CTI Generation and Sharing, and CTI Consumption. The first and third stages are well represented in the literature, whereas only a small number of papers address CTI Generation and Sharing. To learn how this stage is practiced, we survey practitioners across multiple organizations who routinely generate and share CTI. They describe a largely manual process with four recurring challenges: preventing the exposure of sensitive information, extracting indicators from noisy attack data, correlating observed behavior with standardized tactics, techniques, and procedures (TTPs), and translating CTI into the formats that sharing platforms require. Using the insights from the practitioner survey, we divide the CTI Generation and Sharing stage into four steps: Intelligence Extraction, Normalization and Enrichment, Codification, and Distribution. We then conduct pilot studies that probe the feasibility of current Large Language Models (LLMs) for each step. The pilot studies show that LLMs can assist an analyst in each of the four steps. However, the models recover only a fraction of the indicators the evidence contains, struggle to ground every claim in the supplied evidence, and do not judge what keeps shared intelligence useful to its recipients. Each step therefore requires expert supervision. Based on these observations, we derive three research directions for automating the production of shareable intelligence.