发表机构
Binghamton University, State University of New York; Oakland University; University of Iowa(纽约州立大学宾汉姆顿分校; 奥克兰大学; 爱荷华大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
POLAR利用LLM合成真实世界网络证据,通过推断严重性和利用信号进行威胁优先级排序,并关联修复知识以支持缓解,在零日场景中优于基线。
AI 中文摘要
网络威胁分析日益依赖于分布在供应商公告、漏洞数据库和威胁情报源中的证据。将这些碎片化的观察转化为及时决策,需要模型将技术严重性与不断演变的利用证据和可用的防御措施联系起来。我们提出了POLAR,一个基于LLM的框架,用于将真实世界的网络证据合成为以威胁为中心的评估,以支持优先级排序和缓解。POLAR首先解开重叠的事件,并将每个威胁锚定到来源关联的证据上。对于优先级排序,它从网络证据中推断严重性指标,并将所得评估与按时间排序的利用信号相结合,以估计近期利用可能性。对于缓解,它将合成的威胁数据与权威的修复知识联系起来,并根据威胁紧迫性和操作约束组织适用的行动。我们在从公共资源收集的真实世界漏洞证据上评估了POLAR,并将其与多个基线进行了比较。在异构事件和零日漏洞场景中,POLAR改善了威胁排名和缓解检索,同时生成了支持分析师检查的证据关联的中间评估。结果确立了证据合成作为基于LLM的网络决策支持在相关安全任务中的实用基础。
英文摘要
Cyber threat analysis increasingly depends on evidence distributed across vendor advisories, vulnerability databases, and threat intelligence sources. Turning these fragmented observations into timely decisions requires models to connect technical severity with evolving exploitation evidence and available defensive actions. We present POLAR, an LLM-powered framework for synthesizing real-world cyber evidence into threat-centric assessments for prioritization and mitigation. POLAR first disentangles overlapping incidents and grounds each threat in source-linked evidence. For prioritization, it infers severity metrics from cyber evidence and combines the resulting assessment with temporally ordered exploitation signals to estimate near-term exploitation likelihood. For mitigation, it links the synthesized threat data to authoritative remediation knowledge and organizes applicable actions according to threat urgency and operational constraints. We evaluate POLAR on real-world vulnerability evidence collected from public resources and compare it with multiple baselines. Across heterogeneous incidents and zero-day settings, POLAR improves threat ranking and mitigation retrieval while producing evidence-linked intermediate assessments that support analyst inspection. The results establish evidence synthesis as a practical foundation for LLM-based cyber decision support across related security tasks.