arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

从沙箱到执行:面向关键基础设施的置信度限定威胁情报

From Sandbox to Enforcement: Confidence-Qualified Threat Intelligence for Critical Infrastructure

Nikolaos Kekatos, Mihaela Curcă, Georgios Koutidis, Mihai Nena, Tom Nianios, Robert-Ştefan Şandru, Michael Ioannou, Charalambos Bratsas

arXiv 2610.07310首次发表:更新:

发表机构

Clone Systems; Romanian National Cyber Security Directorate (DNSC); Bolton Technologies; International Hellenic University(克隆系统公司; 罗马尼亚国家网络安全局(DNSC); 博尔顿技术公司; 国际希腊大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

针对关键基础设施威胁数据难以转化为可操作情报的问题,提出CG-CTI管道,将沙箱输出转为STIX 2.1并关联传感器,以置信度门控自动化执行,经评估验证其有效性与可审计性。

AI 中文摘要

保卫关键基础设施的安全运营中心和国家级事件响应团队收集了海量威胁数据,却难以将其转化为可操作的情报。恶意软件沙箱能产生详细的行为证据,但作为一份庞大且未排序的报告,其置信度并未明确说明。我们提出了CG-CTI,一个运营管道,将实时沙箱输出(CAPEv2)转换为STIX 2.1,在知识图谱中与关键基础设施的其他传感器进行关联,并为每个情报对象附加一个明确的置信度状态,该状态源自来源、跨源佐证和观察持久性。此状态控制自动化执行:仅经过佐证的情报有资格进行自动化执行,而低置信度对象则被路由至分析师审查或保留为背景信息。随后,一个基于语言模型的阶段对置信度限定的证据进行叙述,其中每个陈述要么引用一个支持对象,要么标记为不支持,从而在分析师审查前移除虚构的引用。我们在CYBERGUARD项目中实施了CG-CTI,其联盟包括罗马尼亚国家网络安全局,并针对标记的恶意软件语料库在实时沙箱上进行了评估,测量了转换有效性、指标产出、技术覆盖、佐证、执行资格、延迟和摘要接地性。CG-CTI将零散的沙箱输出转化为经过佐证、置信度排序且可审计的情报,用于关键基础设施防御。

英文摘要

Security operations centres and national incident-response teams defending critical infrastructure collect abundant threat data yet struggle to turn it into actionable intelligence. A malware sandbox produces detailed behavioural evidence, but as a large, unranked report whose confidence is unstated. We present CG-CTI, an operational pipeline that converts live sandbox output (CAPEv2) into STIX 2.1, correlates it in a knowledge graph with other critical-infrastructure sensors, and attaches to every intelligence object an explicit confidence status derived from provenance, cross-source corroboration, and observation durability. This status gates automated action: only corroborated intelligence is eligible for automated enforcement, while lower-confidence objects are routed to analyst review or kept as context. A grounded language-model stage then narrates the confidence-qualified evidence, where each statement either cites a supporting object or is marked unsupported, so fabricated references are removed before analyst review. We implement CG-CTI within the CYBERGUARD project, whose consortium includes Romania's national cyber-security directorate, and evaluate it against the live sandbox on a labelled malware corpus, measuring conversion validity, indicator yield, technique coverage, corroboration, enforcement eligibility, latency, and summary grounding. CG-CTI turns fragmented sandbox output into corroborated, confidence-ranked, and auditable intelligence for critical-infrastructure defence.

Comments20 pages, 3 figures. Accepted at the 21st International Conference on Critical Information Infrastructures Security (CRITIS 2026)

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑