An Automated Framework for Extracting Reachable Attack Chains from Cyber Threat Intelligence Reports
一种从网络威胁情报报告中提取可达攻击链的自动化框架
机构 * Guangdong Provincial Key Laboratory of Novel Security Intelligence Technologies(广东新型安全情报技术重点实验室) ; School of Computer Science and Technology(计算机科学与技术学院) ; Harbin Institute of Technology(哈尔滨工业大学) ; New Network Research Department(新网络研究部) ; Peng Cheng Laboratory(鹏城实验室) ; Great Bay University(大湾区大学)
专题命中 规划推理 :reasoning(abstract);分类 cs.AI
AI总结 该研究针对CTI报告非结构化无法用于自动化攻击路径推理的问题,提出将攻击步骤建模为含条件和行为的单元,经多阶段管道结合大语言模型提取并规范化,编译成规则推理,在数据集上有更好表现,能有效提取可达攻击链。
Comments 16 pages, 3 figures