ThreatKG: An AI-Powered System for Automated Open-Source Cyber Threat Intelligence Gathering and Management

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Gao, Peng, Liu, Xiaoyuan, Choi, Edward, Ma, Sibo, Yang, Xinyu, Song, Dawn
Format: Preprint
Published: 2022
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866913568153141248
author Gao, Peng
Liu, Xiaoyuan
Choi, Edward
Ma, Sibo
Yang, Xinyu
Song, Dawn
author_facet Gao, Peng
Liu, Xiaoyuan
Choi, Edward
Ma, Sibo
Yang, Xinyu
Song, Dawn
contents Open-source cyber threat intelligence (OSCTI) has become essential for keeping up with the rapidly changing threat landscape. However, current OSCTI gathering and management solutions mainly focus on structured Indicators of Compromise (IOC) feeds, which are low-level and isolated, providing only a narrow view of potential threats. Meanwhile, the extensive and interconnected knowledge found in the unstructured text of numerous OSCTI reports (e.g., security articles, threat reports) available publicly is still largely underexplored. To bridge the gap, we propose ThreatKG, an automated system for OSCTI gathering and management. ThreatKG efficiently collects a large number of OSCTI reports from multiple sources, leverages specialized AI-based techniques to extract high-quality knowledge about various threat entities and their relationships, and constructs and continuously updates a threat knowledge graph by integrating new OSCTI data. ThreatKG features a modular and extensible design, allowing for the addition of components to accommodate diverse OSCTI report structures and knowledge types. Our extensive evaluations demonstrate ThreatKG's practical effectiveness in enhancing threat knowledge gathering and management.
format Preprint
id arxiv_https___arxiv_org_abs_2212_10388
institution arXiv
publishDate 2022
record_format arxiv
spellingShingle ThreatKG: An AI-Powered System for Automated Open-Source Cyber Threat Intelligence Gathering and Management
Gao, Peng
Liu, Xiaoyuan
Choi, Edward
Ma, Sibo
Yang, Xinyu
Song, Dawn
Cryptography and Security
Databases
Open-source cyber threat intelligence (OSCTI) has become essential for keeping up with the rapidly changing threat landscape. However, current OSCTI gathering and management solutions mainly focus on structured Indicators of Compromise (IOC) feeds, which are low-level and isolated, providing only a narrow view of potential threats. Meanwhile, the extensive and interconnected knowledge found in the unstructured text of numerous OSCTI reports (e.g., security articles, threat reports) available publicly is still largely underexplored. To bridge the gap, we propose ThreatKG, an automated system for OSCTI gathering and management. ThreatKG efficiently collects a large number of OSCTI reports from multiple sources, leverages specialized AI-based techniques to extract high-quality knowledge about various threat entities and their relationships, and constructs and continuously updates a threat knowledge graph by integrating new OSCTI data. ThreatKG features a modular and extensible design, allowing for the addition of components to accommodate diverse OSCTI report structures and knowledge types. Our extensive evaluations demonstrate ThreatKG's practical effectiveness in enhancing threat knowledge gathering and management.
title ThreatKG: An AI-Powered System for Automated Open-Source Cyber Threat Intelligence Gathering and Management
topic Cryptography and Security
Databases
url https://arxiv.org/abs/2212.10388