Tweezers: A Framework for Security Event Detection via Event Attribution-centric Tweet Embedding

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Cui, Jian, Kim, Hanna, Jang, Eugene, Yim, Dayeon, Kim, Kicheol, Lee, Yongjae, Chung, Jin-Woo, Shin, Seungwon, Liao, Xiaojing
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909313486815232
author Cui, Jian
Kim, Hanna
Jang, Eugene
Yim, Dayeon
Kim, Kicheol
Lee, Yongjae
Chung, Jin-Woo
Shin, Seungwon
Liao, Xiaojing
author_facet Cui, Jian
Kim, Hanna
Jang, Eugene
Yim, Dayeon
Kim, Kicheol
Lee, Yongjae
Chung, Jin-Woo
Shin, Seungwon
Liao, Xiaojing
contents Twitter is recognized as a crucial platform for the dissemination and gathering of Cyber Threat Intelligence (CTI). Its capability to provide real-time, actionable intelligence makes it an indispensable tool for detecting security events, helping security professionals cope with ever-growing threats. However, the large volume of tweets and inherent noises of human-crafted tweets pose significant challenges in accurately identifying security events. While many studies tried to filter out event-related tweets based on keywords, they are not effective due to their limitation in understanding the semantics of tweets. Another challenge in security event detection from Twitter is the comprehensive coverage of security events. Previous studies emphasized the importance of early detection of security events, but they overlooked the importance of event coverage. To cope with these challenges, in our study, we introduce a novel event attribution-centric tweet embedding method to enable the high precision and coverage of events. Our experiment result shows that the proposed method outperforms existing text and graph-based tweet embedding methods in identifying security events. Leveraging this novel embedding approach, we have developed and implemented a framework, Tweezers, that is applicable to security event detection from Twitter for CTI gathering. This framework has demonstrated its effectiveness, detecting twice as many events compared to established baselines. Additionally, we have showcased two applications, built on Tweezers for the integration and inspection of security events, i.e., security event trend analysis and informative security user identification.
format Preprint
id arxiv_https___arxiv_org_abs_2409_08221
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Tweezers: A Framework for Security Event Detection via Event Attribution-centric Tweet Embedding
Cui, Jian
Kim, Hanna
Jang, Eugene
Yim, Dayeon
Kim, Kicheol
Lee, Yongjae
Chung, Jin-Woo
Shin, Seungwon
Liao, Xiaojing
Cryptography and Security
Twitter is recognized as a crucial platform for the dissemination and gathering of Cyber Threat Intelligence (CTI). Its capability to provide real-time, actionable intelligence makes it an indispensable tool for detecting security events, helping security professionals cope with ever-growing threats. However, the large volume of tweets and inherent noises of human-crafted tweets pose significant challenges in accurately identifying security events. While many studies tried to filter out event-related tweets based on keywords, they are not effective due to their limitation in understanding the semantics of tweets. Another challenge in security event detection from Twitter is the comprehensive coverage of security events. Previous studies emphasized the importance of early detection of security events, but they overlooked the importance of event coverage. To cope with these challenges, in our study, we introduce a novel event attribution-centric tweet embedding method to enable the high precision and coverage of events. Our experiment result shows that the proposed method outperforms existing text and graph-based tweet embedding methods in identifying security events. Leveraging this novel embedding approach, we have developed and implemented a framework, Tweezers, that is applicable to security event detection from Twitter for CTI gathering. This framework has demonstrated its effectiveness, detecting twice as many events compared to established baselines. Additionally, we have showcased two applications, built on Tweezers for the integration and inspection of security events, i.e., security event trend analysis and informative security user identification.
title Tweezers: A Framework for Security Event Detection via Event Attribution-centric Tweet Embedding
topic Cryptography and Security
url https://arxiv.org/abs/2409.08221