LSTM Recurrent Neural Networks for Cybersecurity Named Entity Recognition

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Gasmi, Houssem, Laval, Jannik, Bouras, Abdelaziz
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866910606576058368
author Gasmi, Houssem
Laval, Jannik
Bouras, Abdelaziz
author_facet Gasmi, Houssem
Laval, Jannik
Bouras, Abdelaziz
contents The automated and timely conversion of cybersecurity information from unstructured online sources, such as blogs and articles to more formal representations has become a necessity for many applications in the domain nowadays. Named Entity Recognition (NER) is one of the early phases towards this goal. It involves the detection of the relevant domain entities, such as product, version, attack name, etc. in technical documents. Although generally considered a simple task in the information extraction field, it is quite challenging in some domains like cybersecurity because of the complex structure of its entities. The state of the art methods require time-consuming and labor intensive feature engineering that describes the properties of the entities, their context, domain knowledge, and linguistic characteristics. The model demonstrated in this paper is domain independent and does not rely on any features specific to the entities in the cybersecurity domain, hence does not require expert knowledge to perform feature engineering. The method used relies on a type of recurrent neural networks called Long Short-Term Memory (LSTM) and the Conditional Random Fields (CRFs) method. The results we obtained showed that this method outperforms the state of the art methods given an annotated corpus of a decent size.
format Preprint
id arxiv_https___arxiv_org_abs_2409_10521
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle LSTM Recurrent Neural Networks for Cybersecurity Named Entity Recognition
Gasmi, Houssem
Laval, Jannik
Bouras, Abdelaziz
Information Retrieval
Artificial Intelligence
Cryptography and Security
Machine Learning
The automated and timely conversion of cybersecurity information from unstructured online sources, such as blogs and articles to more formal representations has become a necessity for many applications in the domain nowadays. Named Entity Recognition (NER) is one of the early phases towards this goal. It involves the detection of the relevant domain entities, such as product, version, attack name, etc. in technical documents. Although generally considered a simple task in the information extraction field, it is quite challenging in some domains like cybersecurity because of the complex structure of its entities. The state of the art methods require time-consuming and labor intensive feature engineering that describes the properties of the entities, their context, domain knowledge, and linguistic characteristics. The model demonstrated in this paper is domain independent and does not rely on any features specific to the entities in the cybersecurity domain, hence does not require expert knowledge to perform feature engineering. The method used relies on a type of recurrent neural networks called Long Short-Term Memory (LSTM) and the Conditional Random Fields (CRFs) method. The results we obtained showed that this method outperforms the state of the art methods given an annotated corpus of a decent size.
title LSTM Recurrent Neural Networks for Cybersecurity Named Entity Recognition
topic Information Retrieval
Artificial Intelligence
Cryptography and Security
Machine Learning
url https://arxiv.org/abs/2409.10521