Revealing the True Indicators: Understanding and Improving IoC Extraction From Threat Reports

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Froudakis, Evangelos, Avgetidis, Athanasios, Frankum, Sean Tyler, Perdisci, Roberto, Antonakakis, Manos, Keromytis, Angelos D.
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866908608491421696
author Froudakis, Evangelos
Avgetidis, Athanasios
Frankum, Sean Tyler
Perdisci, Roberto
Antonakakis, Manos
Keromytis, Angelos D.
author_facet Froudakis, Evangelos
Avgetidis, Athanasios
Frankum, Sean Tyler
Perdisci, Roberto
Antonakakis, Manos
Keromytis, Angelos D.
contents Indicators of Compromise (IoCs) are critical for threat detection and response, marking malicious activity across networks and systems. Yet, the effectiveness of automated IoC extraction systems is fundamentally limited by one key issue: the lack of high-quality ground truth. Current extraction tools rely either on manually extracted ground truth, which is labor-intensive and costly, or on automated ground truth creation methods that include non-malicious artifacts, leading to inflated false positive (FP) rates and unreliable threat intelligence. In this work, we analyze the shortcomings of existing ground truth creation strategies and address them by introducing the first hybrid human-in-the-loop pipeline for IoC extraction, which combines a large language model-based classifier (LANCE) with expert analyst validation. Our system improves precision through explainable, context-aware labeling and reduces analysts' work factor by 43% compared to manual annotation, as demonstrated in our evaluation with six analysts. Using this approach, we produce PRISM, a high-quality, publicly available benchmark of 1,791 labeled IoCs from 50 real-world threat reports. PRISM supports both fair evaluation and training of IoC extraction methods and enables reproducible research grounded in expert-validated indicators.
format Preprint
id arxiv_https___arxiv_org_abs_2506_11325
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Revealing the True Indicators: Understanding and Improving IoC Extraction From Threat Reports
Froudakis, Evangelos
Avgetidis, Athanasios
Frankum, Sean Tyler
Perdisci, Roberto
Antonakakis, Manos
Keromytis, Angelos D.
Cryptography and Security
Indicators of Compromise (IoCs) are critical for threat detection and response, marking malicious activity across networks and systems. Yet, the effectiveness of automated IoC extraction systems is fundamentally limited by one key issue: the lack of high-quality ground truth. Current extraction tools rely either on manually extracted ground truth, which is labor-intensive and costly, or on automated ground truth creation methods that include non-malicious artifacts, leading to inflated false positive (FP) rates and unreliable threat intelligence. In this work, we analyze the shortcomings of existing ground truth creation strategies and address them by introducing the first hybrid human-in-the-loop pipeline for IoC extraction, which combines a large language model-based classifier (LANCE) with expert analyst validation. Our system improves precision through explainable, context-aware labeling and reduces analysts' work factor by 43% compared to manual annotation, as demonstrated in our evaluation with six analysts. Using this approach, we produce PRISM, a high-quality, publicly available benchmark of 1,791 labeled IoCs from 50 real-world threat reports. PRISM supports both fair evaluation and training of IoC extraction methods and enables reproducible research grounded in expert-validated indicators.
title Revealing the True Indicators: Understanding and Improving IoC Extraction From Threat Reports
topic Cryptography and Security
url https://arxiv.org/abs/2506.11325