Enabling Transparent Cyber Threat Intelligence Combining Large Language Models and Domain Ontologies

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Cotti, Luca, Rula, Anisa, Bianchini, Devis, Cerutti, Federico
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866918466515107840
author Cotti, Luca
Rula, Anisa
Bianchini, Devis
Cerutti, Federico
author_facet Cotti, Luca
Rula, Anisa
Bianchini, Devis
Cerutti, Federico
contents Effective Cyber Threat Intelligence (CTI) relies upon accurately structured and semantically enriched information extracted from cybersecurity system logs. However, current methodologies often struggle to identify and interpret malicious events reliably and transparently, particularly in cases involving unstructured or ambiguous log entries. In this work, we propose a novel methodology that combines ontology-driven structured outputs with Large Language Models (LLMs), to build an Artificial Intelligence (AI) agent that improves the accuracy and explainability of information extraction from cybersecurity logs. Central to our approach is the integration of domain ontologies and SHACL-based constraints to guide the language model's output structure and enforce semantic validity over the resulting graph. Extracted information is organized into an ontology-enriched graph database, enabling future semantic analysis and querying. The design of our methodology is motivated by the analytical requirements associated with honeypot log data, which typically comprises predominantly malicious activity. While our case study illustrates the relevance of this scenario, the experimental evaluation is conducted using publicly available datasets. Results demonstrate that our method achieves higher accuracy in information extraction compared to traditional prompt-only approaches, with a deliberate focus on extraction quality rather than processing speed.
format Preprint
id arxiv_https___arxiv_org_abs_2509_00081
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Enabling Transparent Cyber Threat Intelligence Combining Large Language Models and Domain Ontologies
Cotti, Luca
Rula, Anisa
Bianchini, Devis
Cerutti, Federico
Cryptography and Security
Artificial Intelligence
I.2.7; I.2.6; I.2.4
Effective Cyber Threat Intelligence (CTI) relies upon accurately structured and semantically enriched information extracted from cybersecurity system logs. However, current methodologies often struggle to identify and interpret malicious events reliably and transparently, particularly in cases involving unstructured or ambiguous log entries. In this work, we propose a novel methodology that combines ontology-driven structured outputs with Large Language Models (LLMs), to build an Artificial Intelligence (AI) agent that improves the accuracy and explainability of information extraction from cybersecurity logs. Central to our approach is the integration of domain ontologies and SHACL-based constraints to guide the language model's output structure and enforce semantic validity over the resulting graph. Extracted information is organized into an ontology-enriched graph database, enabling future semantic analysis and querying. The design of our methodology is motivated by the analytical requirements associated with honeypot log data, which typically comprises predominantly malicious activity. While our case study illustrates the relevance of this scenario, the experimental evaluation is conducted using publicly available datasets. Results demonstrate that our method achieves higher accuracy in information extraction compared to traditional prompt-only approaches, with a deliberate focus on extraction quality rather than processing speed.
title Enabling Transparent Cyber Threat Intelligence Combining Large Language Models and Domain Ontologies
topic Cryptography and Security
Artificial Intelligence
I.2.7; I.2.6; I.2.4
url https://arxiv.org/abs/2509.00081