KnowHow: Automatically Applying High-Level CTI Knowledge for Interpretable and Accurate Provenance Analysis
Fuente:
arXiv
Saved in:
| Main Authors: | Meng, Yuhan, Li, Shaofei, Gui, Jiaping, Jiang, Peng, Li, Ding |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
Query Provenance Analysis: Efficient and Robust Defense against Query-based Black-box Attacks
by: Li, Shaofei, et al.
Published: (2024)
by: Li, Shaofei, et al.
Published: (2024)
RHINO: Guided Reasoning for Mapping Network Logs to Adversarial Tactics and Techniques with Large Language Models
by: Meng, Fanchao, et al.
Published: (2025)
by: Meng, Fanchao, et al.
Published: (2025)
Local Layer-wise Differential Privacy in Federated Learning
by: Li, Yunbo, et al.
Published: (2026)
by: Li, Yunbo, et al.
Published: (2026)
Towards Explainable Privacy Preservation in Federated Learning via Shapley Value-Guided Noise Injection
by: Li, Yunbo, et al.
Published: (2025)
by: Li, Yunbo, et al.
Published: (2025)
How Far Should We Need to Go : Evaluate Provenance-based Intrusion Detection Systems in Industrial Scenarios
by: Xiao, Yue, et al.
Published: (2026)
by: Xiao, Yue, et al.
Published: (2026)
From Secure Agentic AI to Secure Agentic Web: Challenges, Threats, and Future Directions
by: Deng, Zhihang, et al.
Published: (2026)
by: Deng, Zhihang, et al.
Published: (2026)
Kitten or Panda? Measuring the Specificity of Threat Group Behaviors in Public CTI Knowledge Bases
by: Saha, Aakanksha, et al.
Published: (2025)
by: Saha, Aakanksha, et al.
Published: (2025)
From IOCs to Regex: Automating CTI Operationalization for SOC with LLMs
by: Tseng, Pei-Yu, et al.
Published: (2026)
by: Tseng, Pei-Yu, et al.
Published: (2026)
Marlin: Knowledge-Driven Analysis of Provenance Graphs for Efficient and Robust Detection of Cyber Attacks
by: Li, Zhenyuan, et al.
Published: (2024)
by: Li, Zhenyuan, et al.
Published: (2024)
CTI-HAL: A Human-Annotated Dataset for Cyber Threat Intelligence Analysis
by: Della Penna, Sofia, et al.
Published: (2025)
by: Della Penna, Sofia, et al.
Published: (2025)
SeCTIS: A Framework to Secure CTI Sharing
by: Arikkat, Dincy R., et al.
Published: (2024)
by: Arikkat, Dincy R., et al.
Published: (2024)
The Procedural Semantics Gap in Structured CTI: A Measurement-Driven STIX Analysis for APT Emulation
by: Ferraz, Ágney Lopes Roth, et al.
Published: (2025)
by: Ferraz, Ágney Lopes Roth, et al.
Published: (2025)
Knowledge Transfer from LLMs to Provenance Analysis: A Semantic-Augmented Method for APT Detection
by: Zuo, Fei, et al.
Published: (2025)
by: Zuo, Fei, et al.
Published: (2025)
Attackers reveal their arsenal: An investigation of adversarial techniques in CTI reports
by: Rahman, Md Rayhanur, et al.
Published: (2024)
by: Rahman, Md Rayhanur, et al.
Published: (2024)
reconCTI: A Proactive Approach to Cyber-Threat Intelligence
by: Rahman, Mohammed Mahir, et al.
Published: (2026)
by: Rahman, Mohammed Mahir, et al.
Published: (2026)
CLIProv: A Contrastive Log-to-Intelligence Multimodal Approach for Threat Detection and Provenance Analysis
by: Li, Jingwen, et al.
Published: (2025)
by: Li, Jingwen, et al.
Published: (2025)
DEFENDCLI: {Command-Line} Driven Attack Provenance Examination
by: Wu, Peilun, et al.
Published: (2025)
by: Wu, Peilun, et al.
Published: (2025)
No Data? No Problem: Synthesizing Security Graphs for Better Intrusion Detection
by: Huang, Yi, et al.
Published: (2025)
by: Huang, Yi, et al.
Published: (2025)
LaSM: Layer-wise Scaling Mechanism for Defending Pop-up Attack on GUI Agents
by: Yan, Zihe, et al.
Published: (2025)
by: Yan, Zihe, et al.
Published: (2025)
CTI-REALM: Benchmark to Evaluate Agent Performance on Security Detection Rule Generation Capabilities
by: Chakraborty, Arjun, et al.
Published: (2026)
by: Chakraborty, Arjun, et al.
Published: (2026)
SynthCTI: LLM-Driven Synthetic CTI Generation to enhance MITRE Technique Mapping
by: Ruiz-Ródenas, Álvaro, et al.
Published: (2025)
by: Ruiz-Ródenas, Álvaro, et al.
Published: (2025)
SynAT: Enhancing Security Knowledge Bases via Automatic Synthesizing Attack Tree from Crowd Discussions
by: Jiang, Ziyou, et al.
Published: (2026)
by: Jiang, Ziyou, et al.
Published: (2026)
The Granularity Mismatch in Agent Security: Argument-Level Provenance Solves Enforcement and Isolates the LLM Reasoning Bottleneck
by: Fan, Linfeng, et al.
Published: (2026)
by: Fan, Linfeng, et al.
Published: (2026)
The CTI Echo Chamber: Fragmentation, Overlap, and Vendor Specificity in Twenty Years of Cyber Threat Reporting
by: Suarez-Roman, Manuel, et al.
Published: (2026)
by: Suarez-Roman, Manuel, et al.
Published: (2026)
Verifiable Provenance of Software Artifacts with Zero-Knowledge Compilation
by: Ron, Javier, et al.
Published: (2026)
by: Ron, Javier, et al.
Published: (2026)
Incorporating Gradients to Rules: Towards Lightweight, Adaptive Provenance-based Intrusion Detection
by: Wang, Lingzhi, et al.
Published: (2024)
by: Wang, Lingzhi, et al.
Published: (2024)
Elevating Cyber Threat Intelligence against Disinformation Campaigns with LLM-based Concept Extraction and the FakeCTI Dataset
by: Cotroneo, Domenico, et al.
Published: (2025)
by: Cotroneo, Domenico, et al.
Published: (2025)
CTI Dataset Construction from Telegram
by: Arikkat, Dincy R., et al.
Published: (2025)
by: Arikkat, Dincy R., et al.
Published: (2025)
An End-to-End Framework for Functionality-Embedded Provenance Graph Construction and Threat Interpretation
by: Ghosh, Kushankur, et al.
Published: (2026)
by: Ghosh, Kushankur, et al.
Published: (2026)
Interpreting GNN-based IDS Detections Using Provenance Graph Structural Features
by: Mukherjee, Kunal, et al.
Published: (2023)
by: Mukherjee, Kunal, et al.
Published: (2023)
Slot: Provenance-Driven APT Detection through Graph Reinforcement Learning
by: Qiao, Wei, et al.
Published: (2024)
by: Qiao, Wei, et al.
Published: (2024)
PromoGuardian: Detecting Promotion Abuse Fraud with Multi-Relation Fused Graph Neural Networks
by: Li, Shaofei, et al.
Published: (2025)
by: Li, Shaofei, et al.
Published: (2025)
ProvX: Generating Counterfactual-Driven Attack Explanations for Provenance-Based Detection
by: Wu, Weiheng, et al.
Published: (2025)
by: Wu, Weiheng, et al.
Published: (2025)
Are We There Yet? Unraveling the State-of-the-Art Graph Network Intrusion Detection Systems
by: Wang, Chenglong, et al.
Published: (2025)
by: Wang, Chenglong, et al.
Published: (2025)
TFLAG:Towards Practical APT Detection via Deviation-Aware Learning on Temporal Provenance Graph
by: Jiang, Wenhan, et al.
Published: (2025)
by: Jiang, Wenhan, et al.
Published: (2025)
Know Thy Enemy: Securing LLMs Against Prompt Injection via Diverse Data Synthesis and Instruction-Level Chain-of-Thought Learning
by: Chang, Zhiyuan, et al.
Published: (2026)
by: Chang, Zhiyuan, et al.
Published: (2026)
LLM-driven Provenance Forensics for Threat Investigation and Detection
by: Mukherjee, Kunal, et al.
Published: (2025)
by: Mukherjee, Kunal, et al.
Published: (2025)
Zero-Knowledge Location Privacy via Accurate Floating-Point SNARKs
by: Ernstberger, Jens, et al.
Published: (2024)
by: Ernstberger, Jens, et al.
Published: (2024)
BackdoorMBTI: A Backdoor Learning Multimodal Benchmark Tool Kit for Backdoor Defense Evaluation
by: Yu, Haiyang, et al.
Published: (2024)
by: Yu, Haiyang, et al.
Published: (2024)
PIDSMaker: Building and Evaluating Provenance-based Intrusion Detection Systems
by: Bilot, Tristan, et al.
Published: (2026)
by: Bilot, Tristan, et al.
Published: (2026)
Similar Items
-
Query Provenance Analysis: Efficient and Robust Defense against Query-based Black-box Attacks
by: Li, Shaofei, et al.
Published: (2024) -
RHINO: Guided Reasoning for Mapping Network Logs to Adversarial Tactics and Techniques with Large Language Models
by: Meng, Fanchao, et al.
Published: (2025) -
Local Layer-wise Differential Privacy in Federated Learning
by: Li, Yunbo, et al.
Published: (2026) -
Towards Explainable Privacy Preservation in Federated Learning via Shapley Value-Guided Noise Injection
by: Li, Yunbo, et al.
Published: (2025) -
How Far Should We Need to Go : Evaluate Provenance-based Intrusion Detection Systems in Industrial Scenarios
by: Xiao, Yue, et al.
Published: (2026)