遇见数据集

ChronoCTI: Mining Knowledge Graph of Temporal Relations among Cyberattack Actionsin the proceedings of International Conference on Data Mining 2024

收藏
Figshare2024-11-18 更新2026-04-08 收录
官方服务:

资源简介:

Cyberthreat intelligence (CTI) reports on past cyberattacks describe the sequence of actions of attackers in terms of time. The sequence contains temporal relations among attack actions, such as \textit{a malware is first downloaded and then executed}. Information related to temporal relations enables cybersecurity practitioners to investigate past cyberattack incidents and analyze attackers' behavior. However, cybersecurity practitioners must extract such information automatically, in a structured manner, through a common vocabulary to reduce human effort and enable sharing and collaboration. \textit{The goal of this paper is to aid security practitioners in proactive defense against attacks by automatic information extraction of temporal relations among attack actions from cyberthreat intelligence reports}. We propose \textbf{ChronoCTI}, an automated pipeline for extracting temporal relations among attack actions from CTI reports. The attack actions are represented as MITRE ATT\&CK techniques, and the relations are represented as a knowledge graph. To construct \textbf{ChronoCTI}, we build a ground truth dataset of temporal relations and apply large language models, natural language processing, and machine learning techniques. \textbf{ChronoCTI} demonstrates higher precision but lower recall performance on a real-world dataset of 94 CTI reports. \textbf{ChronoCTI} achieves macro precision, recall, and F1 scores of 0.75, 0.46, and 0.54, respectively. ChronoCTI aids practitioners in analyzing large volumes of CTI reports, thinking like attackers, and knowing what malicious actions are likely to happen next, which enables the practitioners to assess imminent threats and strengthen their cybersecurity readiness.

网络威胁情报(Cyberthreat Intelligence, CTI)报告针对过往网络攻击,按时间维度梳理攻击者的行动序列。该序列包含攻击动作间的时序关联,例如“恶意软件先被下载,随后执行”。此类时序关联相关信息可助力网络安全从业者复盘过往网络攻击事件、剖析攻击者行为模式。然而,当前网络安全从业者需依托统一的术语体系,以结构化方式自动提取此类信息,以此降低人力投入并促进信息共享与跨团队协作。本文旨在从网络威胁情报报告中自动提取攻击动作间的时序关联信息,助力安全从业者开展主动防御。我们提出了**ChronoCTI**——一种用于从CTI报告中提取攻击动作时序关联的自动化处理流水线。攻击动作以MITRE ATT&CK技术(MITRE ATT&CK)进行表征,而时序关联则以知识图谱形式呈现。为构建**ChronoCTI**系统,我们构建了时序关联标注真值数据集,并应用了大语言模型、自然语言处理与机器学习技术。**ChronoCTI**在包含94份CTI报告的真实数据集上展现出更高的精确率,但召回率表现相对较低。**ChronoCTI**的宏精确率、宏召回率与宏F1值分别为0.75、0.46与0.54。**ChronoCTI**可帮助从业者分析海量CTI报告、模拟攻击者思维预判后续可能发生的恶意动作,从而使从业者能够评估迫在眉睫的威胁并提升自身网络安全防御准备水平。

提供机构:
Rahman, Md Rayhanur
创建时间:
2024-11-18
二维码
社区交流群
二维码
科研交流群
商业服务