arXiv:2501.06239cs.CRcs.AI2025-01被引 8

零数据也能提取威胁情报,框架可适配各种数据条件。

Towards a scalable AI-driven framework for data-independent Cyber Threat Intelligence Information Extraction

  • 用Transformer模型处理完整报告,支持有监督与零样本学习。
  • 零样本模式下实体与关系抽取效果超越现有方法。
  • 输出符合STIX标准,适合安全团队快速共享情报。

网络威胁情报(CTI)对组织、政府和机构的防护至关重要,但相关数据常分散在多种格式中。现有基于AI的威胁情报信息抽取(IE)方法通常依赖高质量标注数据,而这些数据并不总能获得。本文提出0-CTI,一种可扩展的AI驱动框架,用于高效进行CTI信息抽取。该框架利用先进的自然语言处理技术,特别是基于Transformer的架构,处理完整的CTI报告文本,提取网络安全本体中的命名实体及其关系。本研究的贡献在于开发了首个支持监督与零样本学习的模块化CTI信息抽取框架。与依赖大量标注数据的现有模型不同,0-CTI通过零样本方法实现完全无需数据的操作,适用于各类数据可用性场景。此外,其监督式实体抽取器在网络安全实体抽取任务上超越当前最先进水平。通过将系统输出对齐至结构化威胁信息表达(STIX)格式——网络安全领域通用的信息交换标准——0-CTI实现了知识标准化,提升安全运营中的协作效率。

原文摘要 · Abstract (English)

Cyber Threat Intelligence (CTI) is critical for mitigating threats to organizations, governments, and institutions, yet the necessary data are often dispersed across diverse formats. AI-driven solutions for CTI Information Extraction (IE) typically depend on high-quality, annotated data, which are not always available. This paper introduces 0-CTI, a scalable AI-based framework designed for efficient CTI Information Extraction. Leveraging advanced Natural Language Processing (NLP) techniques, particularly Transformer-based architectures, the proposed system processes complete text sequences of CTI reports to extract a cyber ontology of named entities and their relationships. Our contribution is the development of 0-CTI, the first modular framework for CTI Information Extraction that supports both supervised and zero-shot learning. Unlike existing state-of-the-art models that rely heavily on annotated datasets, our system enables fully dataless operation through zero-shot methods for both Entity and Relation Extraction, making it adaptable to various data availability scenarios. Additionally, our supervised Entity Extractor surpasses current state-of-the-art performance in cyber Entity Extraction, highlighting the dual strength of the framework in both low-resource and data-rich environments. By aligning the system's outputs with the Structured Threat Information Expression (STIX) format, a standard for information exchange in the cybersecurity domain, 0-CTI standardizes extracted knowledge, enhancing communication and collaboration in cybersecurity operations.

威胁情报零样本学习NLPSTIX

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。