自动挖掘黑客论坛中的安全事件并排序,提升威胁预警效率。
EventHunter: Dynamic Clustering and Ranking of Security Events from Hacker Forum Discussions
- 用对比学习微调Transformer模型,无监督聚类相关讨论
- 基于时效性等四指标每日排名,识别出零日漏洞等高危事件
- 适合安全分析师快速响应新兴威胁,无需预设关键词
黑客论坛为新兴网络安全威胁提供关键早期预警,但从其非结构化、嘈杂的内容中提取可操作情报仍具挑战。本文提出一种无监督框架,可自动检测、聚类并优先排序跨论坛帖子讨论的安全事件。该方法采用对比学习微调的Transformer嵌入,将相关讨论聚类为独立安全事件,识别出如零日漏洞披露或恶意软件发布等事件,无需依赖预定义关键词。框架引入每日排名机制,通过反映时效性、来源可信度、信息完整性和相关性的量化指标对事件进行优先级排序。在真实黑客论坛数据上的实验表明,该方法有效降低噪声,突出高优先级威胁,使安全分析师能够主动应对。本工作将分散的黑客论坛讨论转化为结构化、可操作的情报,解决了自动化威胁检测与分析中的核心难题。
原文摘要 · Abstract (English)
Hacker forums provide critical early warning signals for emerging cybersecurity threats, but extracting actionable intelligence from their unstructured and noisy content remains a significant challenge. This paper presents an unsupervised framework that automatically detects, clusters, and prioritizes security events discussed across hacker forum posts. Our approach leverages Transformer-based embeddings fine-tuned with contrastive learning to group related discussions into distinct security event clusters, identifying incidents like zero-day disclosures or malware releases without relying on predefined keywords. The framework incorporates a daily ranking mechanism that prioritizes identified events using quantifiable metrics reflecting timeliness, source credibility, information completeness, and relevance. Experimental evaluation on real-world hacker forum data demonstrates that our method effectively reduces noise and surfaces high-priority threats, enabling security analysts to mount proactive responses. By transforming disparate hacker forum discussions into structured, actionable intelligence, our work addresses fundamental challenges in automated threat detection and analysis.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。