arXiv:2603.12455cs.CRcs.AI2026-03

用AI自动关联网络攻击与防御措施,帮小企业提升安全防护效率。

Operationalising Cyber Risk Management Using AI: Connecting Cyber Incidents to MITRE ATT&CK Techniques, Security Controls, and Metrics

  • 用NLP将安全事件自动匹配到MITRE ATT&CK攻击技术
  • 模型在7.5万组数据上达到0.8756的皮尔逊相关性
  • 开源工具包适合资源有限的安全团队快速部署

日益频繁的网络攻击给组织带来严峻挑战,尤其对缺乏专业人才、知识和资金的小型企业。本研究提出一个新框架,利用自然语言处理技术实现攻击事件与攻击手法的自动映射。我们构建了Cyber Catalog知识库,系统整合了CIS关键安全控制、MITRE ATT&CK技术及SMART指标。该资源使威胁情报可直接对接可执行的防护措施与可衡量的结果。为落地应用,我们在包含74,986个事件-技术对的增强数据集上微调all-mpnet-base-v2模型,使其文本向量化能力显著提升。微调后模型在语义相似度任务中取得0.7894的斯皮尔曼相关系数和0.8756的皮尔逊相关系数,优于all-mpnet-base-v2、all-distilroberta-v1、all-MiniLM-L12-v2等主流基线模型。预测误差也更低(MAE=0.135,MSE=0.027),验证了其更高准确性和一致性。Cyber Catalog、训练数据、训练好的模型及代码均已公开,支持后续研究与资源受限环境中的实际部署。该工作弥合了威胁情报与实际安全管理之间的鸿沟,提供系统化响应和基于证据的风险管理工具。

原文摘要 · Abstract (English)

The escalating frequency of cyber-attacks poses significant challenges for organisations, particularly small enterprises constrained by limited in-house expertise, insufficient knowledge, and financial resources. This research presents a novel framework that leverages Natural Language Processing to address these challenges through automated mapping of cyber incidents to adversary techniques. We introduce the Cyber Catalog, a knowledge base that systematically integrates CIS Critical Security Controls, MITRE ATT&CK techniques, and SMART metrics. This integrated resource enables organisations to connect threat intelligence directly to actionable controls and measurable outcomes. To operationalise the framework, we fine-tuned all-mpnet-base-v2, a highly regarded sentence-transformers model used to convert text into numerical vectors on an augmented dataset comprising 74,986 incident-technique pairs to enhance semantic similarity between cyber incidents and MITRE ATT&CK techniques. Our fine-tuned model achieved a Spearman correlation of 0.7894 and Pearson correlation of 0.8756, demonstrating substantial improvements over top baseline models including all-mpnet-base-v2, all-distilroberta-v1, and all-MiniLM-L12-v2. Furthermore, our model exhibited significantly lower prediction errors (MAE = 0.135, MSE = 0.027) compared to all baseline models, confirming superior accuracy and consistency. The Cyber Catalog, training dataset, trained model, and implementation code made publicly available to facilitate further research and enable practical deployment in resource-constrained environments. This work bridges the gap between threat intelligence and operational security management, providing an actionable tool for systematic cyber incident response and evidence-based cyber risk management.

网络安全AI安全威胁情报自动化

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。