用知识图谱实现威胁情报提取结果的可审计治理
TRACE-CTI: Auditable Post-Extraction Governance of TTP Claims with Knowledge Graphs
- 构建图结构存储提取结果与验证证据,支持追溯和信任评估
- 六套系统一致认定时,准确率从25.3%升至90.6%,召回率降至16.3%
- 适合安全运营中心需追踪威胁情报可信度的场景
安全运营中心越来越多依赖自动化将网络威胁情报报告映射到MITRE ATT&CK框架,但提取结果常不可靠,且缺乏证据、来源和验证历史,难以判断具体映射是否可信。我们提出TRACE-CTI,一种后提取的战术技术与过程(TTP)声明治理框架。该框架保留运行级预测,聚合为配置级图断言(GraphAssertions),将去重后的共识证据转化为共识断言(ConsensusAssertions),仅暴露符合策略的验证依据支持的图断言。系统保持原始证据粒度、完整提取溯源、版本化信任决策及非破坏性撤销记录。在包含65份报告、5,303个句子的两个公开威胁情报语料库上评估,采用受控的2×3组合检索器与生成器家族,分六轮图版本增量摄入。所有设置无需修改模式,溯源路径完整,操作范围互斥,每个可信图断言均有有效验证依据。跨生成器家族的设置对表现出比同家族更大的输出多样性。最终图状态中,支持度从k≥1提升至六系统一致,黄金标准对齐准确率从25.3%增至90.6%,召回率从88.2%降至16.3%。图结构直接回答了关于溯源、信任、版本、依赖、分歧与审查队列等七个问题,而原始扁平输出无法在不增强或重处理的情况下完整回应。结果表明,该框架支持明确、可审计的提取声明治理;观察到的共识轨迹具描述性,未建立统计独立性或模型族因果效应。
原文摘要 · Abstract (English)
Security Operations Centers increasingly rely on automated mapping of Cyber Threat Intelligence reports to MITRE ATT&CK, yet extractor outputs remain fallible and are often stored without the evidence, provenance, and validation history needed to decide whether an individual mapping should be trusted. We present TRACE- CTI, a post-extraction claim-governance framework that preserves run-level Predictions, aggregates them into configuration-level GraphAssertions, materializes setup-deduplicated corroboration as ConsensusAssertions, and exposes only GraphAssertions backed by policy-compliant validation grounds. The framework retains native evidence granularity, complete extraction provenance, versioned trust decisions, and non-destructive revocation history. We evaluate TRACE-CTI on two public CTI corpora comprising 65 reports and 5,303 sentences, using a controlled 2 x 3 matrix of retrievers and generator families, incrementally ingested across six GraphVersions. All setups are incorporated without schema modification; provenance paths remain complete, operational scopes remain disjoint, and every trusted GraphAssertion has an active qualifying validation ground. Cross-generator-family setup pairs exhibit greater output diversity than same-family pairs. At the final graph state, increasing setup support from k >= 1 to six-setup unanimity raises gold-aligned precision from 25.3% to 90.6%, while recall decreases from 88.2% to 16.3%. The graph also directly answers seven questions about provenance, trust, versioning, dependency, disagreement, and review-queue that the evaluated minimal flat output cannot fully answer without enrichment or reprocessing. These results support explicit, auditable governance of extracted TTP claims; the observed corroboration trajectory is descriptive and does not establish statistical independence or a causal model-family effect.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。