用AI自动匹配威胁情报到对应行业,提升防御响应速度。
DisCTI: Who Needs to Know Timely? Automated Sector-Aware Cyber Threat Intelligence Dissemination

- 将威胁情报分发建模为多标签分类问题,结合领域知识与BERT模型。
- 在自建数据集上达到0.89的F1分数,94.5%的标签预测准确率。
- 适合需要快速响应攻击的能源、金融等关键基础设施单位。
及时传播网络威胁情报(CTI)对组织快速应对安全事件至关重要。当有效情报在恰当时间送达正确行业时,可显著遏制或减轻相同攻击。然而,当前不断扩张的CTI生态令分析人员不堪重负,需从海量异构情报源中筛选信息。现有平台如恶意软件信息共享平台(MISP)虽提供行业标签(如能源、金融、政府),但实际使用中仅有2%的事件被标注(98%未分类)。这种缺乏自动化且延迟的行业映射严重削弱了共享情报的实战价值,使关键信息基础设施部门暴露于风险之中。为此,本文将行业定向的CTI分发建模为多标签分类问题。基于对CTI结构及行业特异性威胁模式的深度领域知识,构建了包含872个行业标注的新型数据集(来自威胁情报平台,TIP)。采用BERT这一基于Transformer的模型,实现对CTI事件的行业自动映射。利用结构化威胁信息表达(STIX)格式保障跨平台互操作性,该方法在自建数据集上取得宏平均F1分数0.89,汉明损失0.055,即94.5%的单个行业标签分配正确。结果不仅证明了行业感知型自动化分发的可行性,更揭示将专家领域知识嵌入机器学习设计,可填补威胁情报链路中的关键空白,推动更快、更精准的防御行动。
原文摘要 · Abstract (English)
The timely dissemination of cyber threat intelligence (CTI) is critical for organizations to mount swift and effective incident response. When valid CTI is delivered to the right sector at the right time, identical attacks can often be contained or mitigated. However, today's rapidly expanding CTI landscape overwhelms analysts, who must sift through massive and heterogeneous feeds. Existing platforms such as the Malware Information Sharing Platform (MISP) provide sector tagging features (e.g., energy, finance, government), but in practice, these remain largely unmapped (98% of events are left uncategorized). This lack of automated and timely sector mapping severely limits the operational value of shared intelligence, leaving organizations that belong especially to the critical information infrastructure sector exposed. To address this gap, we formulate sector-targeted CTI dissemination as a multilabel classification problem. Leveraging deep field knowledge of CTI structures and sector-specific threat patterns, we construct a novel data set of 872 sector-labelled CTI events from a threat intelligence platform (TIP). We then apply BERT, a transformer-based model, to automate the mapping of CTI events to sectors. Using the structured threat information expression (STIX) format for cross-platform interoperability, our approach achieves a macro-averaged F1-score of 0.89 at a Hamming loss of 0.055 on the custom dataset, i.e. 94.5% of individual sector-label assignments are correct. These results not only demonstrate the feasibility of sector-aware, automated CTI dissemination but also highlight how embedding expert field knowledge into machine learning design fills a crucial gap in the threat intelligence pipeline, enabling faster and context-relevant defensive action.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。