Useful Cyber Threat Intelligence Relation Retrieval Using Transfer Learning


연구 분야: Safety



학회: EICC '23: Proceedings of the 2023 European Interdisciplinary Cybersecurity Conference


초록

The emergence of hacker groups extends the complexity and frequency of cyberattacks. To adapt to the rapidly evolving cyberattacks, acquiring valuable information from security incident reports is critical for businesses to gain visibility into the fast-evolving threat landscape and to timely deploy preventive measures. As such threat intelligence is mostly presented in textual reports, such information needs to be extracted manually by security analysts and is highly dependent on personnel experience. This research proposes a novel cyber threat intelligence extraction system called “CARE” (Cyber Attack Relation Extraction) that extracts critical threat entities and presents their relationship in both graphical and textual forms that help cybersecurity staff quickly grasp the key information from security reports. To capture attack-related information, this study adopts BERT to enhance contextualized word representation and applies transfer learning to extract the relations among threat entities. The evaluation results show that the proposed CARE system achieves a 97% F1-score on relation extraction and that it could retrieve useful threat information effectively.


Author Profile
Chiamei Chen

National Sun Yat-Sen University Taiwan

Senegal
Author Profile
Fanghsuan Hsu

National Sun Yat-Sen University Taiwan

Senegal
Author Profile
Jenq Neng Hwang

University of Washington United States

United States

📄 논문 정보

발행 연도 2023년
인용수 3
출판 국가 Senegal, United States
사이트 ACM
좋아요 수 0

연관 논문 목록 (563건)