ThreatKG: An AI-Powered System for Automated Open-Source Cyber Threat Intelligence Gathering and Management

dc.contributor.authorGao, Pengen
dc.contributor.authorLiu, Xiaoyuanen
dc.contributor.authorChoi, Edwarden
dc.contributor.authorMa, Siboen
dc.contributor.authorYang, Xinyuen
dc.contributor.authorSong, Dawnen
dc.date.accessioned2024-12-03T18:12:28Zen
dc.date.available2024-12-03T18:12:28Zen
dc.date.issued2023-11-19en
dc.date.updated2024-12-01T09:01:56Zen
dc.description.abstractOpen-source cyber threat intelligence (OSCTI) has become essential for keeping up with the rapidly changing threat landscape. However, current OSCTI gathering and management solutions mainly focus on structured Indicators of Compromise (IOC) feeds, which are lowlevel and isolated, providing only a narrow view of potential threats. Meanwhile, the extensive and interconnected knowledge found in the unstructured text of numerous OSCTI reports (e.g., security articles, threat reports) available publicly is still largely underexplored. To bridge the gap, we propose THREATKG, an automated system for OSCTI gathering and management. THREATKG efficiently collects a large number of OSCTI reports from multiple sources, leverages specialized AI-based techniques to extract high-quality knowledge about various threat entities and their relationships, and constructs and continuously updates a threat knowledge graph by integrating new OSCTI data. THREATKG features a modular and extensible design, allowing for the addition of components to accommodate diverse OSCTI report structures and knowledge types. Our extensive evaluations demonstrate THREATKG’s practical effectiveness in enhancing threat knowledge gathering and management.en
dc.description.versionPublished versionen
dc.format.mimetypeapplication/pdfen
dc.identifier.doihttps://doi.org/10.1145/3689217.3690613en
dc.identifier.urihttps://hdl.handle.net/10919/123720en
dc.language.isoenen
dc.publisherACMen
dc.rightsCreative Commons Attribution 4.0 Internationalen
dc.rights.holderThe author(s)en
dc.rights.urihttp://creativecommons.org/licenses/by/4.0/en
dc.titleThreatKG: An AI-Powered System for Automated Open-Source Cyber Threat Intelligence Gathering and Managementen
dc.typeArticle - Refereeden
dc.type.dcmitypeTexten

Files

Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
3689217.3690613.pdf
Size:
1.45 MB
Format:
Adobe Portable Document Format
Description:
Published version
License bundle
Now showing 1 - 1 of 1
Name:
license.txt
Size:
1.5 KB
Format:
Item-specific license agreed upon to submission
Description: