AttacKG: Constructing Technique Knowledge Graph from Cyber Threat Intelligence Reports
Zhenyuan Li, Jun Zeng, Yan Chen, Zhenkai Liang

TL;DR
AttacKG automatically extracts and aggregates structured attack behavior graphs from cyber threat intelligence reports, significantly improving the identification of attack techniques and supporting security tasks like attack detection.
Contribution
This paper introduces AttacKG, a novel method for converting unstructured CTI reports into comprehensive technique knowledge graphs, outperforming existing approaches in accuracy.
Findings
Effectively identifies 28,262 attack techniques from 1,515 reports.
Achieves high F1-scores of 0.887, 0.896, and 0.789 in entity, dependency, and technique extraction.
Outperforms state-of-the-art methods in extracting threat intelligence.
Abstract
Cyber attacks are becoming more sophisticated and diverse, making detection increasingly challenging. To combat these attacks, security practitioners actively summarize and exchange their knowledge about attacks across organizations in the form of cyber threat intelligence (CTI) reports. However, as CTI reports written in natural language texts are not structured for automatic analysis, the report usage requires tedious manual efforts of cyber threat intelligence recovery. Additionally, individual reports typically cover only a limited aspect of attack patterns (techniques) and thus are insufficient to provide a comprehensive view of attacks with multiple variants. To take advantage of threat intelligence delivered by CTI reports, we propose AttacKG to automatically extract structured attack behavior graphs from CTI reports and identify the adopted attack techniques. We then aggregate…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsCybercrime and Law Enforcement Studies · Information and Cyber Security · Terrorism, Counterterrorism, and Political Violence
