LOCALINTEL: Generating Organizational Threat Intelligence from Global and Local Cyber Knowledge
Shaswata Mitra, Subash Neupane, Trisha Chakraborty, Sudip Mittal,, Aritran Piplai, Manas Gaur, Shahram Rahimi

TL;DR
LocalIntel is an automated framework that leverages large language models to generate organization-specific threat intelligence by integrating global threat reports with internal knowledge bases, significantly aiding Security Operations Centers.
Contribution
The paper introduces LocalIntel, a novel framework that automates threat intelligence generation by combining global threat data and internal repositories using LLMs, improving efficiency and accuracy.
Findings
Achieved up to 93% accuracy in threat intelligence generation
Demonstrated 64% inter-rater agreement in assessments
Effectively integrates global and local cyber knowledge sources
Abstract
Security Operations Center (SoC) analysts gather threat reports from openly accessible global threat repositories and tailor the information to their organization's needs, such as developing threat intelligence and security policies. They also depend on organizational internal repositories, which act as private local knowledge database. These local knowledge databases store credible cyber intelligence, critical operational and infrastructure details. SoCs undertake a manual labor-intensive task of utilizing these global threat repositories and local knowledge databases to create both organization-specific threat intelligence and mitigation policies. Recently, Large Language Models (LLMs) have shown the capability to process diverse knowledge sources efficiently. We leverage this ability to automate this organization-specific threat intelligence generation. We present LocalIntel, a novel…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsInformation and Cyber Security · Intelligence, Security, War Strategy · Terrorism, Counterterrorism, and Political Violence
