ThreatPilot: Attack-Driven Threat Intelligence Extraction
Ming Xu, Hongtai Wang, Jiahao Liu, Xinfeng Li, Zhengmin Yu, Weili Han, Hoon Wei Lim, Jin Song Dong, Jiaheng Zhang

TL;DR
ThreatPilot is a novel system that extracts comprehensive layered threat intelligence from reports, capturing tactics and techniques to improve detection accuracy and automate rule generation for cybersecurity defenses.
Contribution
It introduces a method to extract complete adversarial behaviors and integrates this intelligence into security applications, surpassing existing fragmented approaches.
Findings
Outperforms state-of-the-art in threat intelligence extraction with 1.34X F1 score improvement.
Significantly enhances attack detection accuracy in real-world logs.
Automates rule generation, saving time and costs for security teams.
Abstract
Efficient defense against dynamically evolving advanced persistent threats (APT) requires the structured threat intelligence feeds, such as techniques used. However, existing threat-intelligence extraction techniques predominantly focuses on individual pieces of intelligence-such as isolated techniques or atomic indicators-resulting in fragmented and incomplete representations of real-world attacks. This granularity inherently limits on both the depth and the contextual richness of the extracted intelligence, making it difficult for downstream security systems to reason about multi-step behaviors or to generate actionable detections. To address this gap, we propose to extract the layered Attack-driven Threat Intelligence (ATIs), a comprehensive representation that captures the full spectrum of adversarial behavior. We propose ThreatPilot, which can accurately identify the AITs including…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsNetwork Security and Intrusion Detection · Advanced Malware Detection Techniques
