MITREtrieval: Retrieving MITRE Techniques From Unstructured Threat Reports by Fusion of Deep Learning and Ontology

计算机科学 本体论 人工智能 合并(版本控制) 深度学习 对手 鉴定(生物学) 机器学习 数据科学 情报检索 计算机安全 哲学 认识论 植物 生物
作者
Yi-Ting Huang,R. Vaitheeshwari,Meng Chang Chen,Ying‐Dar Lin,Ren‐Hung Hwang,Po‐Ching Lin,Yuan‐Cheng Lai,Eric Hsiao‐Kuang Wu,Chung‐Hsuan Chen,Zi-Jie Liao,Chung-Kuan Chen
出处
期刊:IEEE Transactions on Network and Service Management [Institute of Electrical and Electronics Engineers]
卷期号:21 (4): 4871-4887 被引量:1
标识
DOI:10.1109/tnsm.2024.3401200
摘要

Cyber Threat Intelligence (CTI) plays a crucial role in understanding and preemptively defending against emerging threats. Typically disseminated through unstructured reports, CTI encompasses detailed insights into threat actors, their actions, and attack patterns. The MITRE ATT&CK framework offers a comprehensive catalog of adversary tactics, techniques, and procedures (TTPs), serving as a valuable resource for deciphering attacker behavior and enhancing defensive measures. Addressing the challenge of time-consuming manual analysis of MITRE TTPs in unstructured CTI reports, this paper presents MITREtrieval, a novel system that leverages deep learning and ontology to efficiently extract MITRE techniques. This approach mitigates issues related to the implicit nature of TTPs, textual semantic dependencies, and the scarcity of adequately labeled datasets, enabling more effective analysis even with limited sample sizes. Our approach combines a sophisticated sentence-level BERT deep learning model with ontology knowledge to address sparse data challenges, using a voting algorithm to merge outcomes. This results in a more accurate classification of MITRE techniques, capturing contextual nuances effectively. Our evaluation confirms MITREtrieval's effectiveness in identifying techniques, regardless of their representation in training samples. MITREtrieval has surpassed benchmarks, achieving F2 scores of 58%, 62%, and 69% in multi-label technique identification across 113, 46, and 23 CTI reports, respectively, thereby streamlining CTI analysis and improving threat intelligence.

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
荣哥儿发布了新的文献求助80
刚刚
英姑应助开朗筮采纳,获得10
刚刚
打打应助常璐旸采纳,获得10
刚刚
小丸子发布了新的文献求助10
刚刚
宁1完成签到,获得积分10
1秒前
1秒前
3469907229完成签到 ,获得积分10
1秒前
1秒前
man完成签到,获得积分10
2秒前
精明冬卉发布了新的文献求助10
2秒前
2秒前
莉莉周发布了新的文献求助10
3秒前
Lucas应助Luffy采纳,获得10
3秒前
Hello应助不说再见采纳,获得10
4秒前
叮叮叮铛完成签到,获得积分0
4秒前
Akim应助ZWL001采纳,获得10
4秒前
5秒前
5秒前
6秒前
CodeCraft应助dd采纳,获得10
6秒前
cvev发布了新的文献求助10
6秒前
83048815发布了新的文献求助30
6秒前
7秒前
7秒前
友好冥王星完成签到 ,获得积分10
7秒前
7秒前
星球日记发布了新的文献求助10
7秒前
大大小发布了新的文献求助10
8秒前
Akim应助知性的半仙采纳,获得10
8秒前
LMX发布了新的文献求助10
8秒前
8秒前
8秒前
8秒前
戴衡霞发布了新的文献求助10
9秒前
9秒前
一念初见完成签到 ,获得积分10
9秒前
9秒前
9秒前
9秒前
9秒前
高分求助中
(应助此贴封号)【重要!!请各用户(尤其是新用户)详细阅读】【科研通的精品贴汇总】 10000
Les Mantodea de Guyane Insecta, Polyneoptera 2000
Quality by Design - An Indispensable Approach to Accelerate Biopharmaceutical Product Development 800
Pulse width control of a 3-phase inverter with non sinusoidal phase voltages 777
Signals, Systems, and Signal Processing 610
Research Methods for Applied Linguistics: A Practical Guide 600
Research Methods for Applied Linguistics 500
热门求助领域 (近24小时)
化学 材料科学 医学 生物 纳米技术 工程类 有机化学 化学工程 生物化学 计算机科学 物理 内科学 复合材料 催化作用 物理化学 光电子学 电极 细胞生物学 基因 无机化学
热门帖子
关注 科研通微信公众号,转发送积分 6406314
求助须知:如何正确求助?哪些是违规求助? 8225601
关于积分的说明 17442031
捐赠科研通 5458980
什么是DOI,文献DOI怎么找? 2884547
邀请新用户注册赠送积分活动 1860932
关于科研通互助平台的介绍 1701701