Context-aware Entity-Relation Extraction Pipeline for Threat Intelligence Knowledge Graphs
Контекстно-зависимый конвейер извлечения сущностей и отношений для графов знаний о киберугрозах
2025-01-07
SCID: 54.1/j5kqdjb6
Discuss with AI
STIX-2.1SecureBERT embeddingsentity-relation extractionnamed entity recognitionthreat intelligence knowledge graphs
Figures from the paper
Abstract (AI)
Cybersecurity knowledge graphs (CKGs) integrate diverse sources of cyber threat intelligence (CTI) into a structured, queryable format, offering scalable solutions for automating proactive and real-time security responses. This has led to their increased adoption, improving the workflow and effectiveness of security professionals. However, constructing CKGs requires extracting entity-relation triples from unstructured reports, a process complicated by report complexity, specialized cybersecurity terminologies, and language ambiguity. As a result, existing pipeline approaches suffer from error propagation, resulting in low accuracy and poor generalizability. This paper introduces the Context-aware Threat Intelligence Knowledge Graph (CTiKG) framework, designed to accurately identify and classify threat entities and their relationships from CTI reports. CTiKG integrates hybrid NLP models that leverage SecureBERT embeddings and expert knowledge encoded in an ontology to control classification errors and reduce error propagation, thereby enhancing extraction accuracy. Evaluations using the augmented DNRTI-STIX2 dataset, which features 21 entity categories adhering to STIX-2.1 standards, demonstrate the model's superior performance compared to state-of-the-art methods, with increases of 2-3% in NER and up to 5% in RE in terms of precision, recall, and F1-scores. Further validation on the DNRTI and STUCCO datasets and a practical cybersecurity use case illustrate the framework's robustness. The DNRTI-STIX2 and curated CTI datasets are available on GitHub to support further research.
Key Findings
1
CTiKG combines SecureBERT embeddings with ontology-based expert knowledge to control classification errors and reduce pipeline error propagation.
2
CTiKG improves relation-extraction precision, recall, and F1-scores by up to 5% compared with state-of-the-art approaches.
3
On the augmented DNRTI-STIX2 dataset with 21 STIX-2.1 entity categories, CTiKG improves NER performance by 2–3% over state-of-the-art methods.
4
The CTiKG framework extracts threat entities and relationships from unstructured CTI reports using context-aware hybrid NLP models.
5
Validation on DNRTI, STUCCO, and a practical cybersecurity use case demonstrates the framework’s robustness; curated datasets are released on GitHub.
Research Object
cyber threat intelligence reports and the threat intelligence knowledge graphs constructed from them
Research Subject
context-aware extraction and classification of threat entities and their relationships, including accuracy, error propagation, and generalizability
Publication Details
Publication Date
2025-01-07
Journal
Publisher
ISSN
Cited by
1
Open access PDF
Access Type
Author Information
Download PDF
Subscribe to digest