Entity and relation extractions for threat intelligence knowledge graphs

Извлечение сущностей и отношений для графов знаний о киберугрозах
Inoussa Mouiche, Sherif Saad
2024-09-19

SecureBERTattention-based BiLSTMcyber threat intelligenceentity and relation extractionthreat intelligence knowledge graphs
Advanced persistent threats (APTs) represent a complex challenge in cybersecurity as they infiltrate networks stealthily to conduct espionage, steal data, and maintain a long-term presence. To combat these threats, security professionals increasingly rely on cyber knowledge graphs (CKGs), which provide scalable solutions to analyze and structure vast amounts of cyber threat intelligence (CTI) from diverse sources in real-time, enabling the automation of proactive security measures. Developing CKGs requires extracting entity and their relationships from unstructured CTI reports. However, existing approaches face significant limitations, such as difficulties with the nuances of cybersecurity language, diverse threat terminologies, and high rates of error propagation, resulting in low accuracy and poor generalizability. This paper introduces a novel Threat Intelligence Knowledge Graph (TiKG) pipeline designed to address these challenges. The TiKG framework leverages SecureBERT, a domain-specific transformer-based model optimized for cybersecurity, and integrates it with an attention-based BiLSTM to capture the context and nuances of security texts, reducing error propagation and improving extraction accuracy. Additionally, the pipeline incorporates a domain-specific ontology and inference model to ensure precise relation mapping in relation extraction. Using three large-scale TI open-source datasets (DNRTI, STUCCO, and CYNER) and a curated CTI dataset, extensive evaluations demonstrate the effectiveness of our framework, showing significant improvements over existing methods in detecting and linking cyber threats. These contributions provide a robust platform for security professionals to analyze and predict potential attacks, develop effective defenses, and enhance the strategic capabilities of cybersecurity operations.
1
A domain-specific ontology and inference model support precise relation mapping in threat intelligence relation extraction.
2
Evaluations on DNRTI, STUCCO, CYNER, and a curated CTI dataset show significant improvements over existing methods in detecting and linking cyber threats.
3
The framework is intended to strengthen automated threat analysis, attack prediction, defensive planning, and cybersecurity operations.
4
The paper introduces a Threat Intelligence Knowledge Graph pipeline for extracting entities and relationships from unstructured cyber threat intelligence reports.
5
The pipeline combines the cybersecurity-specific SecureBERT model with an attention-based BiLSTM to capture domain context and reduce error propagation during extraction.

unstructured cyber threat intelligence reports concerning advanced persistent threats

accurate extraction and semantic linking of cybersecurity entities and their relationships for threat intelligence knowledge graphs

Publication Details
Publication Date
2024-09-19
Journal
Publisher
ISSN
Cited by
37
Access Type
Author Information
Authors
Inoussa Mouiche
Sherif Saad
Explore further
Open the scid.ai AI chat with a ready-made request: it will find papers on a similar topic and help build a literature review.
Find similar papers in the chat
Make a presentation
100%