To remain aware of the fast-evolving cyber threat landscape, open-source Cyber Threat Intelligence (OSCTI) has received growing attention from the community. Commonly, knowledge about threats is presented in a vast number of OSCTI reports. Despite the pressing need for high-quality OSCTI, existing OSCTI gathering and management platforms, however, have primarily focused on isolated, low-level Indicators of Compromise. On the other hand, higher-level concepts (e.g., adversary tactics, techniques, and procedures) and their relationships have been overlooked, which contain essential knowledge about threat behaviors that is critical to uncovering the complete threat scenario. To bridge the gap, we propose SecurityKG, a system for automated OSCTI gathering and management. SecurityKG collects OSCTI reports from various sources, uses a combination of AI and NLP techniques to extract high-fidelity knowledge about threat behaviors, and constructs a security knowledge graph. SecurityKG also provides a UI that supports various types of interactivity to facilitate knowledge graph exploration.
翻译:为保持对迅速演变的网络威胁景观的认识,开放源码网络威胁情报(OSCTI)日益受到社区的注意,一般而言,关于威胁的知识出现在大量OSCTI报告中,尽管迫切需要高质量的OSCTI,但现有的OSCTI收集和管理平台主要侧重于孤立的、低层次的妥协指标;另一方面,更高层次的概念(如对立战术、技术和程序)及其关系受到忽视,这些概念包含对发现整个威胁情景至关重要的威胁行为的基本知识;为弥合差距,我们提议SecurityKG,这是一个自动收集和管理OSCTI的系统;SecurityKG收集来自各种来源的OSCTI报告,使用AI和NLP技术的组合,以获取关于威胁行为的高信仰知识,并构建一个安全知识图表;Securg还提供了一种支持各种互动活动的UI,以促进知识图表的勘探。