Research on knowledge graph construction technology for cyber threat intelligence based on large language models

As the complexity and sophistication of cyber threats continue to increase, integrating cyber threat intelligence into cybersecurity measures has become crucial. A framework called AutoCTI2KG was proposed, which was based on large language models for constructing cyber threat intelligence knowledge...

Full description

Saved in:
Bibliographic Details
Main Authors: LAI Qingnan, JIN Jiandong, ZHOU Changling
Format: Article
Language:zho
Published: Editorial Department of Journal on Communications 2024-11-01
Series:Tongxin xuebao
Subjects:
Online Access:http://www.joconline.com.cn/zh/article/doi/10.11959/j.issn.1000-436x.2024225/
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1841537124017373184
author LAI Qingnan
JIN Jiandong
ZHOU Changling
author_facet LAI Qingnan
JIN Jiandong
ZHOU Changling
author_sort LAI Qingnan
collection DOAJ
description As the complexity and sophistication of cyber threats continue to increase, integrating cyber threat intelligence into cybersecurity measures has become crucial. A framework called AutoCTI2KG was proposed, which was based on large language models for constructing cyber threat intelligence knowledge graphs. Through instruction prompts and context learning, AutoCTI2KG automatically generated cybersecurity and attack knowledge graphs from cyber threat intelligence and provided actionable defense recommendations. Experimental results show that the proposed framework performs excellently in constructing cybersecurity and attack knowledge graphs, with F1 scores around 0.90, demonstrating the potential of large language models in knowledge graph construction in the cybersecurity domain. This work not only advances the frontier of cybersecurity knowledge graph construction but also provides a practical tool for cybersecurity professionals to better understand and mitigate cyber risks.
format Article
id doaj-art-9e52089a6fa54697849bf4a38e17f4f7
institution Kabale University
issn 1000-436X
language zho
publishDate 2024-11-01
publisher Editorial Department of Journal on Communications
record_format Article
series Tongxin xuebao
spelling doaj-art-9e52089a6fa54697849bf4a38e17f4f72025-01-14T08:46:25ZzhoEditorial Department of Journal on CommunicationsTongxin xuebao1000-436X2024-11-0145334379661066Research on knowledge graph construction technology for cyber threat intelligence based on large language modelsLAI QingnanJIN JiandongZHOU ChanglingAs the complexity and sophistication of cyber threats continue to increase, integrating cyber threat intelligence into cybersecurity measures has become crucial. A framework called AutoCTI2KG was proposed, which was based on large language models for constructing cyber threat intelligence knowledge graphs. Through instruction prompts and context learning, AutoCTI2KG automatically generated cybersecurity and attack knowledge graphs from cyber threat intelligence and provided actionable defense recommendations. Experimental results show that the proposed framework performs excellently in constructing cybersecurity and attack knowledge graphs, with F1 scores around 0.90, demonstrating the potential of large language models in knowledge graph construction in the cybersecurity domain. This work not only advances the frontier of cybersecurity knowledge graph construction but also provides a practical tool for cybersecurity professionals to better understand and mitigate cyber risks.http://www.joconline.com.cn/zh/article/doi/10.11959/j.issn.1000-436x.2024225/knowledge graphlarge language modelthreat intelligencecybersecurityartificial intelligence
spellingShingle LAI Qingnan
JIN Jiandong
ZHOU Changling
Research on knowledge graph construction technology for cyber threat intelligence based on large language models
Tongxin xuebao
knowledge graph
large language model
threat intelligence
cybersecurity
artificial intelligence
title Research on knowledge graph construction technology for cyber threat intelligence based on large language models
title_full Research on knowledge graph construction technology for cyber threat intelligence based on large language models
title_fullStr Research on knowledge graph construction technology for cyber threat intelligence based on large language models
title_full_unstemmed Research on knowledge graph construction technology for cyber threat intelligence based on large language models
title_short Research on knowledge graph construction technology for cyber threat intelligence based on large language models
title_sort research on knowledge graph construction technology for cyber threat intelligence based on large language models
topic knowledge graph
large language model
threat intelligence
cybersecurity
artificial intelligence
url http://www.joconline.com.cn/zh/article/doi/10.11959/j.issn.1000-436x.2024225/
work_keys_str_mv AT laiqingnan researchonknowledgegraphconstructiontechnologyforcyberthreatintelligencebasedonlargelanguagemodels
AT jinjiandong researchonknowledgegraphconstructiontechnologyforcyberthreatintelligencebasedonlargelanguagemodels
AT zhouchangling researchonknowledgegraphconstructiontechnologyforcyberthreatintelligencebasedonlargelanguagemodels