AECR: Automatic attack technique intelligence extraction based on fine-tuned large language model

被引:0
|
作者
机构
[1] [1,Chen, Minghao
[2] 3,Zhu, Kaijie
[3] 1,Lu, Bin
[4] 1,Li, Ding
[5] 1,Yuan, Qingjun
[6] 1,Zhu, Yuefei
来源
关键词
Cyber attacks;
D O I
10.1016/j.cose.2024.104213
中图分类号
学科分类号
摘要
Cyber Threat Intelligence (CTI) reports contain resourceful intelligence on cyber-attack campaigns, which provides great help for security analysts to infer attack trends and enhance their defenses. However, due to the diversity of report content and writing styles, current intelligence extraction is mostly based on time-consuming manual efforts. Moreover, existing automatic methods generally neglect the importance of background knowledge and produce inexact extraction results. These problems prevent the effective utilization and sharing of intelligence from CTI reports. In this paper, we primarily focus on the automatic extraction of attack technique (AT) intelligence, which reveals patterns of attack behaviors and hardly changes over time. We propose a novel automatic AT extraction pipeline for CTI reports (AECR). AECR explores the feasibility of extracting AT intelligence based on a fined-tuned large language model (LLM). Particularly, we endow the selected LLM with enhanced domain-specific knowledge to improve its comprehension of AT-relevant content and alleviate the hallucination problem. Experimental results demonstrate that AECR outperforms state-of-the-art methods by a wide margin with a reasonable time cost. Specifically, we improve the accuracy, precision, recall, and F1-score by 108%, 37.2%, 22.4%, and 67.5% respectively. To the best of our knowledge, AECR is the first to perform AT extraction based on fine-tuned LLM. © 2024 Elsevier Ltd
引用
收藏
相关论文
共 50 条
  • [41] Online aggression detection using ensemble techniques on fine-tuned transformer-based language models
    Chinivar S.
    Roopa M.S.
    Arunalatha J.S.
    Venugopal K.R.
    International Journal of Computers and Applications, 2024, 46 (08) : 567 - 579
  • [42] A fine-tuned multimodal large model for power defect image-text question-answering
    Wang, Qiqi
    Zhang, Jie
    Du, Jianming
    Zhang, Ke
    Li, Rui
    Zhao, Feng
    Zou, Le
    Xie, Chengjun
    SIGNAL IMAGE AND VIDEO PROCESSING, 2024, : 9191 - 9203
  • [43] Dual data mapping with fine-tuned large language models and asset administration shells toward interoperable knowledge representation
    Shi, Dachuan
    Meyer, Olga
    Oberle, Michael
    Bauernhansl, Thomas
    ROBOTICS AND COMPUTER-INTEGRATED MANUFACTURING, 2025, 91
  • [44] Small Pre-trained Language Models Can be Fine-tuned as Large Models via Over-Parameterization
    Gao, Ze-Feng
    Zhou, Kun
    Liu, Peiyu
    Zhao, Wayne Xin
    Wen, Ji-Rong
    PROCEEDINGS OF THE 61ST ANNUAL MEETING OF THE ASSOCIATION FOR COMPUTATIONAL LINGUISTICS, ACL 2023, VOL 1, 2023, : 3819 - 3834
  • [45] Multi-LoRA Fine-Tuned Segment Anything Model for Urban Man-Made Object Extraction
    Lu, Xiaoyan
    Weng, Qihao
    IEEE TRANSACTIONS ON GEOSCIENCE AND REMOTE SENSING, 2024, 62
  • [46] Diagnosis of Leukaemia in Blood Slides Based on a Fine-Tuned and Highly Generalisable Deep Learning Model
    Vogado, Luis
    Veras, Rodrigo
    Aires, Kelson
    Araujo, Flavio
    Silva, Romuere
    Ponti, Moacir
    Tavares, Joao Manuel R. S.
    SENSORS, 2021, 21 (09)
  • [47] Novel Fine-tuned Model-based SRAF Generation Method Using Coherence Map
    Kodera, Katsuyoshi
    Tanaka, Satoshi
    Yamaji, Mikiyasu
    Kodama, Chikaaki
    Kotani, Toshiya
    Nojima, Shigeki
    Hashimoto, Koji
    Mimotogi, Shoji
    Inoue, Soichi
    OPTICAL MICROLITHOGRAPHY XXIII, 2010, 7640
  • [48] Fine-tuned artificial intelligence model using pigeon optimizer for prediction of residual stresses during turning of Inconel 718
    Elsheikh, Ammar H.
    Muthuramalingam, T.
    Shanmugan, S.
    Ibrahim, Ahmed Mohamed Mahmoud
    Ramesh, B.
    Khoshaim, Ahmed B.
    Moustafa, Essam B.
    Bedairi, Badr
    Panchal, Hitesh
    Sathyamurthy, Ravishankar
    JOURNAL OF MATERIALS RESEARCH AND TECHNOLOGY-JMR&T, 2021, 15 : 3622 - 3634
  • [49] NDLP Phishing: A Fine-Tuned Application to Detect Phishing Attacks Based on Natural Language Processing and Deep Learning
    Benavides-Astudillo E.
    Fuertes W.
    Sanchez-Gordon S.
    Nuñez-Agurto D.
    International Journal of Interactive Mobile Technologies, 2024, 18 (10): : 173 - 190
  • [50] Fine-tuned convolutional neural networks for feature extraction and classification of scanned document images using semi-automatic labelling approach
    Kumar, Krishna
    Mudiraj, Nakkala Srinivas
    Mittal, Meenakshi
    Singh, Satwinder
    INTERNATIONAL JOURNAL OF INTELLIGENT ENGINEERING INFORMATICS, 2024, 12 (01) : 103 - 134