返回
Unstructured Big Data Threat Intelligence Parallel Mining Algorithm
DOI:10.26599/BDMA.2023.9020032.png)
摘要
En 中文
To efficiently mine threat intelligence from the vast array of open-source cybersecurity analysis reports on the web, we have developed the Parallel Deep Forest-based Multi-Label Classification (PDFMLC) algorithm. Initially, open-source cybersecurity analysis reports are collected and converted into a standardized text format. Subsequently, five tactics category labels are annotated, creating a multi-label dataset for tactics classification. Addressing the limitations of low execution efficiency and scalability in the sequential deep forest algorithm, our PDFMLC algorithm employs broadcast variables and the Lempel-Ziv-Welch (LZW) algorithm, significantly enhancing its acceleration ratio. Furthermore, our proposed PDFMLC algorithm incorporates label mutual information from the established dataset as input features. This captures latent label associations, significantly improving classification accuracy. Finally, we present the PDFMLC-based Threat Intelligence Mining (PDFMLC-TIM) method. Experimental results demonstrate that the PDFMLC algorithm exhibits exceptional node scalability and execution efficiency. Simultaneously, the PDFMLC-TIM method proficiently conducts text classification on cybersecurity analysis reports, extracting tactics entities to construct comprehensive threat intelligence. As a result, successfully formatted STIX2.1 threat intelligence is established.
Keyword:
unstructured big data mining
parallel deep forest
multi-label classification algorithm
threat intelligence
期刊
IF:
6.2
论文数:
274
被引数:
1.0K
机构
引用论文
Cyber Threat Intelligence Mining for Proactive Cybersecurity Defense: A Survey and New Perspectives用于主动网络安全防御的网络威胁情报挖掘: 调查和新观点
Strategies and Principles of Distributed Machine Learning on Big Data大数据分布式机器学习的策略与原则
ENGINEERING
IF11.6

