arrow
Return

ACTIC: A Large Language Model-Based Method for Threat Intelligence Perception

delete2026-04-21
delete0
PRE
AI
L
Liu, Changcheng
Y
Yang, Changheng
M
Ma, Jun *
DOI:10.1049/cmu2.70162delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
With the increasing complexity and stealthiness of cyber-attacks, conventional threat intelligence analysis methods face challenges such as low processing efficiency, limited semantic comprehension, and difficulties in adapting to dynamic, multi-source, and heterogeneous data. To enhance threat intelligence awareness, this study introduces an automated method for constructing a threat intelligence knowledge graph using large language models, named ACTIC. This approach utilises a locally deployed DeepSeek-32B model, combined with prompt engineering and Low-Rank Adaptation (LoRA) fine-tuning, to extract entities, relationships, and attack steps from unstructured threat intelligence reports. The process produces a dual-layer knowledge graph, comprising a Threat Intelligence Knowledge Graph and an Attack Knowledge Graph. Additionally, ACTIC incorporates the ATT&CK framework for classifying tactics, techniques, and procedures (TTPs), while enabling threat search and protective recommendation generation based on the knowledge graph. Experimental results demonstrate that ACTIC improves F1-scores by 10.4% and 10.6% for entity recognition and relation extraction, and by 13.3% and 10.9% for TTP classification, respectively, significantly outperforming the baseline model. The findings demonstrate the applicability of large language models in local cybersecurity environments and provide an effective approach for developing proactive, intelligent threat detection and response systems.
Keywords:
knowledge graph
large language model
threat intelligence

Journal

IET Communications cover
IET Communications
IF:
1.6
Papers:
130
Citations:
2.9K

Organization

P
pla information engineering university
Scholars:
2.8K
Papers: 1.6K
Citations: 2