arrow
Return

Hyper attack graph: Constructing a hypergraph for cyber threat intelligence analysis

delete2025-02-01
delete0
PRE
AI
J
Junbo Jia
Y
Yang Li *
Y
Yuchen Wang
A
Anyuan Sang
DOI:10.1016/j.cose.2024.104194delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Cybersecurity experts are actively exploring and implementing automated technologies to extract and present attack information from Cyber Threat Intelligence. However, there are multiple relations among security entities within Cyber Threat Intelligence, a feature that existing technologies often overlook. Additionally, integrating external security knowledge into cyber threat intelligence intuitively during analysis and presentation poses challenges. We propose the Hyper Attack Graph (HAG) framework, the first work to apply hypergraph data structures in the analysis of cyber threat intelligence. Our approach uses a joint extraction model that incorporates a multi-head selection mechanism, effectively addressing the extraction of multiple relations among security entities. We use hypergraph to display tactics and techniques in cyber threat intelligence. Our evaluation of the HAG framework on 685 real-world cyber threat intelligence reports shows an increase in the F1 score for security entity extraction by 11.12% and for relation extraction by 6.71% over existing efforts. Furthermore, HAG's ability to visually represent external security knowledge on hypergraphs demonstrates its potential as a valuable tool in cybersecurity analysis.
Keywords:
Cyber threat intelligence
Hypergraph
Relation extraction
Knowledge graph

Journal

C
Computers and Security
IF:
5.4
Papers:
4.6K
Citations:
1.4W

Organization

X
Xidian University
Scholars:
2.4W
Papers: 1.9W
Citations: 9.7K
Cited Papers

Cited Papers

err
IF0
err
err0
PREAI
err
errShare
errSave
Defender Policy Evaluation and Resource Allocation With MITRE ATT&CK Evaluations Data
err2023-05-01
err7
errOAAI
errOutkin, Alexander V.; Schulz, Patricia V.; Schulz, Timothy; Tarman, Thomas D.; Pinar, Ali
errShare
errSave
Cyber-threat intelligence for security decision-making: A review and research agenda for practice
err2023-09-01
err16
errOAAI
errAinslie, Scott; Thompson, Dean; Maynard, Sean; Ahmad, Atif
errShare
errSave
Generalized fuzzy hypergraph for link prediction and identification of influencers in dynamic social media networks
err2024-03-01
err4
errOAAI
errFirouzkouhi, Narjes; Amini, Abbas; Bani-Mustafa, Ahmed; Mehdizadeh, Arash; Damrah, Sadeq; Gholami, Ahmad; Cheng, Chun; Davvaz, Bijan
errShare
errSave
Joint entity recognition and relation extraction as a multi-head selection problem
err2018-12-01
err300
errOAAI
errBekoulis, Giannis; Deleu, Johannes; Demeester, Thomas; Develder, Chris
errShare
errSave
CRF learning with CNN features for image segmentation
err2015-10-01
err177
errOAAI
errLiu, Fayao; Lin, Guosheng; Shen, Chunhua
errShare
errSave
errShare
errSave
A framework for threat intelligence extraction and fusion
err2023-09-01
err13
PREAI
errGuo, Yongyan; Liu, Zhengyu; Huang, Cheng; Wang, Nannan; Min, Hai; Guo, Wenbo; Liu, Jiayong
errShare
errSave
errShare
errSave
researcher View more