跳到正文
arXiv:cs.AI· Nikolaos Kekatos, Mihaela Curc\u{a}, Georgios Koutidis, Mihai Nena, Tom Nianios, Robert-\c{S}tefan \c{S}andru, Michael Ioannou, Charalambos Bratsas·· 10 小时前AI 评分34

CG-CTI:从沙箱到自动化执行的可信威胁情报流水线

From Sandbox to Enforcement: Confidence-Qualified Threat Intelligence for Critical Infrastructure

AI 导读

研究者提出 CG-CTI 流水线,将 CAPEv2 沙箱的实时输出转为 STIX 2.1 格式,并依据来源、跨源印证与观测持久性为每个情报对象标注置信度状态,仅高置信情报可自动执行,低置信对象转交分析师或留存参考。

正文

View PDF HTML (experimental)

Abstract:Security operations centres and national incident-response teams defending critical infrastructure collect abundant threat data yet struggle to turn it into actionable intelligence. A malware sandbox produces detailed behavioural evidence, but as a large, unranked report whose confidence is unstated. We present CG-CTI, an operational pipeline that converts live sandbox output (CAPEv2) into STIX 2.1, correlates it in a knowledge graph with other critical-infrastructure sensors, and attaches to every intelligence object an explicit confidence status derived from provenance, cross-source corroboration, and observation durability. This status gates automated action: only corroborated intelligence is eligible for automated enforcement, while lower-confidence objects are routed to analyst review or kept as context. A grounded language-model stage then narrates the confidence-qualified evidence, where each statement either cites a supporting object or is marked unsupported, so fabricated references are removed before analyst review. We implement CG-CTI within the CYBERGUARD project, whose consortium includes Romania's national cyber-security directorate, and evaluate it against the live sandbox on a labelled malware corpus, measuring conversion validity, indicator yield, technique coverage, corroboration, enforcement eligibility, latency, and summary grounding. CG-CTI turns fragmented sandbox output into corroborated, confidence-ranked, and auditable intelligence for critical-infrastructure defence.
Comments: 20 pages, 3 figures. Accepted at the 21st International Conference on Critical Information Infrastructures Security (CRITIS 2026)
Subjects: Cryptography and Security (cs.CR); Artificial Intelligence (cs.AI)
Cite as: arXiv:2610.07310 [cs.CR]
  (or arXiv:2610.07310v1 [cs.CR] for this version)
  https://doi.org/10.48550/arXiv.2610.07310

arXiv-issued DOI via DataCite (pending registration)

Submission history

From: Nikolaos Kekatos [view email]
[v1] Mon, 5 Oct 2026 19:47:45 UTC (82 KB)

来源:arXiv:cs.AI · arxiv.org