arXiv:cs.AI· Nikolaos Kekatos, Mihaela Curc\u{a}, Georgios Koutidis, Mihai Nena, Tom Nianios, Robert-\c{S}tefan \c{S}andru, Michael Ioannou, Charalambos Bratsas·· 10 小时前AI 评分34
CG-CTI:从沙箱到自动化执行的可信威胁情报流水线
From Sandbox to Enforcement: Confidence-Qualified Threat Intelligence for Critical Infrastructure
AI 导读
研究者提出 CG-CTI 流水线,将 CAPEv2 沙箱的实时输出转为 STIX 2.1 格式,并依据来源、跨源印证与观测持久性为每个情报对象标注置信度状态,仅高置信情报可自动执行,低置信对象转交分析师或留存参考。
正文
Abstract:Security operations centres and national incident-response teams defending critical infrastructure collect abundant threat data yet struggle to turn it into actionable intelligence. A malware sandbox produces detailed behavioural evidence, but as a large, unranked report whose confidence is unstated. We present CG-CTI, an operational pipeline that converts live sandbox output (CAPEv2) into STIX 2.1, correlates it in a knowledge graph with other critical-infrastructure sensors, and attaches to every intelligence object an explicit confidence status derived from provenance, cross-source corroboration, and observation durability. This status gates automated action: only corroborated intelligence is eligible for automated enforcement, while lower-confidence objects are routed to analyst review or kept as context. A grounded language-model stage then narrates the confidence-qualified evidence, where each statement either cites a supporting object or is marked unsupported, so fabricated references are removed before analyst review. We implement CG-CTI within the CYBERGUARD project, whose consortium includes Romania's national cyber-security directorate, and evaluate it against the live sandbox on a labelled malware corpus, measuring conversion validity, indicator yield, technique coverage, corroboration, enforcement eligibility, latency, and summary grounding. CG-CTI turns fragmented sandbox output into corroborated, confidence-ranked, and auditable intelligence for critical-infrastructure defence.
| Comments: | 20 pages, 3 figures. Accepted at the 21st International Conference on Critical Information Infrastructures Security (CRITIS 2026) |
| Subjects: | Cryptography and Security (cs.CR); Artificial Intelligence (cs.AI) |
| Cite as: | arXiv:2610.07310 [cs.CR] |
| (or arXiv:2610.07310v1 [cs.CR] for this version) | |
| https://doi.org/10.48550/arXiv.2610.07310 arXiv-issued DOI via DataCite (pending registration) |
Submission history
From: Nikolaos Kekatos [view email]
[v1]
Mon, 5 Oct 2026 19:47:45 UTC (82 KB)
来源:arXiv:cs.AI · arxiv.org