| 1 |
于丰瑞. 网络威胁技战术情报自动化识别提取研究综述. 计算机工程与应用, 2024, 60 (13): 1- 22.
doi: 10.3778/j.issn.1002-8331.2309-0489
|
|
YU F R . Survey on automated recognition and extraction of TTPs. Computer Engineering and Applications, 2024, 60 (13): 1- 22.
doi: 10.3778/j.issn.1002-8331.2309-0489
|
| 2 |
周雨欣, 卢明欣, 杨海平. 美国网络威胁情报公私合作模式及启示. 情报杂志, 2023, 42 (3): 24- 33.
doi: 10.3969/j.issn.1002-1965.2023.03.004
|
|
ZHOU Y X , LU M X , YANG H P . Review of public-private partnership of U. S. cyber threat intelligence and its enlightenment. Journal of Intelligence, 2023, 42 (3): 24- 33.
doi: 10.3969/j.issn.1002-1965.2023.03.004
|
| 3 |
SCHLETTE D , BÖHM F , CASELLI M , et al. Measuring and visualizing cyber threat intelligence quality. International Journal of Information Security, 2021, 20 (1): 21- 38.
doi: 10.1007/s10207-020-00490-y
|
| 4 |
胡勉宁, 李欣, 李明锋, 等. 面向前端防范的网络威胁情报细粒度本体研究. 情报杂志, 2023, 42 (9): 135-140, 148.
doi: 10.3969/j.issn.1002-1965.2023.09.019
|
|
HU M N , LI X , LI M F , et al. Research on fine-grained ontology of network threat intelligence for front-end prevention. Journal of Intelligence, 2023, 42 (9): 135-140, 148.
doi: 10.3969/j.issn.1002-1965.2023.09.019
|
| 5 |
SHU X K, ARAUJO F, SCHALES D L, et al. Threat intelligence computing[C]//Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security. New York, USA: ACM Press, 2018: 1883-1898.
|
| 6 |
马恒志, 钱育蓉, 冷洪勇, 等. 知识图谱嵌入研究进展综述. 计算机工程, 2025, 51 (2): 18- 34.
doi: 10.19678/j.issn.1000-3428.0068386
|
|
MA H Z , QIAN Y R , LENG H Y , et al. Review of research progress on knowledge graph embedding. Computer Engineering, 2025, 51 (2): 18- 34.
doi: 10.19678/j.issn.1000-3428.0068386
|
| 7 |
SUN N , DING M , JIANG J J , et al. Cyber threat intelligence mining for proactive cybersecurity defense: a survey and new perspectives. IEEE Communications Surveys & Tutorials, 2023, 25 (3): 1748- 1774.
|
| 8 |
BRIDGES R A, JONES C L, IANNACONE M D, et al. Automatic labeling for entity extraction in cyber security[EB/OL]. [2024-10-09]. https://arxiv.org/abs/1308.4941.
|
| 9 |
CHAN H J, HSU C Y, CHIEN C C, et al. FeedRef2022: a named entity recognition dataset for extracting indicators of compromise[C]//Proceedings of the IEEE International Conference on Big Data (Big Data). Washington D.C., USA: IEEE Press, 2023: 2578-2584.
|
| 10 |
CHRISTIAN R, DUTTA S, PARK Y, et al. An ontology-driven knowledge graph for Android malware[C]//Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security. New York, USA: ACM Press, 2021: 2435-2437.
|
| 11 |
AKBAR K A, HALIM S M, SINGHAL A, et al. The design of an ontology for ATT & CK and its application to cybersecurity[C]//Proceedings of the 13th ACM Conference on Data and Application Security and Privacy. New York, USA: ACM Press, 2023: 295-297.
|
| 12 |
MERAH Y, KENAZA T. Proactive ontology-based cyber threat intelligence analytic[C]//Proceedings of the International Conference on Recent Advances in Mathematics and Informatics (ICRAMI). Washington D.C., USA: IEEE Press, 2021: 1-7.
|
| 13 |
WEI Y , BO L L , SUN X B , et al. Automated event extraction of CVE descriptions. Information and Software Technology, 2023, 158, 107178.
doi: 10.1016/j.infsof.2023.107178
|
| 14 |
WANG X R, HE S H, XIONG Z H, et al. APTNER: a specific dataset for NER missions in cyber threat intelligence field[C]//Proceedings of the IEEE 25th International Conference on Computer Supported Cooperative Work in Design (CSCWD). Washington D.C., USA: IEEE Press, 2022: 1233-1238.
|
| 15 |
LANGE L, MVLLER M, TORBATI G H, et al. AnnoCTR: a dataset for detecting and linking entities, tactics, and techniques in cyber threat reports[EB/OL]. [2024-10-09]. https://arxiv.org/abs/2404.07765.
|
| 16 |
LIM S K, MUIS A O, LU W, et al. MalwareTextDB: a database for annotated malware articles[C]//Proceedings of the 55th Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). Vancouver, Canada: Association for Computational Linguistics, 2017: 1557-1567.
|
| 17 |
WANG X R, LIU X P, AO S Q, et al. DNRTI: a large-scale dataset for named entity recognition in threat intelligence[C]//Proceedings of the IEEE 19th International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom). Washington D.C., USA: IEEE Press, 2020: 1842-1848.
|
| 18 |
|
| 19 |
LUO Y L, AO S Q, LUO N, et al. Extracting threat intelligence relations using distant supervision and neural networks[C]//Proceedings of Advances in Digital Forensics XVII. Berlin, Germany: Springer, 2021: 193-211.
|
| 20 |
KIM G , LEE C , JO J , et al. Automatic extraction of named entities of cyber threats using a deep Bi-LSTM-CRF network. International Journal of Machine Learning and Cybernetics, 2020, 11 (10): 2341- 2355.
doi: 10.1007/s13042-020-01122-6
|
| 21 |
LEGOY V, CASELLI M, SEIFERT C, et al. Automated retrieval of ATT & CK tactics and techniques for cyber threat reports[EB/OL]. [2024-10-09]. https://arxiv.org/abs/2004.14322.
|
| 22 |
TSAI C E, YANG C L, CHEN C K. CTI ANT: hunting for Chinese threat intelligence[C]//Proceedings of the IEEE International Conference on Big Data. Washington D.C., USA: IEEE Press, 2021: 1847-1852.
|
| 23 |
LIU Y, SHI R, CHEN Y H, et al. APTTOOLNER: a Chinese dataset of cyber security tool for NER task[C]//Proceedings of the 3rd Asia-Pacific Conference on Communications Technology and Computer Science (ACCTCS). Washington D.C., USA: IEEE Press, 2023: 368-373.
|
| 24 |
ZHOU Y H , REN Y T , YI M , et al. CDTier: a Chinese dataset of threat intelligence entity relationships. IEEE Transactions on Sustainable Computing, 2023, 8 (4): 627- 638.
doi: 10.1109/TSUSC.2023.3240411
|
| 25 |
KESHAVARZI M , GHAFFARY H R . An ontology-driven framework for knowledge representation of digital extortion attacks. Computers in Human Behavior, 2023, 139, 107520.
doi: 10.1016/j.chb.2022.107520
|
| 26 |
YEBOAH-OFORI A, ISMAIL U M, SWIDURSKI T, et al. Cyberattack ontology: a knowledge representation for cyber supply chain security[C]//Proceedings of the International Conference on Computing, Computational Modelling and Applications (ICCMA). Washington D.C., USA: IEEE Press, 2021: 65-70.
|
| 27 |
RASTOGI N, DUTTA S, ZAKI M J, et al. MALOnt: an ontology for malware threat intelligence[C]//Proceedings of International workshop on Deployable Machine Learning for Security Defense. Berlin, Germany: Springer, 2020: 28-44.
|
| 28 |
YEBOAH-OFORI A, ISMAIL U M, SWIDURSKI T, et al. Cyber threat ontology and adversarial machine learning attacks: analysis and prediction perturbance[C]//Proceedings of the International Conference on Computing, Computational Modelling and Applications (ICCMA). Washington D.C., USA: IEEE Press, 2021: 71-77.
|
| 29 |
GONG L, TIAN Y. Threat modeling for cyber range: an ontology-based approach[C]//Proceedings of the 7th International Conference on Communications, Signal Processing, and Systems. Singapore: Springer, 2020: 1055-1062.
|
| 30 |
HUANG C C, HUANG P Y, KUO Y R, et al. Building cybersecurity ontology for understanding and reasoning adversary tactics and techniques[C]//Proceedings of the IEEE International Conference on Big Data. Washington D.C., USA: IEEE Press, 2023: 4266-4274.
|
| 31 |
|
| 32 |
LIU Z J, SUN Z, CHEN J F, et al. STIX-based network security knowledge graph ontology modeling method[C]//Proceedings of the 2020 3rd International Conference on Geoinformatics and Data Analysis. New York, USA: ACM Press, 2020: 152-157.
|
| 33 |
WANG P, DAI G X, ZHAI L D. Event-based threat intelligence ontology model[C]//Proceedings of International Conference on Science of Cyber Security. Berlin, Germany: Springer, 2023: 261-282.
|
| 34 |
GRIGORIADIS C, BERZOVITIS A M, STELLIOS I, et al. A cybersecurity ontology to support risk information gathering in cyber-physical systems[C]//Proceedings of European Symposium on Research in Computer Security. Berlin, Germany: Springer, 2022: 23-39.
|
| 35 |
MULWAD V, LI W J, JOSHI A, et al. Extracting information about security vulnerabilities from web text[C]//Proceedings of the IEEE/WIC/ACM International Conferences on Web Intelligence and Intelligent Agent Technology. Washington D.C., USA: IEEE Press, 2011: 257-260.
|
| 36 |
JOSHI A, LAL R, FININ T, et al. Extracting cybersecurity related linked data from text[C]//Proceedings of the IEEE 7th International Conference on Semantic Computing. Washington D.C., USA: IEEE Press, 2014: 252-259.
|
| 37 |
MCNEIL N, BRIDGES R A, IANNACONE M D, et al. PACE: pattern accurate computationally efficient bootstrapping for timely discovery of cyber-security concepts[C]// Proceedings of the 12th International Conference on Machine Learning and Applications. Washington D.C., USA: IEEE Press, 2014: 60-65.
|
| 38 |
GEORGESCU T M , IANCU B , ZURINI M . Named-entity-recognition-based automated system for diagnosing cybersecurity situations in IoT networks. Sensors, 2019, 19 (15): 3380.
doi: 10.3390/s19153380
|
| 39 |
RAPTIS G E , KATSINI C , ALEXAKOS C , et al. CAVeCTIR: matching cyber threat intelligence reports on connected and autonomous vehicles using machine learning. Applied Sciences, 2022, 12 (22): 11631.
doi: 10.3390/app122211631
|
| 40 |
DELIU I, LEICHTER C, FRANKE K. Collecting cyber threat intelligence from hacker forums via a two-stage, hybrid process using support vector machines and latent Dirichlet allocation[C]//Proceedings of the IEEE International Conference on Big Data. Washington D.C., USA: IEEE Press, 2019: 5008-5013.
|
| 41 |
SIMRAN K, SRIRAM S, VINAYAKUMAR R, et al. Deep learning approach for intelligent named entity recognition of cyber security[C]//Proceedings of the Advances in Signal Processing and Intelligent Recognition Systems. Singapore: Springer, 2020: 163-172.
|
| 42 |
GAO C , ZHANG X , LIU H . Data and knowledge-driven named entity recognition for cyber security. Cybersecurity, 2021, 4 (1): 9.
doi: 10.1186/s42400-021-00072-y
|
| 43 |
WANG X D , LIU J Y . A novel feature integration and entity boundary detection for named entity recognition in cybersecurity. Knowledge-Based Systems, 2023, 260, 110114.
doi: 10.1016/j.knosys.2022.110114
|
| 44 |
|
| 45 |
TANG B H , LI X H , WANG J F , et al. STIOCS: active learning-based semi-supervised training framework for IOC extraction. Computers and Electrical Engineering, 2023, 112, 108981.
doi: 10.1016/j.compeleceng.2023.108981
|
| 46 |
SHANG W L , WANG B W , ZHU P C , et al. A span-based multivariate information-aware embedding network for joint relational triplet extraction of threat intelligence. Knowledge-Based Systems, 2024, 295, 111829.
doi: 10.1016/j.knosys.2024.111829
|
| 47 |
LI J Y, FEI H, LIU J, et al. Unified named entity recognition as word-word relation classification[C]//Proceedings of the AAAI Conference on Artificial Intelligence. Palo Alto, USA: AAAI Press, 2022: 10965-10973.
|
| 48 |
MOUICHE I , SAAD S . Entity and relation extractions for threat intelligence knowledge graphs. Computers & Security, 2025, 148, 104120.
|
| 49 |
LI Y F , GUO Y B , FANG C , et al. Feature-enhanced document-level relation extraction in threat intelligence with knowledge distillation. Electronics, 2022, 11 (22): 3715.
doi: 10.3390/electronics11223715
|
| 50 |
LI Y F , GUO Y B , FANG C , et al. A novel threat intelligence information extraction system combining multiple models. Security and Communication Networks, 2022, 2022, 8477260.
|
| 51 |
SATVAT K, GJOMEMO R, VENKATAKRISHNAN V N. Extractor: extracting attack behavior from threat reports[C]//Proceedings of the IEEE European Symposium on Security and Privacy (EuroS & P). Washington D.C., USA: IEEE Press, 2021: 598-615.
|
| 52 |
WANG G S , LIU P P , HUANG J T , et al. KnowCTI: Knowledge-based cyber threat intelligence entity and relation extraction. Computers & Security, 2024, 141, 103824.
|
| 53 |
DODDINGTON G, MITCHELL A, PRZYBOCKI M, et al. The Automatic Content Extraction (ACE) program-tasks, data, and evaluation[C]//Proceedings of the 4th International Conference on Language Resources and Evaluation (LREC'04). Lisbon, Portugal: Association for Computational Linguistics, 2004: 837-840.
|
| 54 |
邓巧玉, 谢素香, 曾大军, 等. 一种面向公共安全的事件抽取方法. 中文信息学报, 2022, 36, 93- 101.
|
|
DENG Q Y , XIE S X , ZENG D J , et al. An event extraction method for public security. Journal of Chinese Information Processing, 2022, 36, 93- 101.
|
| 55 |
XIANG G , SHI C , ZHANG Y S . An APT event extraction method based on BERT-BiGRU-CRF for APT attack detection. Electronics, 2023, 12 (15): 3349.
doi: 10.3390/electronics12153349
|
| 56 |
QIU X Y, LIN X X, QIU L K. Feature representation models for cyber attack event extraction[C]//Proceedings of the IEEE/WIC/ACM International Conference on Web Intelligence Workshops (WIW). Washington D.C., USA: IEEE Press, 2017: 29-32.
|
| 57 |
RITTER A, WRIGHT E, CASEY W, et al. Weakly supervised extraction of computer security events from Twitter[C]//Proceedings of the 24th International Conference on World Wide Web. Florence, Italy: International World Wide Web Conferences Steering Committee, 2015: 896-905.
|
| 58 |
张少伟, 王鑫, 陈子睿, 等. 有监督实体关系联合抽取方法研究综述. 计算机科学与探索, 2022, 16 (4): 713- 733.
|
|
ZHANG S W , WANG X , CHEN Z R , et al. Survey of supervised joint entity relation extraction methods. Journal of Frontiers of Computer Science and Technology, 2022, 16 (4): 713- 733.
|
| 59 |
GUO Y Y , LIU Z Y , HUANG C , et al. A framework for threat intelligence extraction and fusion. Computers & Security, 2023, 132, 103371.
|
| 60 |
WANG X D , LIU Z L , LIU J Y . Joint relational triple extraction with enhanced representation and binary tagging framework in cybersecurity. Computers & Security, 2024, 144, 104001.
|
| 61 |
ZHU F , CHENG Z D , LI P , et al. ITIRel: joint entity and relation extraction for Internet of Things threat intelligence. IEEE Internet of Things Journal, 2024, 11 (11): 20867- 20878.
doi: 10.1109/JIOT.2024.3373799
|
| 62 |
SUI D B , ZENG X R , CHEN Y B , et al. Joint entity and relation extraction with set prediction networks. IEEE Transactions on Neural Networks and Learning Systems, 2024, 35 (9): 12784- 12795.
doi: 10.1109/TNNLS.2023.3264735
|
| 63 |
VASWANI A, SHAZEER N, PARMAR N, et al. Attention is all you need[C]//Proceedings of Annual Conference on Neural Information Processing Systems. Long Beach, USA: [s. n.], 2017: 6000-6010.
|
| 64 |
|
| 65 |
WADHWA S, AMIR S, WALLACE B. Revisiting relation extraction in the era of large language models[C]//Proceedings of the 61st Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). Toronto, Canada: Association for Computational Linguistics, 2023: 15566-15589.
|
| 66 |
LI X, POLAT F, GROTH P, et al. Do instruction-tuned large language models help with relation extraction?[C]//Proceedings of the 1st Workshop on Knowledge Base Construction from Pre-Trained Language Models and the 2nd Challenge on Language Models for Knowledge Base Construction. Athens, Greece: CEUR-WS, 2023: 7.
|
| 67 |
WAN Z, CHENG F, MAO Z Y, et al. GPT-RE: in-context learning for relation extraction using large language models[EB/OL]. [2024-10-09]. https://arxiv.org/abs/2305.02105.
|
| 68 |
ZHANG K, GUTIÉRREZ B J, SU Y. Aligning instruction tasks unlocks large language models as zero-shot relation extractors[EB/OL]. [2024-10-09]. https://arxiv.org/abs/2305.11159.
|
| 69 |
|
| 70 |
|
| 71 |
FAYYAZI R, YANG S J. On the uses of large language models to interpret ambiguous cyberattack descriptions[EB/OL]. [2024-10-09]. https://arxiv.org/abs/2306.14062.
|
| 72 |
AGHAEI E, NIU X, SHADID W, et al. SecureBERT: a domain-specific language model for cybersecurity[C]//Proceedings of International Conference on Security and Privacy in Communication Networks. Berlin, Germany: Springer, 2023: 39-56.
|
| 73 |
|
| 74 |
FIEBLINGER R, ALAM M T, RASTOGI N. Actionable cyber threat intelligence using knowledge graphs and large language models[C]//Proceedings of the IEEE European Symposium on Security and Privacy Workshops (EuroS & PW). Washington D.C., USA: IEEE Press, 2024: 100-111.
|
| 75 |
|
| 76 |
|
| 77 |
|
| 78 |
FAYYAZI R, TAGHDIMI R, YANG S J. Advancing TTP analysis: harnessing the power of large language models with retrieval augmented generation[EB/OL]. [2024-10-09]. https://arxiv.org/abs/2401.00280.
|
| 79 |
|
| 80 |
|
| 81 |
GIRAY L . Prompt engineering with ChatGPT: a guide for academic writers. Annals of Biomedical Engineering, 2023, 51 (12): 2629- 2633.
doi: 10.1007/s10439-023-03272-4
|
| 82 |
FERRAG M A, NDHLOVU M, TIHANYI N, et al. Revolutionizing cyber threat detection with large language models: a privacy-preserving BERT-based lightweight model for IoT/IIoT devices[EB/OL]. [2024-10-09]. https://arxiv.org/abs/2306.14263.
|
| 83 |
SIRACUSANO G, SANVITO D, GONZALEZ R, et al. Time for aCTIon: automated analysis of cyber threat intelligence in the wild[EB/OL]. [2024-10-09]. https://arxiv.org/abs/2307.10214.
|
| 84 |
BAYER M , FREY T , REUTER C . Multi-level fine-tuning, data augmentation, and few-shot learning for specialized cyber threat intelligence. Computers & Security, 2023, 134, 103430.
|
| 85 |
FLORIDI L , CHIRIATTI M . GPT-3: its nature, scope, limits, and consequences. Minds and Machines, 2020, 30 (4): 681- 694.
doi: 10.1007/s11023-020-09548-1
|
| 86 |
|
| 87 |
JI H Y, YANG J, CHAI L Z, et al. SEvenLLM: benchmarking, eliciting, and enhancing abilities of large language models in cyber threat intelligence[EB/OL]. [2024-10-09]. https://arxiv.org/abs/2405.03446.
|
| 88 |
|
| 89 |
|