ai.hackcv
论文精选 65arXiv

TRACE-CTI: Auditable Post-Extraction Governance of TTP Claims with Knowledge Graphs· TRACE-CTI:使用知识图谱审计和管理 TTP 声明的后提取治理

Security Operations Centers increasingly rely on automated mapping of Cyber Threat Intelligence reports to MITRE ATT&CK, yet extractor outputs remain fallible and are often stored without the evidence, provenance, and validation history needed to decide whether an individual mapping should be trusted. We present TRACE- CTI, a post-extraction claim-governance framework that preserves run-level Predictions, aggregates them into configuration-level GraphAssertions, materializes setup-deduplicated corroboration as ConsensusAssertions, and exposes only GraphAssertions backed by policy-compliant validation grounds. The framework retains native evidence granularity, complete extraction provenance, versioned trust decisions, and non-destructive revocation history. We evaluate TRACE-CTI on two

AI 解读论文

使用知识图谱进行 TTP 声明的后提取治理,提高信任度和可审计性。

核心方法
通过保留运行级预测、聚合为配置级图断言、去重确认为共识断言,并仅显示符合策略验证条件的图断言来实现治理。
适合谁读
安全运营中心的研究者和工程师
要解决的问题
自动化提取的网络安全威胁情报报告在映射到 MITRE ATT&CK 时缺乏证据、来源和验证历史,影响信任度。
关键实验
对两个数据集进行了评估,但未提供具体实验细节。
主要贡献
提供了一种保留证据颗粒度、完整提取来源、版本化信任决策和非破坏性撤销历史的框架。
意义与局限
提高了自动化提取的威胁情报报告的可审计性和信任度,但框架的复杂性和实施成本可能较高。
领域:cs.AI作者:Federico Valletta、Giacomo Longo、Enrico Russo
相关推荐

本站内容由 LLM 精选聚合,原文版权归 arXiv 所有 · 摘录仅供参考