A SoK for SoCs: Reading the TI Leaves on AI for Cyber Threat Intelligence Generation and Sharing

πŸ“… 2026-09-01
πŸ“ˆ Citations: 0
✨ Influential: 0
πŸ“„ PDF
πŸ€– AI Summary
ζœ¬ζ–‡η ”η©ΆδΊ†ε¦‚δ½•εˆ©η”¨ε€§εž‹θ―­θ¨€ζ¨‘εž‹θ‡ͺεŠ¨εŒ–η”Ÿζˆε’Œεˆ†δΊ«η½‘η»œε¨θƒζƒ…ζŠ₯,δ»₯解决θ―₯θΏ‡η¨‹δΈ­ηš„ε››δΈͺδΈ»θ¦ζŒ‘ζˆ˜γ€‚
πŸ“ Abstract
Cyber Threat Intelligence (CTI) is essential for defending mission-critical infrastructure, yet the process of transforming raw attack evidence into shareable CTI remains fragmented and understudied. We conduct a literature survey of academic papers, organizing the CTI lifecycle into three stages: Threat Data Collection, CTI Generation and Sharing, and CTI Consumption. The first and third stages are well represented in the literature, whereas only a small number of papers address CTI Generation and Sharing. To learn how this stage is practiced, we survey practitioners across multiple organizations who routinely generate and share CTI. They describe a largely manual process with four recurring challenges: preventing the exposure of sensitive information, extracting indicators from noisy attack data, correlating observed behavior with standardized tactics, techniques, and procedures (TTPs), and translating CTI into the formats that sharing platforms require. Using the insights from the practitioner survey, we divide the CTI Generation and Sharing stage into four steps: Intelligence Extraction, Normalization and Enrichment, Codification, and Distribution. We then conduct pilot studies that probe the feasibility of current Large Language Models (LLMs) for each step. The pilot studies show that LLMs can assist an analyst in each of the four steps. However, the models recover only a fraction of the indicators the evidence contains, struggle to ground every claim in the supplied evidence, and do not judge what keeps shared intelligence useful to its recipients. Each step therefore requires expert supervision. Based on these observations, we derive three research directions for automating the production of shareable intelligence.
Problem

Research questions and friction points this paper is trying to address.

Cyber Threat Intelligence
Threat Data Collection
CTI Generation and Sharing
Sensitive Information Exposure
Indicators Extraction
Innovation

Methods, ideas, or system contributions that make the work stand out.

Cyber Threat Intelligence
Large Language Models
Intelligence Extraction
Normalization and Enrichment
Codification
πŸ”Ž Similar Papers
No similar papers found.