Merging Cyber Threat Intelligence Through Retrieval-Augmented Generation and Small Language Models for Rich Threat Representation

📅 2026-09-07
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
为解决网络安全中分散的威胁情报难以整合的问题,提出了一种结合检索增强生成和小型语言模型的方法,自动生成丰富且可操作的攻击图表示。
📝 Abstract
Modern cybersecurity operations rely on CTI collected from heterogeneous sources, including semi-structured threat representations, IoCs, and narrative technical reports. However, these artifacts are often insufficient in isolation to reconstruct how an attack unfolds, under which conditions each step is feasible, and which traces it leaves behind. In practice, analysts must manually correlate partial evidence scattered across multiple and only partially structured sources, delaying the design of effective prevention, detection, and response actions. To address this gap, we propose an automated pipeline that derives an actionable representation of a cyberattack from heterogeneous CTI sources. The pipeline combines a RAG architecture with a locally deployable SLM, used to consolidate such evidence and infer missing operational details. Starting from a semi-structured threat representation and auxiliary CTI documents, the pipeline produces an enriched Attack Graph that captures a coarse, tactic-aligned progression of the attack and annotates each step with explicit pre-conditions and post-conditions, and an enriched description. This representation supports prevention by exposing execution requirements, detection by highlighting observable traces, and response by clarifying the temporal progression of the attack. Then, due to the lack of validated datasets with ground-truth information on the temporal evolution of real-world attacks, we test the complete pipeline on 10 real-world case studies spanning multiple threat types, including backdoors and staged downloaders delivered via phishing. A manual assessment across 10 real-world case studies provides initial evidence that the generated graphs are consistent with expected attack progressions, indicating that the proposed approach can support analysts by consolidating dispersed CTI evidence into a structured and actionable view of attacks.
Problem

Research questions and friction points this paper is trying to address.

Cyber Threat Intelligence
Heterogeneous Sources
Attack Reconstruction
Manual Correlation
Security Operations
Innovation

Methods, ideas, or system contributions that make the work stand out.

Retrieval-Augmented Generation
Small Language Models
Cyber Threat Intelligence
Attack Graph
Operational Details
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
N
Nicola Deidda
University of Cagliari, Cagliari, Italy
Leonardo Regano
Leonardo Regano
Assistant Professor, Università di Cagliari
Software SecurityNetwork SecurityMachine Learning
A
Alessandro Sanna
University of Cagliari, Cagliari, Italy
Davide Maiorca
Davide Maiorca
Associate Professor of Computer Engineering at University of Cagliari, Italy
Computer SecurityPattern RecognitionAdversarial Machine LearningPDFAndroid
G
Giorgio Giacinto
University of Cagliari, Cagliari, Italy; Consorzio Interuniversitario Nazionale per l’Informatica, Rome, Italy