REVIEW 2 cited by
CTI-HAL: A Human-Annotated Dataset for Cyber Threat Intelligence Analysis
Not yet reviewed by Pith; the record is open.
This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.
SPECIMEN: schema-true, not a live event
T0 review · schema-true
One-sentence machine reading of the paper's core claim.
pith:XXXXXXXX · record.json · timestamp
read the original abstract
Organizations are increasingly targeted by Advanced Persistent Threats (APTs), which involve complex, multi-stage tactics and diverse techniques. Cyber Threat Intelligence (CTI) sources, such as incident reports and security blogs, provide valuable insights, but are often unstructured and in natural language, making it difficult to automatically extract information. Recent studies have explored the use of AI to perform automatic extraction from CTI data, leveraging existing CTI datasets for performance evaluation and fine-tuning. However, they present challenges and limitations that impact their effectiveness. To overcome these issues, we introduce a novel dataset manually constructed from CTI reports and structured according to the MITRE ATT&CK framework. To assess its quality, we conducted an inter-annotator agreement study using Krippendorff alpha, confirming its reliability. Furthermore, the dataset was used to evaluate a Large Language Model (LLM) in a real-world business context, showing promising generalizability.
Forward citations
Cited by 2 Pith papers
-
From Text to Actionable Intelligence: Automating STIX Entity and Relationship Extraction
Fine-tuned LLMs extract STIX entities and relationships from threat reports with per-module F1 scores of 84.4%, 88.5%, 95.5%, and 84.6%, backed by a new 4,011-entity annotated dataset.
-
SynthCTI: LLM-Driven Synthetic CTI Generation to enhance MITRE Technique Mapping
A clustering-guided LLM data augmentation pipeline raises macro-F1 for MITRE technique classification, e.g., ALBERT from 0.35 to 0.52 and SecureBERT to 0.66, across two CTI datasets.
Discussion (0). Continue with ORCID to comment.