Using Entropy and Mutual Information to Extract Threat Actions from Cyber Threat Intelligence

2018 IEEE International Conference on Intelligence and Security Informatics (ISI)(2018)

引用 71|浏览77
暂无评分
摘要
With the rapid growth of the cyber attacks, cyber threat intelligence (CTI) sharing becomes essential for providing advance threat notice and enabling timely response to cyber attacks. Our goal in this paper is to develop an approach to extract low-level cyber threat actions from publicly available CTI sources in an automated manner to enable timely defense decision making. Specifically, we innovatively and successfully used the metrics of entropy and mutual information from Information Theory to analyze the text in the cybersecurity domain. Combined with some basic NLP techniques, our framework, called ActionMiner has achieved higher precision and recall than the state-of-the-art Stanford typed dependency parser, which usually works well in general English but not cybersecurity texts.
更多
查看译文
关键词
Cyber threat intelligence,Text mining,Information Theory,NLP,Cybersecurity,Malware behavior analysis
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要