[論文レビュー] What are the attackers doing now? Automating cyber threat intelligence extraction from text on pace with the changing threat landscape: A survey
本調査では、自然言語処理(NLP)および機械学習を活用して、非構造化テキストからのサイバー脅威インテリジェンス(CTI)抽出を自動化する体系的フレームワークを提案する。10のCTI抽出目的と7つの主要なデータソース(特に脅威レポート、ハッキングフォーラム、ソーシャルメディア)を特定した。研究では、教師ありおよび教師なしNLP技術をコアな手法として特定し、データ品質と再現性の課題を強調し、実用的でスケーラブルかつ優先順位を明確にしたCTIパイプラインの構築を提言することで、能動的脅威防御を支援する。
Cybersecurity researchers have contributed to the automated extraction of CTI from textual sources, such as threat reports and online articles, where cyberattack strategies, procedures, and tools are described. The goal of this article is to aid cybersecurity researchers understand the current techniques used for cyberthreat intelligence extraction from text through a survey of relevant studies in the literature. We systematically collect "CTI extraction from text"-related studies from the literature and categorize the CTI extraction purposes. We propose a CTI extraction pipeline abstracted from these studies. We identify the data sources, techniques, and CTI sharing formats utilized in the context of the proposed pipeline. Our work finds ten types of extraction purposes, such as extraction indicators of compromise extraction, TTPs (tactics, techniques, procedures of attack), and cybersecurity keywords. We also identify seven types of textual sources for CTI extraction, and textual data obtained from hacker forums, threat reports, social media posts, and online news articles have been used by almost 90% of the studies. Natural language processing along with both supervised and unsupervised machine learning techniques such as named entity recognition, topic modelling, dependency parsing, supervised classification, and clustering are used for CTI extraction. We observe the technical challenges associated with these studies related to obtaining available clean, labelled data which could assure replication, validation, and further extension of the studies. As we find the studies focusing on CTI information extraction from text, we advocate for building upon the current CTI extraction work to help cybersecurity practitioners with proactive decision making such as threat prioritization, automated threat modelling to utilize knowledge from past cybersecurity incidents.
研究の動機と目的
- テキストデータからの自動サイバー脅威インテリジェンス(CTI)抽出に関する既存研究を体系的かつ分類化すること。
- CTI抽出研究で用いられる主な目的、データソース、技術、共有フォーマットを特定すること。
- 再現性とスケーラビリティを支援する一般化されたCTI抽出パイプラインを提案すること。
- 清浄でラベル付けされたデータの不足や、研究間でのモデルの一般化性の低さといった技術的課題に対処すること。
- 実世界のサイバー防御応用に向け、実行可能で優先順位付けされ、相関関係のあるCTIを提供するための今後の研究を導くこと。
提案手法
- 6つの学術データベースを対象とした体系的文献レビューを実施し、テキストからのCTI抽出に関する64件の研究を収集した。
- オープンコーディングおよびカードソーティング技術を用いて、研究を定性的に分析し、CTI抽出目的と技術を分類した。
- 統合された研究から抽出した標準化されたCTI抽出パイプラインを提案した。このパイプラインには、データインジェスト、NLP処理、CTIの構造化の段階が含まれる。
- 10種類の明確に区別されたCTI抽出目的(例:IoC抽出、TTPs、攻撃パターン抽出)と7つのテキストデータソース(例:脅威レポート、ソーシャルメディア、ダークウェブフォーラム)をマッピングした。
- コアとなるNLPおよび機械学習技術を特定:名前付きエンティティ認識(NER)、トピックモデリング、従属構文解析、教師あり分類、クラスタリング、ワードエムベディング。
- 出版済みの研究におけるコードおよびデータの可用性を評価し、再現性と研究持続可能性を検証した。
実験結果
リサーチクエスチョン
- RQ1現在の研究において、テキストデータからのサイバー脅威インテリジェンス抽出の主な目的は何か?
- RQ2CTI抽出に最も頻繁に使用されるテキストデータソースは何か?また、その有用性と信頼性はどのように異なるか?
- RQ3CTI抽出で主に用いられるNLPおよび機械学習技術は何か?性能と応用面での比較は?
- RQ4CTI抽出研究の再現性とスケーラビリティを阻害する技術的課題は何か?
- RQ5今後のCTI抽出システムは、実行可能で優先順位付けされ、相関関係のある脅威インテリジェンスを実時間防御に活用できるように、どのように設計すべきか?
主な発見
- 本研究では10種類の明確に区別されたCTI抽出目的を同定した。その中でも、CTIテキスト分類、攻撃パターン抽出、サイバーセキュリティキーワード抽出が、最も多くの研究対象となった。
- ハッキングフォーラム、脅威レポート、ソーシャルメディア投稿、オンラインニュース記事が、調査対象の64件の研究の約90%のテキストデータソースを占めた。
- 教師ありおよび教師なしNLP技術、特に名前付きエンティティ認識(NER)、トピックモデリング、従属構文解析が、CTI抽出の主な手法として広く採用された。
- コードおよびラベル付きデータセットをGitHubで公開した研究は少数(例:NiakanlahijiらやSamtaniら)にとどまり、再現性における顕著なギャップが浮き彫りになった。
- 大多数の研究が単一のデータセットに限定されており、研究間の相関関係の構築とスケーラビリティが制限されており、複数ソースを統合した集約的CTI統合の必要性が強調された。
- 今後の研究は、実行可能なCTI、進化する攻撃戦略への適応性、および抽出精度の向上を目的とした分野特化型言語モデル(例:sec2vec)の開発を優先すべきである。
より良い研究を、今すぐ始めましょう
論文の読解から最終レビューまで、研究時間を劇的に削減しましょう。
クレジットカード登録不要
このレビューはAIが作成し、人間の編集者が確認しました。