首页 / 资料库 / 文献详情

Multi-Step LLM Pipeline for Enhancing TTP Extraction in Cyber Threat Intelligence

Hyoung Rok KimDonghyeon LeeInseop LeeSoohan LeeSangjin Lee

2025IEEE AccessComputer Science被引 1开放获取

出版方页面 →

摘要

Tactics, techniques, and procedures (TTPs) are essential for modeling adversary behavior and supporting cyber defense operations. Despite their importance, most cyber threat intelligence (CTI) is provided in unstructured formats, making automated TTP extraction challenging. While manual identification is labor-intensive, current automated approaches suffer from limited accuracy and coverage. To address these challenges, we present a novel multi-step framework based on large language models (LLMs) for extracting MITRE ATT&CK techniques from raw CTI document. Our framework consists of three components: an LLM-basedExtractorfor extracting procedure-level threat actions, an embedding-drivenTechnique Candidate Generatorfor retrieving semantically relevant technique candidates, and aValidatorthat ranks candidate techniques by likelihood using LLM inference to refine final predictions and reduce false positives. Experimental results on the benchmark dataset demonstrate that our approach significantly outperforms existing baselines, achieving an F1-score of 82.28%, thereby validating its effectiveness. Additionally, the modularity of our framework allows seamless integration of future LLMs, suggesting continual performance gains as foundation models evolve.

引用本文(GB/T 7714)

Hyoung Rok Kim, Donghyeon Lee, Inseop Lee, 等. Multi-Step LLM Pipeline for Enhancing TTP Extraction in Cyber Threat Intelligence[J]. IEEE Access, 2025.

引文网络

参考文献与被引分析加载中…

DOI:https://doi.org/10.1109/access.2025.3622350

本站仅收录题录与摘要供学习参考,全文版权归属出版方;如有侵权请联系我们删除。