Review of Information Extraction in the Field of Cyber Threat Intelligence
摘要
Cyber Threat Intelligence (CTI) provides critical support for the construction of cybersecurity defense systems by analyzing and predicting cyber threats. Information Extraction (IE) technology, which is a foundational component of CTI, has garnered significant attention from both academia and industry in recent years. Its application is particularly important for constructing threat intelligence knowledge graphs. Given the ever-evolving nature of threat types and attack techniques, precise IE capabilities play a decisive role in enhancing cybersecurity defense. This review systematically examines the development of IE technologies within the CTI domain and presents a comprehensive analysis and summary of the key components of IE frameworks. IE methods are categorized into three major types: traditional machine-learning-based, deep-learning-based, and large language-model-based methods. The characteristics, applicable scenarios, and progress of research in each category are discussed in detail. Moreover, quantitative and theoretical analyses of existing techniques are presented, along with a discussion of their implications and limitations in practical applications. The review also outlines the current challenges in the field and proposes potential research directions to address them. By presenting a detailed assessment of IE technologies for CTI, this review offers a comprehensive academic perspective and lays an important theoretical foundation for fostering more efficient and intelligent cybersecurity defense systems.