Effective Application of Natural Language Processing Techniques in Automated Cyber Threat Intelligence

Otgonpurev Mendsaikhan · Institutional Repositories DataBase (IRDB) · 2021

by MENDSAIKHAN OtgonpurevThe latest advancements of Artificial Intelligence (AI) techniques are complicating the cyber threat landscape.In this arms race, the cybersecurity defenders need to automate their tools to be competent enough against these ever-increasing threats.This thesis proposes to utilize Natural Language Processing techniques for cyber defense, specifically in the Cyber Threat Intelligence process.As a demonstration, I have developed a prototype system that identifies cybersecurity specific text content, analyzes the significance and relevance of it, and enriches it with the existing threat information.The proposed system consists of the following modules.1. Natural Language Filter module classifies and filters the cybersecurity-related text documents from any information source.It has been implemented using Doc2Vec and BERT language models to identify and filter the security-related text documents.2. Analyzer module determines the significance and relevance of the threat information to the user.It has been implemented using a novel approach of engineering the features of the text through Knowledge Graph and Named Entity Recognition methods. 3.Mapper module enriches the threat information with the adversarial tactics and techniques.It has been implemented by converting the threat information into its vector representation and applying multi-label classification on it.Each module has been independently experimented and the individual results support the utilization of particular method.Essentially, it could be inferred that by utilizing various Natural Language Processing techniques in the Cyber Threat Intelligence process the cyber defense could be improved, specifically in situational awareness and security automation operations.

Read the paper · More papers on PaperTik