יום רביעי, 7 באוקטובר 2026 LIVE
AI־INFO

כתבה arXiv cs.AI ·

מודיעין איומים מובטח

From Sandbox to Enforcement: Confidence-Qualified Threat Intelligence for Critical Infrastructure
CG-CTI הוא פייפליין אופרטיבי הממיר נתוני איום מסנדבוק למודיעין פעיל. הוא משתמש בגרף ידע ומקצה מעמד ביטחון לכל אובייקט מודיעין. המערכת מוערכת במסגרת פרויקט CYBERGUARD.
תקציר מקורי באנגליתarXiv:2610.07310v1 Announce Type: cross Abstract: Security operations centres and national incident-response teams defending critical infrastructure collect abundant threat data yet struggle to turn it into actionable intelligence. A malware sandbox produces detailed behavioural evidence, but as a large, unranked report whose confidence is unstated. We present CG-CTI, an operational pipeline that converts live sandbox output (CAPEv2) into STIX 2.1, correlates it in a knowledge graph with other critical-infrastructure sensors, and attaches to every intelligence object an explicit confidence status derived from provenance, cross-source corroboration, and observation durability. This status gates automated action: only corroborated intelligence is eligible for automated enforcement, while low
קרא במקור המקורי