כתבה
arXiv cs.AI ·
מודיעין איומים מובטח
From Sandbox to Enforcement: Confidence-Qualified Threat Intelligence for Critical Infrastructure
CG-CTI הוא פייפליין אופרטיבי הממיר נתוני איום מסנדבוק למודיעין פעיל. הוא משתמש בגרף ידע ומקצה מעמד ביטחון לכל אובייקט מודיעין. המערכת מוערכת במסגרת פרויקט CYBERGUARD.
תקציר מקורי באנגליתarXiv:2610.07310v1 Announce Type: cross Abstract: Security operations centres and national incident-response teams defending critical infrastructure collect abundant threat data yet struggle to turn it into actionable intelligence. A malware sandbox produces detailed behavioural evidence, but as a large, unranked report whose confidence is unstated. We present CG-CTI, an operational pipeline that converts live sandbox output (CAPEv2) into STIX 2.1, correlates it in a knowledge graph with other critical-infrastructure sensors, and attaches to every intelligence object an explicit confidence status derived from provenance, cross-source corroboration, and observation durability. This status gates automated action: only corroborated intelligence is eligible for automated enforcement, while low
קרא במקור המקורי
arxiv.org
פתח כתבה מקורית