PulseAugur
EN
LIVE 09:40:42

TRACE-CTI framework enhances audibility of cyber threat intelligence claims

A new framework called TRACE-CTI has been developed to improve the audibility and governance of cyber threat intelligence (CTI) claims extracted by automated systems. This framework preserves evidence, provenance, and validation history, allowing for more trustworthy decision-making regarding the mapping of CTI reports to frameworks like MITRE ATT&CK. TRACE-CTI aggregates predictions into graph assertions and materializes corroborated claims as consensus assertions, ensuring that only policy-compliant claims are exposed. Evaluations on public CTI corpora demonstrated that increasing setup support significantly raises precision while decreasing recall, highlighting the trade-offs in claim validation. AI

IMPACT Enhances trust and audibility in automated cyber threat intelligence analysis, potentially improving security operations' decision-making.

RANK_REASON The cluster contains a research paper detailing a new framework for auditable post-extraction governance of cyber threat intelligence claims. [lever_c_demoted from research: ic=1 ai=1.0]

Read on arXiv cs.AI →

AI-generated summary · Google Gemini · from 1 sources. How we write summaries →

TRACE-CTI framework enhances audibility of cyber threat intelligence claims

COVERAGE [1]

  1. arXiv cs.AI TIER_1 English(EN) · Federico Valletta, Giacomo Longo, Enrico Russo, Alessio Merlo ·

    TRACE-CTI: Auditable Post-Extraction Governance of TTP Claims with Knowledge Graphs

    arXiv:2607.24563v1 Announce Type: new Abstract: Security Operations Centers increasingly rely on automated mapping of Cyber Threat Intelligence reports to MITRE ATT&CK, yet extractor outputs remain fallible and are often stored without the evidence, provenance, and validation…