A new framework called TRACE-CTI has been developed to improve the audibility and governance of cyber threat intelligence (CTI) claims extracted by automated systems. This framework preserves evidence, provenance, and validation history, allowing for more trustworthy decision-making regarding the mapping of CTI reports to frameworks like MITRE ATT&CK. TRACE-CTI aggregates predictions into graph assertions and materializes corroborated claims as consensus assertions, ensuring that only policy-compliant claims are exposed. Evaluations on public CTI corpora demonstrated that increasing setup support significantly raises precision while decreasing recall, highlighting the trade-offs in claim validation. AI
IMPACT Enhances trust and audibility in automated cyber threat intelligence analysis, potentially improving security operations' decision-making.
RANK_REASON The cluster contains a research paper detailing a new framework for auditable post-extraction governance of cyber threat intelligence claims. [lever_c_demoted from research: ic=1 ai=1.0]
- Connected Papers
- ConsensusAssertions
- GraphAssertions
- Hugging Face
- Litmaps
- Mitre ATT&CK
- scite Smart Citations
- TRACE-CTI
AI-generated summary · Google Gemini · from 1 sources. How we write summaries →