KIT | KIT-Bibliothek | Impressum | Datenschutz

Leveraging Large Language Models for supporting Cyber Threat Analysis

Rybinski, Fabian ORCID iD icon 1; Schiefer, Gunther ORCID iD icon 1; Frister, Demian ORCID iD icon 1; Malekzadeh Mahani, Marzieh 1
1 Institut für Angewandte Informatik und Formale Beschreibungsverfahren (AIFB), Karlsruher Institut für Technologie (KIT)

Abstract:

The efficient and accurate analysis of cyber threat data is crucial in the constantly evolving cybersecurity landscape. However, a major challenge lies in the vast amounts of unstructured, human-readable information that is often used for threat intelligence communication, such as threat reports and news articles. While structured formats like STIX (Structured Threat Information eXpression) enable effective machine-tomachine exchange of threat data, they often lack the contextual information needed by human analysts. This paper proposes a novel framework that leverages Large Language Models (LLMs) to bridge the gap between unstructured text and structured cyber threat intelligence. The key contributions of this work are twofold:
(1) Automating the conversion of unstructured cyber threat data into the standardized STIX format, enabling the efficient incorporation of diverse threat intelligence sources into automated analysis and sharing systems. (2) Generating human-readable reports and insights from structured STIX data, tailored to the needs of different personas within an organization, such as CISOs, security analysts, executives, etc.
... mehr


Zugehörige Institution(en) am KIT Institut für Angewandte Informatik und Formale Beschreibungsverfahren (AIFB)
Kompetenzzentrum für angewandte Sicherheitstechnologie (KASTEL)
Publikationstyp Proceedingsbeitrag
Publikationsdatum 27.03.2026
Sprache Englisch
Identifikator ISBN: 978-3-032-14098-2
ISSN: 2196-8705
KITopen-ID: 1000190336
Erschienen in Recent Advances in Information Systems Proceedings of the ICRAIS, Pointe aux Piments, Mauritius, 10–12 September 2025 Jorge Marx Gómez, Roopesh Kevin Sungkur, Sameerchand Pudaruth, Jan-Hendrik Witte, Gerrit Schumann
Veranstaltung 1th 2025 International Conference on Recent Advances in Information Systems (2025), Pointe aux Piments, Mauritius, 10.09.2025 – 12.09.2025
Auflage 1
Verlag Springer Cham
Serie Progress in IS
Schlagwörter Large Language Models, Cyber Security, Structured Threat Intelligence, STIX
KIT – Die Universität in der Helmholtz-Gemeinschaft
KITopen Landing Page