BEACON: Behavior-Anchored Cross-Source Knowledge Graph Construction for Cyber Threat Intelligence
BEACON uses MITRE ATT&CK techniques as anchors to merge threat-intelligence reports that may name the same threat differently.
The paper describes an LLM-driven framework that first extracts report-level graphs, then verifies candidates against report evidence and official ATT&CK definitions. It attaches actors, campaigns, products, and IoCs to behavior anchors so separate reports can be placed in a shared space. A second stage aligns and merges graphs using character, semantic, and technique-neighborhood signals. The authors say BEACON beats baselines on two human-annotated CTI datasets built from 34 sources.
ArXiv · AI/CL/LG's note
The paper describes an LLM-driven framework that first extracts report-level graphs, then verifies candidates against report evidence and official ATT&CK definitions. It attaches actors, campaigns, products, and IoCs to behavior anchors so separate reports can be placed in a shared space. A second stage aligns and merges graphs using character, semantic, and technique-neighborhood signals. The authors say BEACON beats baselines on two human-annotated CTI datasets built from 34 sources.
ArXiv · AI/CL/LG's note
score 4