Leveraging threat intelligence to construct a proactive security correlation analysis and operation framework
Online published: 2026-04-01
Copyright
Cyber threat intelligence has been proven to be a mainstream method for executing efficient threat detection, and how to systematically generate and operate threat intelligence has become a core issue. To address this, a solution is proposed that utilizes the processing and integration of threat intelligence data to construct a proactive security correlation analysis and operation framework, which aims to achieve comprehensive, adaptive, and real-time cybersecurity defense. The solution encompasses technical modules such as data collection, model establishment, analysis engine, intelligence production, and intelligence application and sharing. Among these, the proactive security correlation framework based on threat intelligence and the full-process correlation analysis system of the knowledge graph integrate technologies such as machine learning, data fusion, and large language models. This integration realizes the automated operation of the entire process from data collection to threat detection, applies threat intelligence throughout the entire lifecycle operation, and enhances the proactivity and intelligence of cybersecurity defense. Experiments have proven that constructing a proactive security correlation framework through in-depth analysis and utilization of threat intelligence is an effective way to enhance the capability of cybersecurities defense.
Bai Min , Wang Liejun . Leveraging threat intelligence to construct a proactive security correlation analysis and operation framework[J]. Journal of Cybersecurity, 2025 , 3(5) : 84 -101 . DOI: 10.20172/j.issn.2097-3136.250508
| 1 |
Symantec Corporation. Internet security threat report 2019 [R].[2025-09-19]https://www.symantec.com/content/dam/symantec/docs/ reports/istr-24-2019-en.pdf.
|
| 2 |
Agrafiotis I , Nurse J , Goldsmith M , et al. A security metrics taxonomy for the information and communication technology industry. [J/OL]Journal of Cybersecurity, 2018, 4(1). https://doi.org/10.1093/cybsec/tyy006.
|
| 3 |
Mandiant. M-Trends 2021 Report. Mandiant[R]. [2025-09-19] https://www.mandiant.com/resources/reports/m-trends-2021.
|
| 4 |
Riesco R, Villagrá V A. Leveraging cyber threat intelligence for a dynamic risk framework: automation by using a semantic reasoner and a new combination of standards (STIX™, SWRL and OWL)[J]. International Journal of Information Security, 2019, 18 (6): 715- 739.
|
| 5 |
Ponemon Institute LLC. Live threat intelligence impact report 2013[R]. [2025-09-19] https://www.ponemon.org/blog/live-threat-intelligence-impact-report-2013-1.
|
| 6 |
Carriegos M V, Castañeda Á L M, Trobajo M T, et al. On aggregation and prediction of cybersecurity incident reports[J]. IEEE Access, 2021, 9, 102636- 102648.
|
| 7 |
Definition: threat intelligence. [EB/OL]. [2025-09-19] https://www.gartner.com/en/documents/2487216.
|
| 8 |
Tounsi W, Rais H. A survey on technical threat intelligence in the age of sophisticated cyber attacks[J]. Computers & Security, 2018, 72, 212- 233.
|
| 9 |
CCID赛迪顾问. 中国威胁情报市场研究报告 (2023)[R].
CCID Consultant. China Threat Intelligence Market Research Report(2023)[R].
|
| 10 |
Brown R, Lee R M. The evolution of cyber threat intelligence (CTI): 2019 SANS CTI survey[J/OL]. SANS Institute[2025-09-19] https://www. sans. org/white-papers/38790/(2021-07-12), 2019.
|
| 11 |
Doerr C. Cyber threat intelligences standards–a high level overview[R]. TU Delft CTI Labs, 2018.
|
| 12 |
Li Y, Huang G Q, Wang C Z, et al. Analysis framework of network security situational awareness and comparison of implementation methods[J]. EURASIP Journal on Wireless Communications and Networking, 2019, 205.
|
| 13 |
NIST. Framework for Improving Critical Infrastructure Cybersecurity[S]. Washington D C, 2018.
|
| 14 |
You Y Z, Jiang J, Jiang Z W, et al. TIM: threat context-enhanced TTP intelligence mining on unstructured threat data[J]. Cybersecurity, 2022, 5, 3.
|
| 15 |
Barnum S. Standardizing cyber threat intelligence information with the structured threat information expression (STIX)[R]. Bedford: MITRE Corporation, 2012.
|
| 16 |
Piazza R, Wunder J, Jordan B: StixTM version 2.0. part 1: Stix core concepts (2017) [EB/OL]. [2025-09-19] https://docs.oasis-open.org/cti/stix/v2.0/stix-v2.0-part1-stix-core.html.
|
| 17 |
Bayer U, Moser A, Kruegel C, et al. Dynamic analysis of malicious code[J]. Journal in Computer Virology, 2006, 2 (1): 67- 77.
|
| 18 |
Hendler D, Kels S, Rubin A. Detecting malicious PowerShell commands using deep neural networks[C]//Proceedings of the 2018 Asia Conference on Computer and Communications Security. New York: ACM, 2018: 187-197.
|
| 19 |
Bayer U, Comparetti P M, Hlauschek C, et al. Scalable, behavior-based malware clustering[C]//Proceedings of the Network and Distributed System Security Symposium. San Diego: The Internet Society, 2009.
|
| 20 |
向灵孜, 白敏, 汪列军. 样本程序恶意程度自动识别方法及装置: 202010143686.5 [P]. 2023-08-22.
Xiang L Z, Bai M, Wang L J. Automatic identification method and device of malicious degree of sample program. 202010143686.5 [P]. 2023-08-22.
|
| 21 |
Zhou Y J, Jiang X X. Dissecting Android malware: characterization and evolution[C]//Proceedings of the 2012 IEEE Symposium on Security and Privacy. Piscataway: IEEE Press, 2012: 95-109.
|
| 22 |
白敏, 白皓文, 汪列军等. 文件恶意度的评估方法、装置、电子设备和介质, 202011480004.6[P]. 2022-06-17.
Bai M, Bai H W, Wang L J, et al. File malicious level evaluation methods, devices, electronic equipment and media, 202011480004.6[P]. 2022-06-17.
|
| 23 |
Liao X J, Yuan K, Wang X F, et al. Acing the IOC game: toward automatic discovery and analysis of open-source cyber threat intelligence[C]//Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security. New York: ACM, 2016: 755-766
|
| 24 |
Kaspersky Lab. IT threat evolution Q3 2020[EB/OL]. (2020-11-20)[2025-09-19]. https://securelist.com/it-threat-evolution-q3-2020/99382/.
|
| 25 |
MITRE. ATT&CK: Adversarial tactics, techniques, and common knowledge for enterprise[EB/OL]. (2018)[2025-09-19]. https://attack.mitre.org/.
|
| 26 |
宋国宝. 面向APT的网络威胁情报知识图谱构建研究[J]. 软件导刊, 2025, 24 (5): 179- 185.
Song G B. Research on the construction of network threat intelligence knowledge graph for APT[J]. Software Guide, 2025, 24 (5): 179- 185.
|
| 27 |
Liu J, Yan J J, Jiang J, et al. TriCTI: an actionable cyber threat intelligence discovery system via trigger-enhanced neural network[J]. Cybersecurity, 2022, 5, 8.
|
| 28 |
Bilge L, Dumitraş T. Before we knew it: an empirical study of zero-day attacks in the real world[C]//Proceedings of the 2012 ACM Conference on Computer and Communications Security. New York: ACM, 2012: 833-844.
|
| 29 |
Canali D, Cova M, Vigna G, et al. Prophiler: a fast filter for the large-scale detection of malicious web pages[C]//Proceedings of the 20th International Conference on World Wide Web. New York: ACM, 2011: 197-206.
|
| 30 |
Kirda E, Kruegel C, Machtaler S, et al. Automating mimicry attacks using static binary analysis[C]//Proceedings of the USENIX Security Symposium. Vancouver: USENIX Association, 2006. 1419-1435.
|
| 31 |
Nicho M, Adelaiye O, McDermott C D, et al. Enhanced detection of APT vector lateral movement in organizational networks using lightweight machine learning[J]. Computers, Materials & Continua, 2025, 83(1): 281-308.
|
| 32 |
Shaukat K, Luo S H, Chen S, et al. Cyber threat detection using machine learning techniques: a performance evaluation perspective[C]//Proceedings of the 2020 International Conference on Cyber Warfare and Security (ICCWS). Piscataway: IEEE Press, 2020: 1-6.
|
| 33 |
Yang F Y, Han Y N, Ding Y, et al. A flexible approach for cyber threat hunting based on kernel audit records[J]. Cybersecurity, 2022, 5, 11.
|
| 34 |
Zhao X J, Jiang R, Han Y, et al. A survey on cybersecurity knowledge graph construction[J]. Computers & Security, 2024, 136, 103524.
|
| 35 |
Hu Y L, Zou F T, Han J J, et al. LLM-TIKG: Threat intelligence knowledge graph construction utilizing large language model[J]. Computers & Security, 2024, 145, 103999.
|
| 36 |
Böhm F, Menges F, Pernul G. Graph-based visual analytics for cyber threat intelligence[J]. Cybersecurity, 2018, 1, 16.
|
| 37 |
白敏, 万文杰, 黄朝文, 等. 一种基于威胁情报的威胁分析图谱生成、应用方法及装置, 202111335619.4[P]. 2022-03-01.
Bai M , Wan W J , Huang C W, et al. A threat analysis map generation, application method and device based on threat intelligence. 202111335619.4[P]. 2022-03-01.
|
| 38 |
Jiang F, Gu T L, Chang L, et al. Case retrieval for network security emergency response based on description logic[C]//Progress in Pattern Recognition, Image Analysis, Computer Vision, and Applications. ChamSpringer International Publishing, 2014: 284-293.
|
| 39 |
Polatidis N, Pimenidis E, Pavlidis M, et al. From product recommendation to cyber-attack prediction: generating attack graphs and predicting future attacks[J]. Evolving Systems, 2020, 11 (3): 479- 490.
|
| 40 |
Yao S, Zhao J, Yu D, et al. ReAct: Synergizing reasoning and acting in language models[PP/OL]//International Conference on Learning Representations. Kigali: OpenReview. net, 2023. https://arxiv.org/abs/2210.03629.
|
| 41 |
Brown T B, Mann B, Ryder N, et al. Language models are few-shot learners[C]//Proceedings of the 34th International Conference on Neural Information Processing Systems. New York: ACM, 2020: 1877-1901.
|
| 42 |
Wang S R, Zhou W A, Jiang C. A survey of word embeddings based on deep learning[J]. Computing, 2020, 102 (3): 717- 740.
|
| 43 |
Hasanov I, Virtanen S, Hakkala A, et al. Application of large language models in cybersecurity: a systematic literature review[J]. IEEE Access, 2024, 12, 176751- 176778.
|
| 44 |
Kraeva I, Yakhyaeva G. Application of the metric learning for security incident playbook recommendation[C]//Proceedings of the 2021 IEEE 22nd International Conference of Young Professionals in Electron Devices and Materials (EDM). Piscataway: IEEE Press, 2021: 475-479.
|
| 45 |
Ranade P, Mittal S, Joshi A, et al. Using deep neural networks to translate multi-lingual threat intelligence[C]//Proceedings of the 2018 IEEE International Conference on Intelligence and Security Informatics (ISI). Piscataway: IEEE Press, 2018: 238-243.
|
/
| 〈 |
|
〉 |