TY - GEN
T1 - Credibility-Driven Quality Assessment of Multi-source Cyber Threat Intelligence
AU - Wang, Mengjiao
AU - Zeng, Liyi
AU - Zhang, Mingrui
AU - Xiang, Xiayu
AU - Gu, Zhaoquan
N1 - Publisher Copyright:
© The Author(s), under exclusive license to Springer Nature Singapore Pte Ltd. 2026.
PY - 2026
Y1 - 2026
N2 - As cyber threats grow in sophistication, single-source cyber threat intelligence proves inadequate for robust defense. Multi-source cyber threat intelligence offers broader coverage but introduces challenges such as redundancy, format inconsistency, and variable credibility. Open and commercial sources often contain low-value, duplicated, or short-lived data, complicating reliable insight extraction. To address this, we propose a credibility analysis framework for resolving conflicts in multi-source cyber threat intelligence by jointly evaluating intelligence content and source reliability. We design a Random Forest-based model to assess content quality and employ Retrieval-Augmented Generation to enrich source evaluation, leveraging a Large Language Model to generate contextual insights from expert knowledge. A feedback mechanism dynamically refines credibility scores by reinforcing agreement between content and source assessments. Experiments on a real-world cyber threat intelligence dataset show that the proposed method achieves high accuracy in classifying cyber threat intelligence as reliable, unreliable, or uncertain, effectively filtering noise and enhancing overall intelligence quality.
AB - As cyber threats grow in sophistication, single-source cyber threat intelligence proves inadequate for robust defense. Multi-source cyber threat intelligence offers broader coverage but introduces challenges such as redundancy, format inconsistency, and variable credibility. Open and commercial sources often contain low-value, duplicated, or short-lived data, complicating reliable insight extraction. To address this, we propose a credibility analysis framework for resolving conflicts in multi-source cyber threat intelligence by jointly evaluating intelligence content and source reliability. We design a Random Forest-based model to assess content quality and employ Retrieval-Augmented Generation to enrich source evaluation, leveraging a Large Language Model to generate contextual insights from expert knowledge. A feedback mechanism dynamically refines credibility scores by reinforcing agreement between content and source assessments. Experiments on a real-world cyber threat intelligence dataset show that the proposed method achieves high accuracy in classifying cyber threat intelligence as reliable, unreliable, or uncertain, effectively filtering noise and enhancing overall intelligence quality.
KW - Credibility Analysis
KW - Cyber Threat Intelligence
KW - Retrieval-Augmented Generation
UR - https://www.scopus.com/pages/publications/105020737044
U2 - 10.1007/978-981-95-3456-2_3
DO - 10.1007/978-981-95-3456-2_3
M3 - 会议稿件
AN - SCOPUS:105020737044
SN - 9789819534555
T3 - Lecture Notes in Computer Science
SP - 34
EP - 41
BT - Advanced Data Mining and Applications - 21st International Conference, ADMA 2025, Proceedings
A2 - Yoshikawa, Masatoshi
A2 - Meng, Xiaofeng
A2 - Cao, Yang
A2 - Xiao, Chuan
A2 - Chen, Weitong
A2 - Wang, Yanda
PB - Springer Science and Business Media Deutschland GmbH
T2 - 21st International Conference on Advanced Data Mining and Applications, ADMA 2025
Y2 - 22 October 2025 through 24 October 2025
ER -