Labeling Hacker Exploits for Proactive Cyber Threat Intelligence: A Deep Transfer Learning Approach

Labeling Hacker Exploits for Proactive Cyber Threat Intelligence: A Deep Transfer Learning Approach
复制标题

DOI:
10.1109/isi49825.2020.9280548
复制
发表时间:
2020-11
期刊:
2020 IEEE International Conference on Intelligence and Security Informatics (ISI)
影响因子:
--
通讯作者:
Benjamin Ampel;Sagar Samtani;Hongyi Zhu;Steven Ullman;Hsinchun Chen
Benjamin Ampel;Sagar Samtani;Hongyi Zhu;Steven Ullman;Hsinchun Chen
中科院分区:
其他
文献类型:
--
作者:
Benjamin Ampel;Sagar Samtani;Hongyi Zhu;Steven Ullman;Hsinchun Chen

文献摘要

被引文献

相似文献

随着新技术的快速发展,漏洞数量达到了有史以来的最高水平。企业正在投资开发网络威胁情报(CTI)以应对这些新的漏洞。然而,这种CTI通常是基于内部数据的被动反应。黑客论坛可以通过对新趋势和漏洞利用的自动化分析提供主动的CTI价值。识别漏洞利用的一种方法是分析这些论坛上发布的源代码。这些源代码片段往往杂乱且无标签,使得标准的数据标注技术无效。本研究旨在设计一个用于自动收集和分类黑客论坛漏洞利用源代码的新颖框架。我们提出了一个深度迁移学习框架,即用于漏洞利用标注的深度迁移学习(DTL - EL)。DTL - EL利用从专业标注的漏洞利用中学习到的表示,更好地推广到黑客论坛的漏洞利用。该模型将收集到的黑客论坛漏洞利用分类为八个预定义类别,以实现主动和及时的CTI。本研究结果表明,DTL - EL在黑客论坛文献中的表现优于其他突出模型。
With the rapid development of new technologies, vulnerabilities are at an all-time high. Companies are investing in developing Cyber Threat Intelligence (CTI) to counteract these new vulnerabilities. However, this CTI is generally reactive based on internal data. Hacker forums can provide proactive CTI value through automated analysis of new trends and exploits. One way to identify exploits is by analyzing the source code that is posted on these forums. These source code snippets are often noisy and unlabeled, making standard data labeling techniques ineffective. This study aims to design a novel framework for the automated collection and categorization of hacker forum exploit source code. We propose a deep transfer learning framework, the Deep Transfer Learning for Exploit Labeling (DTL-EL). DTL-EL leverages the learned representation from professional labeled exploits to better generalize to hacker forum exploits. This model classifies the collected hacker forum exploits into eight predefined categories for proactive and timely CTI. The results of this study indicate that DTL-EL outperforms other prominent models in hacker forum literature.