圖檢索增強威脅檢測

2026年8月16日 00:00
站內 AI 整理稿

Computer Science > Cryptography and Security arXiv:2608.13050 (cs) [Submitted on 13 Aug 2026] Title:Operationalizing Cyber Threat Intelligence with GraphRAG Authors:Atul Kabra, Prakhar Paliwal, Manjesh K.

Hanawal View a PDF of the paper titled Operationalizing Cyber Threat Intelligence with GraphRAG, by Atul Kabra and 2 other authors View PDF HTML (experimental) Abstract:When a security researcher publishes a report on a cyberattack, detection engineers are supposed to turn it into working detection rules.

In practice, most automated attempts at this only extract the simplest clues from the report --- bad IP addresses, domain names, and file hashes --- and turn them into block lists.

This is a weak strategy, because attackers can change these simple clues within hours or days, so the resulting detections stop working almost as soon as they are deployed.Security teams describe this idea with the Pyramid of Pain.

This project asks whether feeding a report into a knowledge-graph retrieval system, Microsoft GraphRAG, rather than a standard vector-similarity retrieval system (Naive RAG), produces detection plans that rely more on these durable, top-of-pyramid clues.

Both systems are given the same report, the same generation instructions, and the same language model to write the final plan; only the retrieval step differs.

In a detailed case study of one APT28 report, the GraphRAG plan kept firing at 100\% of its detections after every IP address, domain, and file hash in the report was rotated, while the Naive RAG plan kept firing at only 29\%.

Repeating the comparison across nine real CTI reports from four vendors confirms the same pattern: GraphRAG plans consistently reach higher, harder-to-evade levels of the pyramid, even when the two systems end up close on total score.

The results support treating knowledge-graph-aware retrieval as the architecturally correct foundation for automatically generating SOC-deployable hunting plans, while showing that the wording of the generation prompt matters almost as much as the retrieval back-end itself.

Comments: 12 pages Subjects: Cryptography and Security (cs.CR); Artificial Intelligence (cs.AI) Cite as: arXiv:2608.13050 [cs.CR] (or arXiv:2608.13050v1 [cs.CR] for this version) https://doi.org/10.48550/arXiv.2608.

13050 Focus to learn more arXiv-issued DOI via DataCite (pending registration) Submission history From: Manjesh Kumar Hanawal [view email] [v1] Thu, 13 Aug 2026 10:15:05 UTC (500 KB) Full-text links: Access Paper: View a PDF of the paper titled Operationalizing Cyber Threat Intelligence with GraphRAG, by Atul Kabra and 2 other authorsView PDFHTML (experimental)TeX Source view license Current browse context: cs.

CR < prev | next > new | recent | 2026-08 Change to browse by: cs cs.AI References & Citations NASA ADSGoogle Scholar Semantic Scholar export BibTeX citation Loading...BibTeX formatted citation × loading...

Data provided by: Bookmark Bibliographic Tools Bibliographic and Citation Tools Bibliographic Explorer Toggle Bibliographic Explorer (What is the Explorer?) Connected Papers Toggle Connected Papers (What is Connected Papers?) Litmaps Toggle Litmaps (What is Litmaps?) scite.

ai Toggle scite Smart Citations (What are Smart Citations?) Code, Data, Media Code, Data and Media Associated with this Article alphaXiv Toggle alphaXiv (What is alphaXiv?) Links to Code Toggle CatalyzeX Code Finder for Papers (What is CatalyzeX?) DagsHub Toggle DagsHub (What is DagsHub?

) GotitPub Toggle Gotit.pub (What is GotitPub?) Huggingface Toggle Hugging Face (What is Huggingface?) ScienceCast Toggle ScienceCast (What is ScienceCast?) Demos Demos Replicate Toggle Replicate (What is Replicate?) Spaces Toggle Hugging Face Spaces (What is Spaces?) Spaces Toggle TXYZ.

AI (What is TXYZ.AI?) Related Papers Recommenders and Search Tools Link to Influence Flower Influence Flower (What are Influence Flowers?) Core recommender toggle CORE Recommender (What is CORE?

) Author Venue Institution Topic About arXivLabs arXivLabs: experimental projects with community collaborators arXivLabs is a framework that allows collaborators to develop and share new arXiv features directly on our website.

Both individuals and organizations that work with arXivLabs have embraced and accepted our values of openness, community, excellence, and user data privacy.arXiv is committed to these values and only works with partners that adhere to them.

Have an idea for a project that will add value for arXiv's community?Learn more about arXivLabs.Which authors of this paper are endorsers?| Disable MathJax (What is MathJax?)

Related

相關文章

AI偶像,不能照搬真人明星的邏輯

虛眸2026.08.24 14:26 · 來自北京全文4075字00:00 / 11:50就算看著再逼真,也知道不是人。文 | 虛眸第一波AI明星出道,並不順利。AI短劇《被裁掉的女孩》的虛擬女主角方桃子,代言隱形眼鏡時稱“戴了一天很舒服”,隨即被大眾質疑:一個沒有身體的AI角色,如何感受“舒服”?《與你深情,侵入餘生》中的男女主段宴和容寄僑,以演員身份二搭“出演”新劇《分手後男頻女頻大亂鬥》,讓粉絲對自家偶像究竟是誰、屬於哪個次元的世界產生認知混亂。

剛剛
何夕2077AI應用場景

KINO轉向家庭

根據業界消息指出,KINO 近期已調整發展方向,將業務重心轉向家庭應用場景。此舉顯示該公司正重新定位其產品與服務策略,以因應市場變化與用戶需求。 目前關於 KINO 轉向家庭的具體細節仍有限,但這項策略轉變可能意味著未來將推出更多針對家庭用戶的解決方案或功能。外界正密切關注後續動向,以了解這項調整將如何影響其生態布局。

7 小時前

小米推出米家掃拖機器人 7C:滾筒活水增壓拖地,到手價 2069.1 元

作者:浩渺 責編:浩渺 評論: 感謝網友 很宅很怕生 的線索投遞!8 月 23 日消息,米家掃拖機器人 7C 現已在小米有品上架預約,官方標價 2299 元,券後到手價 2069.1 元,8 月 26 日 10 點現貨開售(點擊前往)。從商品頁面獲悉,這款新品支持滾筒活水拖地,配備恆壓恆溼滾筒拖布,200 轉 / 分鐘高速洗拖,強效清潔咖啡漬、油漬、寵物腳印等頑固汙漬; 配合活水邊拖邊洗,有效減少二次汙染。

20 小時前

抖快B紅集體押注“AI互動內容”,創作者如何抓住新機會?

中國四大內容平台抖音、快手、B站與小紅書近期同時押注AI互動內容,讓觀眾能與AI角色對話或主導劇情,被視為下一波短影音戰場的提前卡位。海外相關新創App也獲得近億美元融資,使這場競賽升級為資金與流量的軍備賽。對創作者而言,這波浪潮將編劇與產品設計能力納入創作門檻,平台雖推出工具與分成機制,但商業模式仍在摸索階段。

2 天前