DoctorateOpen Access

Centrally monitoring cyber threat intelligence data and development of new approaches in detecting of attacks

2025
0 views
0 downloads
Advisor: Prof. Dr. Davut Hanbay ; Prof. Dr. Resul Daş

Abstract (EN)

Today's dynamically changing cyber security environment and increasing threat and attack complexity have made it necessary to quickly extract meaningful information from raw security content and turn it into action. The inability of cyber security experts to respond to or anticipate threats in a timely manner can inevitably expose organisations to significant data loss, reputational damage and operational disruptions. Therefore, obtaining cyber threat intelligence quickly and accurately is vital for organisations to increase the effectiveness of defence strategies and minimise potential damages. The ability of security experts to quickly analyse and extract insights from these large volumes of content without losing their intelligence value has become a significant challenge, especially due to the increasing volume of data. Due to the complex and dynamic nature of cyber threats, traditional text analysis methods are insufficient to extract meaningful insights from cyber threat data. In this work, we propose a language model that extracts cyber entities from raw threat texts using pre-trained language models and an ontology describing the relationships between these entities, and we present a new approach to analyse cyber entities and relationships using knowledge graphs. With this new approach, it is possible to detect new threats and targets that cannot be predicted by traditional analyses by performing analyses on knowledge graphs. By analysing cyber threat data with knowledge graphs, this thesis provides a better understanding of the relationships between threat actors and malware, and can also help discover previously hidden relationships between different threat actors and malware. The results highlights the importance of knowledge graphs in the development of cyber security intelligence, providing greater insight into cyber threats. In addition, the results of the analysis can also help in the development of effective defence strategies.

Author

Doygun Demirol

How to Cite

Doygun Demirol (Doctorate thesis). Centrally monitoring cyber threat intelligence data and development of new approaches in detecting of attacks, 2025, İnönü University.

License

Tüm Hakları Saklıdır

This work is shared under the specified license terms.

More theses from İnönü University