<p>Effective Cyber Threat Intelligence (CTI) requires a localized and interpretable system that is capable of addressing region-specific threats. In this study, we present an integrated approach that combines both Knowledge Graph construction with Cyber-based query answering to enhance cybersecurity analysis within Nigerian cyberspace. Built in Neo4j, the system represents key CTI entities such as <i>Actor</i>, <i>Technique</i>, and <i>Organization</i>, the proposed approach shows feasibility and transparent threat analysis by a scheme guided methodology. A use case involving <Emphasis FontCategory="NonProportional">SilverTerrier</Emphasis>, a major threat group in Nigerian cyberspace generated a graph which comprises 287 nodes and 364 relationships, demonstrating the approach’s ability to organize heterogeneous threat data into a more coherent and semantically consistent structure. The results demonstrate the feasibility of the proposed integration as a domain-specific approach that supports structured and efficient query execution, improved situational awareness, and proactive defense within the cyber environment or ecosystem.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Integrating knowledge graphs and cypher queries for enhanced Cyber threat intelligence in Nigerian cyberspace

  • Emmanuel Innocent Umoh,
  • Sanju Tiwari,
  • Kusum Lata

摘要

Effective Cyber Threat Intelligence (CTI) requires a localized and interpretable system that is capable of addressing region-specific threats. In this study, we present an integrated approach that combines both Knowledge Graph construction with Cyber-based query answering to enhance cybersecurity analysis within Nigerian cyberspace. Built in Neo4j, the system represents key CTI entities such as Actor, Technique, and Organization, the proposed approach shows feasibility and transparent threat analysis by a scheme guided methodology. A use case involving SilverTerrier, a major threat group in Nigerian cyberspace generated a graph which comprises 287 nodes and 364 relationships, demonstrating the approach’s ability to organize heterogeneous threat data into a more coherent and semantically consistent structure. The results demonstrate the feasibility of the proposed integration as a domain-specific approach that supports structured and efficient query execution, improved situational awareness, and proactive defense within the cyber environment or ecosystem.