Cyber Threat Intelligence (CTI) Utilizing Machine Learning to Identify Security Attacks
摘要
Automation of threat analysis has become essential to improving the efficacy and efficiency of Cyber Threat Intelligence (CTI) in the ever-changing cybersecurity environment. The use of machine learning techniques to automate threat analysis in several domains, such as threat classification, prediction, correlation, and integration with security information and event management (SIEM) systems, is examined in this literature review. By leveraging ML, organizations can swiftly identify and respond to complex cyber threats, reducing the reliance on manual analysis and enabling more proactive defenses. Papers from different databases like Google Scholar, PubMed, Clavirate, IEEE, and other indexed journals were used. The integration of ML with SIEM systems further enhances real-time threat detection and response capabilities. Despite the significant benefits, challenges such as data quality, model interpretability, and adversarial attacks present ongoing obstacles to the effective implementation of ML in threat analysis. Future advancements in this field are expected to focus on improving model robustness, interpretability, and collaborative threat intelligence sharing through emerging technologies like federated learning. This abstract synthesizes key findings from recent studies, highlighting the transformative potential of ML in automating threat analysis and shaping the future of cybersecurity.