An Automated Framework for Extracting Reachable Attack Chains from Cyber Threat Intelligence Reports
This paper proposes an automated framework that extracts reachable attack chains by modeling each attack step as an attack unit of preconditions, an attack behavior, and postconditions, and produces attack units that are more complete and consistent than those generated by end-to-end LLM baselines.
Wenbo Hou, N. Hu, Xueping Wang et al.
· 0 citations