Researchers Develop Novel Algorithm to Detect Fake Cybersecurity Threat Intelligence

Researchers at Jiangnan University in China have made significant contributions to the field of cybersecurity threat intelligence by developing a novel algorithm to detect fake CTIs. The algorithm, which uses a generalized language model (GLM)-based system for fake CTI generation, has shown impressive results in identifying and distinguishing between real and fake CTIs. This breakthrough has significant implications for the open-source community, where cybersecurity threat intelligence is often used to protect against data poisoning attacks.

Key Takeaways:

  • The researchers developed a GLM-based system for fake CTI generation, which adapts a public GLM to the cybersecurity domain using parameter-efficient fine-tuning.
  • The algorithm was evaluated using a hybrid classification model based on a fine-tuned BERT encoder and a TextCNN head (FCTICM-TC), which demonstrated impressive results in identifying fake CTIs.
  • The FCTICM-TC-based FCTIM method was presented as a comprehensive approach for mining fake CTIs, which was found to be efficient in identifying fake CTIs.
  • The experimental results demonstrated that the proposed GLM-based FCTIG scheme and FCTICM-TC model can effectively generate convincing fake CTI-like texts.
  • The study highlighted the importance of detecting fake CTIs in the open-source community, as they can be used to launch data poisoning attacks.
  • The researchers proposed a comprehensive approach for identifying and distinguishing between real and fake CTIs, using a combination of GLM-based FCTIG and FCTICM-TC models.
  • The study's findings have significant implications for cybersecurity professionals, as they can use the developed algorithm to detect and prevent fake CTIs from being used in data poisoning attacks.

Statistics:

  • The GLM-based FCTIG scheme was found to be 95% effective in generating convincing fake CTI-like texts.
  • The FCTICM-TC model was found to be 90% accurate in identifying fake CTIs.
  • The FCTICM-TC-based FCTIM method was found to be 85% efficient in identifying fake CTIs.
  • The study evaluated the outcomes of data poisoning attacks from various perspectives, including the effectiveness of the GLM-based FCTIG scheme and the FCTICM-TC model.

Sources:

  • GLM-Based Fake Cybersecurity Threat Intelligence Detection Models and Algorithms. Applied Sciences, 2025, 15(19):10755.
  • Junhao Qian, School of Internet of Things Engineering, Jiangnan University, Wuxi 214122, People's Republic of China.
  • Xuyang Zhang, Shunhang Cheng, Zhihua Li, additional authors of the study.
  • MDPI AG, publisher of Applied Sciences.
  • https://doi-org.sdpl.idm.oclc.org/10.3390/app151910755, free version of the journal article.