article
The rapid expansion and variety of cyber-threat information put enormous pressure on security operations centers (SOCs) that must convert unstructured data into understandable signals and make decisions upon it. This paper develops a Cyber-Threat-Intelligence (CTI) framework that integrates vulnerability information, product inventories, and weakness taxonomies into a domain-specific knowledge graph via automatic fusing. The proposed solution covers 284,296 CVEs, 101,644 CPE identifiers, and 965 CWE weaknesses, generating more than 800,000 typed edges linking threats, assets, tactics, and mitigations in an integrated CTI Knowledge graph. The graph was cross validated against four external standard datasets achieves full coverage of ATT&CK CAPEC, STIX, and CVE-CAPEC mappings, 98.83 % node recall for CWE references, and edge-level full coverage for CAUSES_WEAKNESS and 99.83 % for AFFECTS; EXPLOITED_BY relations reach 74.58 % precision and recall. These results confirm that the integrated graph preserves structural integrity while substantially consolidating fragmented CTI sources, by consolidating fragmented CTI sources into a semantic model of high fidelity that could reduce analyst workload but also enables SOC workflows to be more efficient, thereby laying the groundwork for more proactive and intelligent cyber-defense capabilities.
This page summarises published work. The authoritative version sits with the publisher.
DOI: 10.1109/icca66035.2025.11430746
Is something wrong with this record? Report it or request removal.
Discussion
Have you built on this work, tried to replicate it, or seen it applied in practice? Share what you know. Verified researchers and MARATTO™ domain experts can open a discussion, and any member can reply. Contributions are reviewed before they appear.
No discussion yet. Open the first thread.
New to MARATTO™? Create a free account.