A SoK for SoCs: Reading the TI Leaves on AI for Cyber Threat Intelligence Generation and Sharing
Systematic literature survey maps how AI is used to generate and share cyber threat intelligence, exposing fragmentation that hampers automated indicator pipelines in operational SOCs.
Summary written by editorial AI · Source link below
arXiv:2609.01174v1 Announce Type: new Abstract: Cyber Threat Intelligence (CTI) is essential for defending mission-critical infrastructure, yet the process of transforming raw attack evidence into shareable CTI remains fragmented and understudied. We conduct a literature survey of academic papers, organizing the CTI lifecycle into three stages: Threat Data Collection, CTI Generation and Sharing, and CTI Consumption. The first and third stages are well represented in the literature, whereas on
Editorial Analysis
Enterprises investing in CTI automation need to understand where academic research still lags behind operational needs; this survey offers a gap map for informed tooling decisions.
Cross-reference the identified gaps with your CTI automation backlog to prioritise investments that address the most impactful shortcomings.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at arXiv Crypto & Security in a new tab.
More from the Threat Intel Desk
- Attackers conceal phishing lures using invisible Unicode characters1d
- Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication1d
- Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner2d
- Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials2d
- Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain2d