A Novel Approach for Cyber Threat Analysis Systems Using BERT Model from Cyber Threat Intelligence Data
| dc.contributor.author | Demirol, Doygun | |
| dc.contributor.author | Das, Resul | |
| dc.contributor.author | Hanbay, Davut | |
| dc.date.accessioned | 2026-04-04T13:30:56Z | |
| dc.date.available | 2026-04-04T13:30:56Z | |
| dc.date.issued | 2025 | |
| dc.department | İnönü Üniversitesi | |
| dc.description.abstract | As today's cybersecurity environment is becoming increasingly complex, it is crucial to analyse threats quickly and effectively. A delayed response or lack of foresight can lead to data loss, reputational damage, and operational disruptions. Therefore, developing methods that can rapidly extract valuable threat intelligence is a critical need to strengthen defence strategies and minimise potential damage. This paper presents an innovative approach that integrates knowledge graphs and a fine-tuned BERT-based model to analyse cyber threat intelligence (CTI) data. The proposed system extracts cyber entities such as threat actors, malware, campaigns, and targets from unstructured threat reports and establishes their relationships using an ontology-driven framework. A named entity recognition dataset was created and a BERT-based model was trained. To address the class imbalance, oversampling and a focal loss function were applied, achieving an F1 score of 96%. The extracted entities and relationships were visualised and analysed using knowledge graphs, enabling the advanced threat analysis and prediction of potential attack targets. This approach enhances cyber-attack prediction and prevention through knowledge graphs. | |
| dc.identifier.doi | 10.3390/sym17040587 | |
| dc.identifier.issn | 2073-8994 | |
| dc.identifier.issue | 4 | |
| dc.identifier.orcid | 0000-0002-3272-1078 | |
| dc.identifier.orcid | 0000-0003-2271-7865 | |
| dc.identifier.orcid | 0000-0002-6113-4649 | |
| dc.identifier.scopus | 2-s2.0-105003645978 | |
| dc.identifier.scopusquality | Q1 | |
| dc.identifier.uri | https://doi.org/10.3390/sym17040587 | |
| dc.identifier.uri | https://hdl.handle.net/11616/108475 | |
| dc.identifier.volume | 17 | |
| dc.identifier.wos | WOS:001475625900001 | |
| dc.identifier.wosquality | Q2 | |
| dc.indekslendigikaynak | Web of Science | |
| dc.indekslendigikaynak | Scopus | |
| dc.language.iso | en | |
| dc.publisher | Mdpi | |
| dc.relation.ispartof | Symmetry-Basel | |
| dc.relation.publicationcategory | Makale - Uluslararası Hakemli Dergi - Kurum Öğretim Elemanı | |
| dc.rights | info:eu-repo/semantics/openAccess | |
| dc.snmz | KA_WOS_20250329 | |
| dc.subject | cyber threat intelligence | |
| dc.subject | knowledge graphs | |
| dc.subject | named entity recognition | |
| dc.subject | pre-trained language model | |
| dc.title | A Novel Approach for Cyber Threat Analysis Systems Using BERT Model from Cyber Threat Intelligence Data | |
| dc.type | Article |











