An Intelligent Cyber Threat Intelligence Frame-work for Network Indicator Analysis and Proac-tive Threat Detection Using MITRE ATT&CK
Authors-P.Premchand Goud, Valli Mounika
Keyword-Cyber Threat Intelligence, Cybersecurity, MITRE ATT&CK, Indicators of Compromise, Threat Detection, Network Security, STIX, TAXII, Intrusion Detection System, Sigma Rules, Vulner-ability Management, YARA, SIEM, Threat Hunting
The increasing dependence on digital infrastructure has significantly expanded the cyber threat landscape, making organizations more vulnerable to sophisticated cyber-attacks. Traditional security mechanisms often rely on reactive defense strategies that struggle to identify emerging threats before they compromise critical assets. To address these challenges, this research propos-es an intelligent Cyber Threat Intelligence (CTI) framework that utilizes technical threat indica-tors to strengthen proactive cyber defense. The proposed framework focuses on the collection, processing, correlation, and consumption of network-based indicators such as malicious IP addresses, suspicious domains, intrusion detection signatures, and vulnerability intelligence. Threat information is organized using standardized CTI formats and mapped to the MITRE ATT&CK framework to improve the understanding of attacker behavior and support effective defensive decision-making. The framework further integrates network intrusion detection sys-tems, vulnerability repositories, Sigma rules, YARA signatures, and threat intelligence feeds to enable continuous monitoring and rapid detection of malicious activities. By combining struc-tured intelligence with real-time security monitoring, the proposed solution enhances threat visi-bility, reduces response time, and supports proactive mitigation against advanced cyber threats. The framework also assists security analysts in prioritizing vulnerabilities, identifying attack patterns, and strengthening organizational cyber resilience through intelligence-driven security operations.
Doi-[https://doi.org/10.5281/zenodo.21735863]