As the volume of Cyber Threat Intelligence (CTI) reports from multiple sources continues to rise, automated tools are essential for consistent and accurate management of heterogeneous data. Existing methods, such as STIXnet and aCTIon, require substantial human intervention, limiting their scalability. This paper introduces STIXAgent, a multi-agent framework that automates the conversion of unstructured CTI reports into STIX-compliant JSON structures. Our approach leverages LangGraph to orchestrate modular task execution, incorporating Large Language Models (LLMs) for information extraction, structured validation, and error handling. This paper utilises 5 LLMs (GPT4o, Gemini, Llama3 (8B), DeepseekR1-distilled Qwen32B, and LLama 70B) for multiagentic LLM evaluation, introducing in the process a novel Bayesian statistical evaluation framework to assess model performance, offering probabilistic insights into content accuracy and structural consistency. We benchmark STIXAgent across 10, 40, 100, and 400 reports from Microsoft and Talos, respectively. The results demonstrate that STIXAgent not only enhances automation but also improves reliability through structured evaluation, setting a new standard for scalable CTI processing.
KeywordsCyber Threat IntelligenceLarge Language Models (LLMs)Natural Language Processing (NLP)Structured Threat Information Expression (STIX)
Zhang, J., Bu, H., Wen, H., Chen, Y., Li, L. and Zhu, H. (2024) When LLMs Meet Cybersecurity: A Systematic Literature Review.
Chowdhary, K.R. (2020) Natural Language Processing. In: Fundamentals of Artificial Intelligence , Springer India, 603-649. https://doi.org/10.1007/978-81-322-3972-7_19
Sun, P., Yang, X., Zhao, X. and Wang, Z. (2018) An Overview of Named Entity Recognition. 2018 International Conference on Asian Language Processing ( IALP ), Bandung, 15-17 November 2018, 273-278. https://doi.org/10.1109/ialp.2018.8629225
Weegar, R. (2021) Applying Natural Language Processing to Electronic Medical Records for Estimating Healthy Life Expectancy. The Lancet Regional Health — Western Pacific , 9, Article ID: 100132. https://doi.org/10.1016/j.lanwpc.2021.100132
Mesbah, S., Lofi, C., Torre, M.V., Bozzon, A. and Houben, G. (2018) TSE-NER: An Iterative Approach for Long-Tail Entity Extraction in Scientific Publications. In: Vrandečić, D., et al ., Eds., The Semantic Web — ISWC 2018, Springer International Publishing, 127-143. https://doi.org/10.1007/978-3-030-00671-6_8
Nadgeri, A., Bastos, A., Singh, K., Mulang’, I.O., Hoffart, J., Shekarpour, S., et al . (2021) KGPool: Dynamic Knowledge Graph Context Selection for Relation Extraction. Findings of the Association for Computational Linguistics : ACL - IJCNLP 2021, August 2021, 535-548. https://doi.org/10.18653/v1/2021.findings-acl.48
Piskorski, J. and Yangarber, R. (2012) Information Extraction: Past, Present and Future. In: Poibeau, T., et al ., Eds., Multi - Source , Multilingual Information Extraction and Summarization , Springer, 23-49. https://doi.org/10.1007/978-3-642-28569-1_2
Park, J.S., O'Brien, J., Cai, C.J., Morris, M.R., Liang, P. and Bernstein, M.S. (2023). Generative Agents: Interactive Simulacra of Human Behavior. Proceedings of the 36 th Annual ACM Symposium on User Interface Software and Technology , San Francisco, 29 October-1 November 2023, 1-22. https://doi.org/10.1145/3586183.3606763
Li, X., Wang, S., Zeng, S., Wu, Y. and Yang, Y. (2024) A Survey on LLM-Based Multi-Agent Systems: Workflow, Infrastructure, and Challenges. Vicinagearth , 1, Article No. 9. https://doi.org/10.1007/s44336-024-00009-2
Porkorny, Z. (2018) What Are the Phases of the Threat Intelligence Lifecycle. The Threat Intelligence Handbook.
Wagner, T.D., Mahbub, K., Palomar, E. and Abdallah, A.E. (2019) Cyber Threat Intelligence Sharing: Survey and Research Directions. Computers & Security , 87, Article ID: 101589. https://doi.org/10.1016/j.cose.2019.101589
Barnum, S. (2012) Standardizing Cyber Threat Intelligence Information with the Structured Threat Information Expression (STIX). Mitre Corporation , 11, 1-22.
Marchiori, F., Conti, M. and Verde, N.V. (2023) STIXnet: A Novel and Modular Solution for Extracting All STIX Objects in CTI Reports. Proceedings of the 18 th International Conference on Availability , Reliability and Security , Benevento, 29 August-1 September 2023, 1-11. https://doi.org/10.1145/3600160.3600182
Siracusano, G., et al . (2023) Time for Action: Automated Analysis of Cyber Threat Intelligence in the Wild.
Perrina, F., Marchiori, F., Conti, M. and Verde, N.V. (2023) AGIR: Automating Cyber Threat Intelligence Reporting with Natural Language Generation. 2023 IEEE International Conference on Big Data ( BigData ), Sorrento, 15-18 December 2023, 3053-3062. https://doi.org/10.1109/bigdata59044.2023.10386116
Alam, M.T., Bhushl, D., Nguyen, L. and Rastogi, N. (2024) CTIBench: A Benchmark for Evaluating LLMs in Cyber Threat Intelligence.
Weerawardhana, S., Mukherjee, S., Ray, I. and Howe, A. (2015) Automated Extraction of Vulnerability Information for Home Computer Security. In: Cuppens, F., et al ., Eds., Foundations and Practice of Security , Springer International Publishing, 356-366. https://doi.org/10.1007/978-3-319-17040-4_24
Li, T., Guo, Y. and Ju, A. (2019) A Self-Attention-Based Approach for Named Entity Recognition in Cybersecurity. 2019 15 th International Conference on Computational Intelligence and Security ( CIS ), Macao, 13-16 December 2019, 147-150. https://doi.org/10.1109/cis.2019.00039
Zhou, Y., Tang, Y., Yi, M., Xi, C. and Lu, H. (2022) CTI View: APT Threat Intelligence Analysis System. Security and Communication Networks , 2022, Article ID: 9875199. https://doi.org/10.1155/2022/9875199
Zhou, Y., Ren, Y., Yi, M., Xiao, Y., Tan, Z., Moustafa, N., et al . (2023) CDTier: A Chinese Dataset of Threat Intelligence Entity Relationships. IEEE Transactions on Sustainable Computing , 8, 627-638. https://doi.org/10.1109/tsusc.2023.3240411
Ranade, P., Piplai, A., Joshi, A. and Finin, T. (2021) CyBERT: Contextualized Embeddings for the Cybersecurity Domain. 2021 IEEE International Conference on Big Data ( Big Data ), Orlando, 15-18 December 2021, 3334-3342. https://doi.org/10.1109/bigdata52589.2021.9671824
Wang, X., Liu, R., Yang, J., Chen, R., Ling, Z., Yang, P., et al . (2022) Cyber Threat Intelligence Entity Extraction Based on Deep Learning and Field Knowledge Engineering. 2022 IEEE 25 th International Conference on Computer Supported Cooperative Work in Design ( CSCWD ), Hangzhou, 4-6 May 2022, 406-413. https://doi.org/10.1109/cscwd54268.2022.9776139