Electronic Thesis/Dissertation
 

Emerging Threat Analysis Using Machine Learning on Unstructured Cyber Threat Intelligence

Open Access Deposited

As the sophistication of cyber threats grows, the demand requires increasingly advanced defensive capabilities. The modern cybersecurity landscape faces an unprecedented crisis, with monetary losses from cybercrime reaching $945 billion in 2020 (Center for Strategic and International Studies, 2020). Traditional threat detection methods demonstrate a dangerous bias toward common attack patterns while consistently failing to identify rare tactics that often signal the most devastating attacks (He & Garcia, 2009). The research to solve this issue resulted in the architecture of Tactic-Aware Adaptive Learning (TAAL). This novel dual-pathway neural network design was able to address the difficult challenge of detecting rare and emerging threats in unstructured Cyber Threat Intelligence (CTI). TAAL enhances threat detection through a new dual-pathway architecture, which processes common and rare tactics through specialized, separate, neural pathways. This new direction addresses the issue of severe class imbalance that is inherent in many cybersecurity datasets, where rare tactics that may represent new or emerging threats are overlooked using conventional single-pathway models (Li, Huang, & Chen, 2024). By using dedicated processing capacity and attention mechanisms to these rare tactics, TAAL was able to achieve significant improvements in rare and emerging threat detection while exceeding performance on common attack patterns in current published systems. An evaluation against a documented specified DistilBERT baseline demonstrates that the optimized TAAL architecture achieves a F0.5 score of 0.856 compared to the baseline's 0.735, representing a 16.5% improvement. The best-performing TAAL model, utilizing CyBERT, achieves a F0.5 score of 0.892—a 21.5% improvement over baseline. The real significance is that TAAL demonstrates a 37% improvement in F1 score for rare tactic detection, which confirms that it is highly effective in the identification of rare or emerging threats that would likely remain undetected. An integrated ablation study was used to validate each architectural component within TAAL. The focal loss and pathway splits features prove to be the most critical, whose removal caused a -8.5% drop and -9.5% drop respectively from the model. The results show that this new specialized multi-pathway architecture represents a new direction in cybersecurity machine learning, providing analysts with a highly effective tool for identifying both common and rare adversarial techniques (Wang et al., 2023). This novel approach enables corporations to achieve a more proactive approach in an evolving threat landscape alerting to rare and emerging threats that may prevent disastrous breaches.

Author Language Keyword Date created Type of Work License
  • All rights reserved
Rights statement GW Unit Degree Advisor Committee Member(s) Persistent URL

Notice to Authors

If you are the author of this work and you have any questions about the information on this page, please use the Contact form to get in touch with us.

Thumbnail Title Date Uploaded Visibility Actions
Preview of Lindstrom_gwu_0075A_17421.pdf Lindstrom_gwu_0075A_17421.pdf 2025-12-11 Open Access