基于MCP智能体的通用威胁情报知识图谱构建方法
作者:
作者单位:

作者简介:

通讯作者:

中图分类号:

TP309

基金项目:

国家自然科学基金(62302236); 江苏省前沿技术研发计划(BF2024071); 江苏省科学技术厅重点研发计划(BE2022081)


Construction Method for Universal Threat Intelligence Knowledge Graph Based on MCP Agent
Author:
Affiliation:

Fund Project:

  • 摘要
  • |
  • 图/表
  • |
  • 访问统计
  • |
  • 参考文献
  • |
  • 相似文献
  • |
  • 引证文献
  • |
  • 资源附件
  • |
  • 文章评论
    摘要:

    随着网络攻击的复杂性不断增加, 威胁情报的收集与整合面临着分散化问题. 在此背景下, 企业开始构建私有化的威胁情报知识图谱系统. 然而传统构建方法效率低下, 因实体关系抽取不准确而难以有效发挥作用. 为解决以上问题, 提出一种基于MCP (model context protocol)智能体的通用威胁情报知识图谱构建框架OPFA (one prompt for all). 通过动态语义主体定位, 微调大语言模型的提示词模板, 从而驱动智能体对威胁实体关系进行抽取. 威胁实体关系将作为知识图谱的节点与边被自动化创建, 通过实体属性值匹配以关联威胁情报, 形成完整的知识图谱. 接着, 系统会针对关键威胁实体(如漏洞、恶意样本)拉取MCP资源从而完成订制化的知识图谱扩充. 实验表明, 智能体不仅能够提升威胁实体和实体关系抽取的精确率(分别为97.22%和97.83%)、召回率(分别为90.91%和95.52%)与F1值(分别为94.44%和96.66%), 还能有效提高知识图谱的构建效率.

    Abstract:

    With the increasing complexity of cyber attacks, the collection and integration of threat intelligence face challenges of fragmentation. In this context, enterprises have begun building private threat intelligence knowledge graph systems. However, traditional construction methods suffer from inefficiency and limited effectiveness due to inaccurate extraction of entities and their relationships. To address these issues, this study proposes OPFA: a general threat intelligence knowledge graph construction framework based on model context protocol (MCP) agents. Through dynamic semantic subject positioning, large language model prompt templates are fine-tuned to drive agents to extract threat entities and their relationships. These threat entities and relationships are automatically created as nodes and edges in the knowledge graph, and threat intelligence is then linked through entity attribute value matching to form a complete knowledge graph. The system subsequently retrieves MCP resources for critical threat entities (such as vulnerabilities and malicious samples) to achieve customized knowledge graph expansion. Experimental results demonstrate that the agents not only improve Precision (97.22% and 97.83%, respectively), Recall (90.91% and 95.52%, respectively), and F1-score (94.44% and 96.66%, respectively) in threat entity and entity relationship extraction, but also effectively enhance the construction efficiency of the knowledge graph.

    参考文献
    相似文献
    引证文献
引用本文

沙乐天,薛磊,陈霄,李德强,肖甫.基于MCP智能体的通用威胁情报知识图谱构建方法.软件学报,,():1-19

复制
相关视频

分享
文章指标
  • 点击次数:
  • 下载次数:
  • HTML阅读次数:
  • 引用次数:
历史
  • 收稿日期:2025-04-21
  • 最后修改日期:2025-09-28
  • 录用日期:
  • 在线发布日期: 2026-07-15
  • 出版日期:
文章二维码
您是第位访问者
版权所有:中国科学院软件研究所 京ICP备05046678号-3
地址:北京市海淀区中关村南四街4号,邮政编码:100190
电话:010-62562563 传真:010-62562533 Email:jos@iscas.ac.cn
技术支持:北京勤云科技发展有限公司

京公网安备 11040202500063号