Key points are not available for this paper at this time.
The contemporary cyber-threat landscape is becoming increasingly diverse and complex, creating a persistent gap between situational awareness and operational response. This study presents a framework designed to bridge this gap by transforming up-to-date cyber-threat intelligence (CTI) into standardized knowledge structures and actionable defense measures. First, the proposed framework integrates the threat data collected from OpenCTI and normalizes them based on the MITRE ATT&CK tactics and techniques matrix. It then leverages a large language model to automatically generate diverse threat scenarios based on the analyzed intelligence. Each scenario is organized as a tactic sequence, and individual techniques are mapped to MITRE D3FEND defensive categories based on official ATT&CK–D3FEND relationships and structured contextual interpretation. Finally, the framework produces outputs in the form of a Defense Description that includes the corresponding technique IDs, recommended defense strategies, supporting rationales, and prerequisites. An evaluation using several recent cases demonstrates that the proposed framework effectively connects current threat intelligence with practical defense strategies. In summary, the proposed framework strengthens proactive cyber defense by directly linking structured attack flows to actionable context-aware defensive techniques. In addition, this framework provides a structured pipeline that systematizes and automates steps conventionally performed manually, thereby reducing repetitive analyst effort.
Jo et al. (Mon,) studied this question.