MAD-CTI: Cyber Threat Intelligence Analysis of the Dark Web Using a Multi-Agent Framework

The dark web is a host to illicit activities where hacker forums, blogs, and articles provide significant insights into Cyber Threat Intelligence (CTI) that are frequently unavailable on the surface web. The increasing incidence of security breaches underscores the necessity for advanced CTI solutio...

Full description

Saved in:
Bibliographic Details
Main Authors: Sayuj Shah, Vijay K. Madisetti
Format: Article
Language:English
Published: IEEE 2025-01-01
Series:IEEE Access
Subjects:
Online Access:https://ieeexplore.ieee.org/document/10908603/
Tags: Add Tag
No Tags, Be the first to tag this record!
Description
Summary:The dark web is a host to illicit activities where hacker forums, blogs, and articles provide significant insights into Cyber Threat Intelligence (CTI) that are frequently unavailable on the surface web. The increasing incidence of security breaches underscores the necessity for advanced CTI solutions to defend against emerging threats. This paper introduces MAD-CTI, a novel multi-agent framework based on Large Language Models (LLM) designed to extract insights from dark web sources. It independently scrapes, analyzes, and classifies content related to vulnerabilities, malware, and hacking, by leveraging a multi-agent architecture to improve efficiency, scalability, and consistency. By utilizing state-of-the-art LLM models and agents, we demonstrate how organizations can adopt this methodology to enhance the accuracy and efficiency of CTI.
ISSN:2169-3536