🤖 AI Summary
This study addresses the challenge that highly fragmented cyber threat evidence impedes timely security decision-making. To overcome this, it proposes POLAR, a large language model-based framework that synthesizes disparate evidence into threat-centric assessments. The framework innovatively decouples overlapping incidents and correlates source evidence, while leveraging temporal exploitation signals to dynamically estimate near-term exploitation probabilities and generate constrained remediation strategies. Evaluated on real-world vulnerability datasets, the proposed method significantly enhances threat prioritization and mitigation retrieval efficiency. Furthermore, it produces verifiable intermediate assessment results, effectively translating fragmented intelligence into automated decision-making.
📝 Abstract
Cyber threat analysis increasingly depends on evidence distributed across vendor advisories, vulnerability databases, and threat intelligence sources. Turning these fragmented observations into timely decisions requires models to connect technical severity with evolving exploitation evidence and available defensive actions. We present POLAR, an LLM-powered framework for synthesizing real-world cyber evidence into threat-centric assessments for prioritization and mitigation. POLAR first disentangles overlapping incidents and grounds each threat in source-linked evidence. For prioritization, it infers severity metrics from cyber evidence and combines the resulting assessment with temporally ordered exploitation signals to estimate near-term exploitation likelihood. For mitigation, it links the synthesized threat data to authoritative remediation knowledge and organizes applicable actions according to threat urgency and operational constraints. We evaluate POLAR on real-world vulnerability evidence collected from public resources and compare it with multiple baselines. Across heterogeneous incidents and zero-day settings, POLAR improves threat ranking and mitigation retrieval while producing evidence-linked intermediate assessments that support analyst inspection. The results establish evidence synthesis as a practical foundation for LLM-based cyber decision support across related security tasks.