Scalable object-relational modeling for synthesizing multi-format visual analytics of STIX-based cyber threat intelligence data

dc.contributor.authorKaya, Muhammed Onur
dc.contributor.authorDas, Resul
dc.date.accessioned2026-09-08T07:08:42Z
dc.date.issued2026
dc.departmentFırat Üniveristesi
dc.description.abstractThe observed increase in cyber threat intelligence data, the diversity of sources, and relational complexity make it difficult for analysts to directly assess and interpret threat profiles from raw Structured Threat Information Expression (STIX) packages. This study utilises an object-relational model to transform all object and relationship types into a single unified representation and reconstruct the same graph model across three different visualisation software packages (plotly, matplotlib, pyvis). The proposed analytical framework generates extended threat models by combining multiple STIX datasets through entity extraction, creating observable entities from each dataset, and completing relationships among them; thus mapping relationship types to the operational meanings of attacks and enabling more comprehensive risk prioritisation. The case study is based on a public OASIS STIX example package. The enriched graph is dominated by relationship types such as uses, indicates, pattern-refers-to, and attributed-to, and the highest risk scores are assigned to the nodes labelled “Privilege Escalation” and “Ugly Gorilla”. Scalability tests performed on 1000-node synthetic directed graphs revealed a processing time of 8.08 seconds, memory consumption of 124.3 MB, and a frame rate of 215.05 fps during interactive preview. These findings demonstrate that the proposed framework offers a unified and viable foundation for visual analysis, risk prioritisation, and scalable analytical reporting of STIX-based cyber threat intelligence. Copyright © 2026 Muhammed Onur Kaya et al., licensed to EAI. This is an open access article distributed under the terms of the CC BY-NC-SA 4.0, which permits copying, redistributing, remixing, transforming, and building upon the material in any medium so long as the original work is properly cited.
dc.description.sponsorshipTürkiye Bilimsel ve Teknolojik Araştırma Kurumu, TUBITAK -- Built Environment -- Edinburgh Napier University
dc.identifier.doi10.4108/eetinis.132.12774
dc.identifier.endpage17
dc.identifier.issn2410-0218
dc.identifier.issue2
dc.identifier.scopus2-s2.0-105044607669
dc.identifier.scopusqualityQ2
dc.identifier.startpage1
dc.identifier.urihttps://doi.org/10.4108/eetinis.132.12774
dc.identifier.urihttps://hdl.handle.net/11508/65000
dc.identifier.volume13
dc.indekslendigikaynakScopus
dc.language.isoen
dc.publisherEuropean Alliance for Innovation
dc.relation.ispartofEAI Endorsed Transactions on Industrial Networks and Intelligent Systems
dc.relation.publicationcategoryMakale - Uluslararası Hakemli Dergi - Kurum Öğretim Elemanı
dc.rightsinfo:eu-repo/semantics/openAccess
dc.snmzKA_Scopus_20250903
dc.subjectCyber Threat Intelligence
dc.subjectGraph Visualisation
dc.subjectScalability
dc.subjectStix
dc.subjectThreat Graph
dc.titleScalable object-relational modeling for synthesizing multi-format visual analytics of STIX-based cyber threat intelligence data
dc.typeArticle

Dosyalar