Publication: Using Large Language Models for Cyber Threat News Prioritization
3
0
Issued Date
2025-01-01
Resource Type
Scopus ID
2-s2.0-105031080823
Journal Title
Proceedings 9th International Conference on Information Technology Incit 2025
Start Page
448
End Page
455
Rights Holder(s)
SCOPUS
Bibliographic Citation
Proceedings 9th International Conference on Information Technology Incit 2025 (2025) , 448-455
Suggested Citation
Lengwehasatit K., Pisawong A., Thewsuwan S. Using Large Language Models for Cyber Threat News Prioritization. Proceedings 9th International Conference on Information Technology Incit 2025 (2025) , 448-455. 455. doi:10.1109/InCIT66780.2025.11276009 Retrieved from: https://hdl.handle.net/20.500.14740/55263
Author(s)
Author's Affiliation
Corresponding Author(s)
Other Contributor(s)
Abstract
Organizations adopting a 'collect-all' strategy for cyber threat intelligence (CTI) often face overwhelming volumes of cybersecurity news, leading to information overload and reduced operational efficiency. This paper investigates the use of Large Language Models (LLMs) to support cyber threat news prioritization in the context of the Thai banking sector. A dataset of 375 cybersecurity news articles was collected and labeled using LLM-based prompting at both coarse-grained (0-2) and fine-grained (1-10) relevance levels. Results show that LLMs can provide consistent relevance judgments when carefully prompted, but inconsistencies remain in borderline cases. To explain and validate LLM decisions, we conducted experiments with text-based classification using TF-IDF and Random Forest, achieving 72% accuracy, and keyword-based classification with logistic regression, which yielded lower accuracy but offered interpretability through risk-associated keywords. The findings suggest that while LLMs are useful for augmenting CTI workflows, they should be combined with traditional machine learning and human oversight to ensure reliability.
