@article{4793, author = {Maleerat Sodanil}, title = {Graph-Based Threat Classification and Embedding Analysis of Cyber Threat Intelligence}, journal = {Journal of Information Security Research}, year = {2026}, volume = {17}, number = {3}, doi = {https://doi.org/10.6025/jisr/2026/17/3/138-154}, url = {https://www.dline.info/jisr/fulltext/v17n3/jisrv17n3_2.pdf}, abstract = {The rapid evolution of Advanced Persistent Threats (APTs) and sophisticated evasion techniques necessitates a shift from traditional signature-based detection to intelligence-driven cybersecurity strategies. However, conventional Indicator of Compromise (IOC) approaches fail to capture the complex, underlying semantic relationships among heterogeneous threat entities. To address these limitations, this study proposes a comprehensive, graph-based Cyber Threat Intelligence (CTI) analysis framework that transforms fragmented IOCs into a structured cybersecurity knowledge graph. Utilizing the CTIDataset, comprising approximately 640,000 structured records extracted from 612 security reports, we constructed a heterogeneous graph modeling complex interactions among malware, campaigns, threat actors, and infrastructure. We evaluated multiple graph embedding techniques, including Node2Vec, Graph Autoencoders (GAE), and Variational Graph Autoencoders (VGAE), alongside advanced machine learning classifiers such as XGBoost, Random Forest, and Graph Neural Networks (GCN, GraphSAGE, GAT). Experimental results demonstrate that XGBoost achieves superior classification performance (Accuracy: 0.85, ROC-AUC: 0.91) by effectively processing complex, hash heavy tabular features and engineered attributes. Meanwhile, VGAE yields the highest embedding quality, achieving optimal cluster separation for major threat families like Burning Umbrella and Turla, as validated by Silhouette scores, Davies Bouldin indices, and comprehensive UMAP visualizations. Ultimately, this research establishes a scalable and explainable foundation for automated threat attribution and campaign discovery, bridging the critical gap between isolated indicators and semantic attack behaviors to enhance proactive cyber defense capabilities in modern digital environments.}, }