RETINA: RAG-Enhanced Threat Intelligence Analysis for Comprehensive Cybersecurity
作者:Vividh Pandey, D. Ghosh, Kartik Arora, T. Naga Malleswari · 发表于:2025 International Conference on Smart & Sustainable Technology (INCSST) · 年份:2025 · DOI:10.1109/incsst64791.2025.11210358
Cyber threats are developing rapidly, making traditional security methods insufficient for investigation and detection in real time. Large Language Models (LLMs), vector databases, and Retrieval-Augmented Generation (RAG) are all combined together in the innovative cybersecurity architecture known as RETINA (RAG-Enhanced Threat Intelligence Analysis) to produce scalable, automated, and strategic threat evaluation. Unlike traditional rule-based threat detection, which follows a strict pattern, RETINA uses dynamic retrieval of historical information and real-time open-source intelligence (OSINT) data to generate structured reports and AI-powered risk evaluations. Our study evaluates RETINA in terms of its execution time, retrieval efficiency, capacity and accuracy. This approach showcases its utility in cybersecurity applications. Its capabilities will be enhanced and built upon by focusing on adaptive learning, and responsive and proactive threat detection. RETINA uses RAG and AI-driven intelligence to provide professionals with actionable real-time threat intelligence, providing a simple solution to today’s problems with cybersecurity. Our evaluative findings confirm RETINA’s accuracy (F1-score: 0.80, AUC-ROC-0.79) and efficiency (approximately four seconds average response time), thus being a valuable solution for SOC teams, threat hunters, and forensic analysts. Thus, next-generation cybersecurity threat intelligence, offering scalability, explainability, and automation, br...