About | Contact Us | Register | Login
ProceedingsSeriesJournalsSearchEAI
inis 26(2):

Research Article

Scalable object-relational modeling for synthesizing multi-format visual analytics of STIX-based cyber threat intelligence data

Download24 downloads
Cite
BibTeX Plain Text
  • @ARTICLE{10.4108/eetinis.132.12774,
        author={Muhammed Onur Kaya and Resul Das},
        title={Scalable object-relational modeling for synthesizing multi-format visual analytics of STIX-based cyber threat intelligence data},
        journal={EAI Endorsed Transactions on Industrial Networks and Intelligent Systems},
        volume={13},
        number={2},
        publisher={EAI},
        journal_a={INIS},
        year={2026},
        month={6},
        keywords={STIX, Cyber Threat Intelligence, Graph Visualisation, Threat Graph, Scalability},
        doi={10.4108/eetinis.132.12774}
    }
    
  • Muhammed Onur Kaya
    Resul Das
    Year: 2026
    Scalable object-relational modeling for synthesizing multi-format visual analytics of STIX-based cyber threat intelligence data
    INIS
    EAI
    DOI: 10.4108/eetinis.132.12774
Muhammed Onur Kaya1, Resul Das1,2,*
  • 1: Fırat University
  • 2: Edinburgh Napier University
*Contact email: resuldas@gmail.com

Abstract

The observed increase in cyber threat intelligence data, the diversity of sources, and relational complexity make it difficult for analysts to directly assess and interpret threat profiles from raw Structured Threat Information Expression (STIX) packages. This study utilises an object-relational model to transform all object and relationship types into a single unified representation and reconstruct the same graph model across three different visualisation software packages (plotly, matplotlib, pyvis). The proposed analytical framework generates extended threat models by combining multiple STIX datasets through entity extraction, creating observable entities from each dataset, and completing relationships among them; thus mapping relationship types to the operational meanings of attacks and enabling more comprehensive risk prioritisation. The case study is based on a public OASIS STIX example package. The enriched graph is dominated by relationship types such as uses, indicates, pattern-refers-to, and attributed-to, and the highest risk scores are assigned to the nodes labelled “Privilege Escalation” and “Ugly Gorilla”. Scalability tests performed on 1000-node synthetic directed graphs revealed a processing time of 8.08 seconds, memory consumption of 124.3 MB, and a frame rate of 215.05 fps during interactive preview. These findings demonstrate that the proposed framework offers a unified and viable foundation for visual analysis, risk prioritisation, and scalable analytical reporting of STIX-based cyber threat intelligence.

Keywords
STIX, Cyber Threat Intelligence, Graph Visualisation, Threat Graph, Scalability
Received
2026-04-24
Accepted
2026-06-15
Published
2026-06-18
Publisher
EAI
http://dx.doi.org/10.4108/eetinis.132.12774

Copyright © 2026 Muhammed Onur Kaya et al., licensed to EAI. This is an open access article distributed under the terms of the CC BY-NC-SA 4.0, which permits copying, redistributing, remixing, transforming, and building upon the material in any medium so long as the original work is properly cited.

EBSCOProQuestDBLPDOAJPortico
EAI Logo

About EAI

  • Who We Are
  • Leadership
  • Research Areas
  • Partners
  • Media Center
  • Cookie Preferences

Community

  • Membership
  • Conference
  • Recognition
  • Sponsor Us

Publish with EAI

  • Publishing
  • Journals
  • Proceedings
  • Books
  • EUDL