Cyber Threat Intelligence Frameworks for Converting Heterogeneous Threat Feeds into Actionable Quantitative Risk Intelligence: A Systematic Review

Authors

Joseph Adebayo Ojeniyi

Department of Cyber Security Science, Federal University of Technology, Minna (Nigeria)

Baha Catherine Maigida

Department of Cyber Security Science, Federal University of Technology, Minna (Nigeria)

Olusanjo Olugbemi Fasola

Department of Cyber Security Science, Federal University of Technology, Minna (Nigeria)

Grace Amina Onyeabor

Department of Data Science, Federal University of Technology, Minna (Nigeria)

Adam Muhammad Saliu

Department of Data Science, Federal University of Technology, Minna (Nigeria)

Fatima Binta Adamu

Department of Data Science, Federal University of Technology, Minna (Nigeria)

Article Information

DOI: 10.47772/IJRISS.2026.1013COM0021

Subject Category: Communication

Volume/Issue: 10/13 | Page No: 288-314

Publication Timeline

Submitted: 2026-04-30

Accepted: 2026-05-05

Published: 2026-05-29

Abstract

The scale, speed, and sophistication of cyber threats continue to grow, creating an urgent need for security frameworks that can convert heterogeneous threat feeds into actionable, quantitative risk intelligence. Existing approaches offer useful capabilities in isolation: some concentrate on Cyber Threat Intelligence (CTI) sharing and semantic reasoning, others on large-scale threat graph analytics or federated risk modelling, and others on automated policy-based response. However, the literature has not yet converged on a framework that can continuously ingest raw threat intelligence, correlate it with asset context, and produce dynamic, asset-specific cyber risk scores for timely mitigation. This paper presents a systematic literature review of frameworks that aim to bridge CTI to cyber risk assessment. Following PRISMA guidelines, 45 peer-reviewed articles published between 2019 and 2025 were selected from an initial collection of 380 papers. The review consolidates existing approaches, including graph-based threat intelligence platforms, ontology-based risk monitoring, federated learning for risk classification, and security-policy-controlled systems. Key findings reveal that while individual components exist such as threat entity reputation scoring (TITAN: macro-F1=0.89), mobile device risk classification (FedCRI: F1>99%), and semantic risk reasoning (ontology-based) no single framework integrates raw CTI ingestion, asset context correlation, continuous quantitative risk scoring, and automated policy response. Furthermore, only 11% of reviewed studies address CTI provenance and trust, and only 7% provide fully automated end-to-end pipelines. Based on these findings, a research agenda is proposed for advancing unified CTI-to-risk frameworks in enterprise environments. The review also highlights three important gaps: (1) lack of analysis of the real-time processing constraints and computational latency in CTI-to-risk pipelines, (2) limited use of emerging Generative AI techniques such as Large Language Models for unstructured threat intelligence processing, and (3) no standardized mathematical formulation for quantitative cyber risk scoring. These findings form the foundation for a research agenda towards the evolution of unified, real-time, AI-enhanced CTI-to-risk frameworks in the enterprise.

Keywords

Cyber Threat Intelligence, cyber risk assessment, quantitative risk scoring, asset-specific risk

Downloads

References

1. Abduljabbar, Z. A., Omollo Nyangaresi, V., Al Sibahee, M. A., Ghrabat, M. J. J., Ma, J., Qays Abduljaleel, I., & Aldarwish, A. J. Y. (2022). Session-Dependent Token-Based Payload Enciphering Scheme for Integrity Enhancements in Wireless Networks. Journal of Sensor and Actuator Networks, 11(3). https://doi.org/10.3390/jsan11030055 [Google Scholar] [Crossref]

2. Alahi, M. E. E., Sukkuea, A., Tina, F. W., Nag, A., Kurdthongmee, W., Suwannarat, K., & Mukhopadhyay, S. C. (2023). Integration of IoT-Enabled Technologies and Artificial Intelligence (AI) for Smart City Scenario: Recent Advancements and Future Trends. Sensors, 23(11). https://doi.org/10.3390/s23115206 [Google Scholar] [Crossref]

3. Amthor, P., Fischer, D., & Stelzer, D. (2026). Automated Cyber Threat Sensing and Responding : Integrating Threat Automated Cyber Threat Sensing and Responding : Integrating Threat Intelligence into Security-Policy-Controlled Systems. (April). https://doi.org/10.1145/3339252.3340509 [Google Scholar] [Crossref]

4. Asgharian Rezaei, A., Munoz, J., Jalili, M., & Khayyam, H. (2022). Vital Node Identification in Complex Networks Using a Machine Learning-Based Approach. SSRN Electronic Journal, 1–20. https://doi.org/10.2139/ssrn.4052361 [Google Scholar] [Crossref]

5. Awan, M., & Alam, A. (2025). Cybersecurity Threats and Defensive Strategies for Small and Medium Firms: A Systematic Mapping Study. Administrative Sciences, 15(12), 1–37. https://doi.org/10.3390/admsci15120481 [Google Scholar] [Crossref]

6. Chen, M., & Fortino, G. (2026). Big Data and Cognitive Computing: Five New Journal Sections Established. Big Data and Cognitive Computing, 10(1), 26. https://doi.org/10.3390/bdcc10010026 [Google Scholar] [Crossref]

7. Davoodi, L., & Mezei, J. (2024). A Large Language Model and Qualitative Comparative Analysis-Based Study of Trust in E-Commerce. Applied Sciences (Switzerland), 14(21). https://doi.org/10.3390/app142110069 [Google Scholar] [Crossref]

8. Elghadghad, A., Alzubi, A., & Iyiola, K. (2024). Out-of-Stock Prediction Model Using Buzzard Coney Hawk Optimization-Based LightGBM-Enabled Deep Temporal Convolutional Neural Network. Applied Sciences (Switzerland), 14(13). https://doi.org/10.3390/app14135906 [Google Scholar] [Crossref]

9. Elicio, A., Maleki, M., Brunetti, G., & Ciminelli, C. (2026). Efficient Nanoparticle Sorting Through an Optofluidic Waveguide Splitter for Early Cancer Diagnosis : A Numerical Study. 1–12. [Google Scholar] [Crossref]

10. Fereidooni, H., Dmitrienko, A., Rieger, P., Miettinen, M., Sadeghi, A. R., & Madlener, F. (2022). FedCRI: Federated Mobile Cyber-Risk Intelligence. 29th Annual Network and Distributed System Security Symposium, NDSS 2022. https://doi.org/10.14722/ndss.2022.23153 [Google Scholar] [Crossref]

11. Freitas, S. (2024). Web Scale Graph Mining for Cyber Threat Intelligence (Vol. 1, Number 1). Association for Computing Machinery. [Google Scholar] [Crossref]

12. Konys, A., & Nowak-Brzezińska, A. (2023). Knowledge Engineering and Data Mining. Electronics (Switzerland), 12(4), 10–12. https://doi.org/10.3390/electronics12040927 [Google Scholar] [Crossref]

13. Li, H., Jiang, J., Li, L., Liu, J., Li, C., & Yu, Z. (2025). A Symmetry-Driven Adaptive Dual-Subpopulation Tree – Seed Algorithm for Complex Optimization with Local Optima Avoidance and Convergence Acceleration. 1–Awan, M., & Alam, A. (2025). Cybersecurity Threats and Defensive Strategies for Small and Medium Firms: A Systematic Mapping Study. Administrative Sciences, 15(12), 1–37. https://doi.org/10.3390/admsci15120481 [Google Scholar] [Crossref]

14. Ma, Z., Zhang, R., & Gao, L. (2025). Detection Model for 5G Core PFCP DDoS Attacks Based on Sin-Cos-bIAVOA. Algorithms, 18(7), 1–23. https://doi.org/10.3390/a18070449 [Google Scholar] [Crossref]

15. Merah, Y., & Kenaza, T. (2026). Ontology-based Cyber Risk Monitoring Using Cyber Threat Intelligence. (April). https://doi.org/10.1145/3465481.3470024 [Google Scholar] [Crossref]

16. Optimization, S. (2020). 2019 Index IEEE Transactions on Dependable and Secure Computing Vol. 16. IEEE Transactions on Dependable and Secure Computing, 17(1), 1–14. https://doi.org/10.1109/tdsc.2019.2957960 [Google Scholar] [Crossref]

17. Ortega-Calvo, A. S., Morcillo-Jimenez, R., Fernandez-Basso, C., Gutiérrez-Batista, K., Vila, M. A., & Martin-Bautista, M. J. (2023). AIMDP: An Artificial Intelligence Modern Data Platform. Use case for Spanish national health service data silo. Future Generation Computer Systems, 143, 248–264. https://doi.org/10.1016/j.future.2023.02.002 [Google Scholar] [Crossref]

18. Santoso, H. A., Fandhi Safsalta, B., Febrianto, N., Wilujeng Saraswati, G., & Haw, S. C. (2024). Comparative analysis of convolutional neural network and DenseNet121 transfer learning in agriculture focusing on crop leaf disease identification. Applied Computing and Informatics. https://doi.org/10.1108/ACI-03-2024-0132 [Google Scholar] [Crossref]

19. Shen, X., Buford, J., Yu, H., & Akon, M. (2010). Handbook of peer-to-peer networking. In Handbook of Peer-to-Peer Networking. https://doi.org/10.1007/978-0-387-09751-0 [Google Scholar] [Crossref]

20. Shen, X., Buford, J., Yu, H., & Akon, M. (2010). Handbook of peer-to-peer networking. In Handbook of Peer-to-Peer Networking. https://doi.org/10.1007/978-0-387-09751-0 [Google Scholar] [Crossref]

21. Silva, I. F. S. da, Silva, A. C., Paiva, A. C. de, Gattass, M., & Cunha, A. M. (2024). A Multi-Stage Automatic Method Based on a Combination of Fully Convolutional Networks for Cardiac Segmentation in Short-Axis MRI. Applied Sciences (Switzerland), 14(16). https://doi.org/10.3390/app14167352 [Google Scholar] [Crossref]

22. Teich, M. C., Escobari, B., & Rehbein, M. (2026). Utilizing large language models to construct a dataset of Württemberg’s 19th-century fauna from historical records. Plos One, 21(3 March), 1–18. https://doi.org/10.1371/journal.pone.0344181 [Google Scholar] [Crossref]

23. Wang, J., Zhang, Z., & Yue, S. (2025). A Validity Index for Clustering Evaluation by Grid Structures. Mathematics, 13(6). https://doi.org/10.3390/math13061017 [Google Scholar] [Crossref]

24. Zhang, H., Li, D., & Nie, X. (2026). Mitigating Execution Hallucinations and Computational Inflation in Agentic RAG via Strict Protocol Boundaries. 1–15. [Google Scholar] [Crossref]

Metrics

Views & Downloads

Similar Articles