Explainable AI for Security Operations : Improving Cyber Threat Intelligence Reporting and Visibility Across African Organizations
Blessing N. Ezeobioha
Abstract
Cyber threat intelligence (CTI) becomes useful only when incidents are reported early, normalized into structured knowledge, and shared in a form that defenders can act upon. Many global CTI systems assume that incident evidence is already available as indicators, reports, or machine-readable objects. In African security operations, however, analysts often face a more basic upstream problem: incidents may be observed, reported informally, or visible on breach monitoring platforms and social media, yet they do not consistently become structured public or sector-level intelligence. This makes monthly TI reporting difficult and weakens regional visibility in global CTI ecosystems. The camera-ready version strengthens the accepted paper by adding practitioner-anchored observations from African security operations, including alleged dark-web exposure claims, cloned public-service portals, financial-sector phishing, payment-platform impersonation, and electricity-utility themed fraud lures. These cases are treated as sanitized reporting-gap observations rather than independently verified public breach claims. The paper proposes a hybrid explainable AI framework that combines rule-guided extraction, lightweight trainable classification, evidence-span tracing, analyst verification, and Privacy-aware STIX-style reporting. To test feasibility, ten analyst-realistic incident narratives were used, including practitioner-informed Nigerian and African SOC scenarios. In a single-analyst feasibility evaluation, the prototype achieved a macro field-extraction accuracy of 0.80 across sector, threat type, indicator, tactic/technique, and privacy sensitivity labels. The failures occurred mainly in higher-level TTP and privacy classification, which supports the need for human verification rather than black-box automation. The paper contributes a regionally grounded CTI reporting problem formulation, an improved hybrid XAI architecture, and a practical validation pathway for African SOCs, CSIRTs, and sectoral information-sharing communities.
Keywords: Cyber threat intelligence, Explainable AI, Security operations, Africa, Threat reporting, SOC