📄 Sciences Methods and Technologies
International Journal (SciMeTech)

Volume 2 · Issue 1 · 2026
ISSN: 3085-5284
Explainable AI for Security Operations : Improving Cyber Threat Intelligence Reporting and Visibility Across African Organizations
Blessing N. Ezeobioha
Pages 207–215 · Mina Open University
Abstract
Cyber threat intelligence (CTI) becomes useful only when incidents are reported early, normalized into structured knowledge, and shared in a form that defenders can act upon. Many global CTI systems assume that incident evidence is already available as indicators, reports, or machine-readable objects. In African security operations, however, analysts often face a more basic upstream problem: incidents may be observed, reported informally, or visible on breach monitoring platforms and social media, yet they do not consistently become structured public or sector-level intelligence. This makes monthly TI reporting difficult and weakens regional visibility in global CTI ecosystems. The camera-ready version strengthens the accepted paper by adding practitioner-anchored observations from African security operations, including alleged dark-web exposure claims, cloned public-service portals, financial-sector phishing, payment-platform impersonation, and electricity-utility themed fraud lures. These cases are treated as sanitized reporting-gap observations rather than independently verified public breach claims. The paper proposes a hybrid explainable AI framework that combines rule-guided extraction, lightweight trainable classification, evidence-span tracing, analyst verification, and Privacy-aware STIX-style reporting. To test feasibility, ten analyst-realistic incident narratives were used, including practitioner-informed Nigerian and African SOC scenarios. In a single-analyst feasibility evaluation, the prototype achieved a macro field-extraction accuracy of 0.80 across sector, threat type, indicator, tactic/technique, and privacy sensitivity labels. The failures occurred mainly in higher-level TTP and privacy classification, which supports the need for human verification rather than black-box automation. The paper contributes a regionally grounded CTI reporting problem formulation, an improved hybrid XAI architecture, and a practical validation pathway for African SOCs, CSIRTs, and sectoral information-sharing communities.
Keywords: Cyber threat intelligence, Explainable AI, Security operations, Africa, Threat reporting, SOC

References

  1. African Union, African Union Convention on Cyber Security and Personal Data Protection (Malabo Convention), 2014. Available: https://au.int/en/treaties/african-union-convention-cybersecurity-and-personal-data-protection
  2. S. Barnum, Standardizing Cyber Threat Intelligence Information with the Structured Threat Information eXpression (STIX), MITRE Corporation, 2014. Available: https://stixproject.github.io/
  3. Breach.house, Breach intelligence search platform, 2026. Accessed: Apr. 29, 2026. Available: https://breach.house/
  4. E. M. Hutchins, M. J. Cloppert, and R. M. Amin, "Intelligence-driven computer network defense informed by analysis of adversary campaigns and intrusion kill chains," in Leading Issues in Information Warfare & Security Research, vol. 1, pp. 80–106, 2011.
  5. INTERPOL, African Cyberthreat Assessment Report, 2021. Available: https://www.interpol.int/
  6. INTERPOL, African Cyberthreat Assessment Report, 2024. Available: https://www.interpol.int/
  7. C. Johnson, L. Badger, D. Waltermire, J. Snyder, and C. Skorupka, Guide to Cyber Threat Information Sharing (NIST SP 800-150), National Institute of Standards and Technology, 2016. doi: 10.6028/NIST.SP.800-150
  8. S. M. Lundberg and S.-I. Lee, "A unified approach to interpreting model predictions," in Proc. 31st Int. Conf. Neural Information Processing Systems (NIPS), pp. 4765–4774, 2017.
  9. V. Mavroeidis and S. Bromander, "Cyber threat intelligence model: An evaluation of taxonomies, sharing standards, and ontologies within cyber threat intelligence," in Proc. European Intelligence and Security Informatics Conf. (EISIC), pp. 91–98, 2017. doi: 10.1109/EISIC.2017.20
  10. MITRE, MITRE ATT&CK: Design and philosophy, 2024. Available: https://attack.mitre.org/
  11. M. A. Nainna and J. Bass, "Cyber Threat Intelligence Sharing in Nigeria," Communications of the IIMA, vol. 22, no. 1, 2024. Available: https://scholarworks.lib.csusb.edu/ciima/vol22/iss1/1/
  12. OASIS, STIX Version 2.1 and TAXII Version 2.1 Specifications, 2021. Available: https://oasisopen.github.io/ctidocumentation/
  13. M. T. Ribeiro, S. Singh, and C. Guestrin, "Why should I trust you? Explaining the predictions of any classifier," in Proc. ACM SIGKDD Int. Conf. Knowledge Discovery and Data Mining, pp. 1135–1144, 2016. doi: 10.1145/2939672.2939778
  14. A. I. Sani and I. Yakub, "Evaluating Nigeria's readiness against state-sponsored cyber attacks: A comparative study of cybersecurity policies, incident response, and international cooperation," Journal of Computational Analysis and Applications, 2025.
  15. F. Skopik, G. Settanni, and R. Fiedler, "A problem shared is a problem halved: A survey on the dimensions of collective cyber defense through security information sharing," Computers & Security, vol. 60, pp. 154–176, 2016. doi: 10.1016/j.cose.2016.04.003
  16. R. Sommer and V. Paxson, "Outside the closed world: On using machine learning for network intrusion detection," in Proc. IEEE Symposium on Security and Privacy, pp. 305–316, 2010. doi: 10.1109/SP.2010.25
  17. W. Tounsi and H. Rais, "A survey on technical threat intelligence in the age of sophisticated cyber attacks," Computers & Security, vol. 72, pp. 212–233, 2018. doi: 10.1016/j.cose.2017.09.001
  18. C. Wagner, A. Dulaunoy, G. Wagener, and A. Iklody, "MISP: The design and implementation of a collaborative threat intelligence sharing platform," in Proc. ACM Workshop on Information Sharing and Collaborative Security, pp. 49–56, 2016. doi: 10.1145/2994539.2994542
  19. FIRST, Traffic Light Protocol (TLP) Definitions and Usage Guidance, 2020. Available: https://www.first.org/tlp/
  20. National Information Technology Development Agency (NITDA), Nigeria Computer Emergency Readiness and Response Team advisories, 2022. Available: https://cert.gov.ng/
  21. Nigeria Data Protection Commission (NDPC), Nigeria Data Protection Act, 2023. Available: https://ndpc.gov.ng/