An Enhanced Threat Intelligence Driven Hybrid Model for Information Security Risk Management

被引:0
|
作者
Amin, Habib E. L. [1 ,2 ,3 ]
Samhat, Abed Ellatif [1 ]
Chamoun, Maroun [2 ]
Oueidat, Lina [1 ]
Feghali, Antoine [3 ]
机构
[1] Lebanese Univ, Fac Engn, CRSI, Beirut, Lebanon
[2] St Joseph Univ Beirut, Ecole Super Ingenieurs Beyrouth, Beirut, Lebanon
[3] POTECH Labs, Riyadh, Saudi Arabia
关键词
Cyber Security; Information Security; Risk Management; Cyber Threat Intelligence; CYBERSECURITY;
D O I
10.1109/WoWMoM60985.2024.00013
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Risk management (RM) frameworks were established to identify, evaluate, and treat information security risks. The hybrid model for information security risk assessment (RA) [1] outlines a systematic process encompassing threat analysis while remaining agnostic to the source of threat information. It is limited in its adaptability to threat changes and dynamics. In an evolving landscape of changing threats, traditional RM methodologies face limitations in dynamic adaptation without considering Cyber Threat Intelligence (CTI) information. In this paper, we overview the established frameworks and methodologies for RM and CTI to identify gaps in the established RM frameworks. We propose a novel enhancement to the hybrid model by integrating CTI. This enhancement distinguishes our approach from other frameworks by facilitating the proactive inclusion of context-rich external threat data, leading to a more efficient RM process that effectively adapts to the ever-evolving cyber threat landscape.
引用
收藏
页码:5 / 12
页数:8
相关论文
共 50 条
  • [41] An Ontology-Based Security Risk Management Model for Information Systems
    Arogundade, Oluwasefunmi T.
    Abayomi-Alli, Adebayo
    Misra, Sanjay
    ARABIAN JOURNAL FOR SCIENCE AND ENGINEERING, 2020, 45 (08) : 6183 - 6198
  • [42] A New Evaluation Model for Information Security Risk Management of SCADA Systems
    Lin, Kuo-Sui
    2019 IEEE INTERNATIONAL CONFERENCE ON INDUSTRIAL CYBER PHYSICAL SYSTEMS (ICPS 2019), 2019, : 757 - 762
  • [43] Information security risk management model for mitigating the impact on SMEs in Peru
    Carnero Garay, Daniel Felipe
    Antonio, Marcos
    Ramos, Carbajal
    Armas-Aguirre, Jimmy
    Madrid Molina, Juan Manuel
    2020 15TH IBERIAN CONFERENCE ON INFORMATION SYSTEMS AND TECHNOLOGIES (CISTI'2020), 2020,
  • [44] An Ontology-Based Security Risk Management Model for Information Systems
    Oluwasefunmi T. Arogundade
    Adebayo Abayomi-Alli
    Sanjay Misra
    Arabian Journal for Science and Engineering, 2020, 45 : 6183 - 6198
  • [45] Ideological and Political Teaching Information Management based on Artificial Intelligence and Data Security Model
    Yan C.
    Computer-Aided Design and Applications, 2023, 20 (S12): : 261 - 282
  • [46] Artificial Intelligence Techniques for Information Security Risk Assessment
    Basallo, Y. A.
    Senti, V. E.
    Sanchez, N. M.
    IEEE LATIN AMERICA TRANSACTIONS, 2018, 16 (03) : 897 - 901
  • [47] Big Data Management System Security Threat Model
    Poltavtseva, M. A.
    Zegzhda, D. P.
    Kalinin, M. O.
    AUTOMATIC CONTROL AND COMPUTER SCIENCES, 2019, 53 (08) : 903 - 913
  • [48] Big Data Management System Security Threat Model
    M. A. Poltavtseva
    D. P. Zegzhda
    M. O. Kalinin
    Automatic Control and Computer Sciences, 2019, 53 : 903 - 913
  • [49] Including technical and security risks in the management of information systems: A programmatic risk management model
    Dillon, Robin L.
    Paté-Cornell, M. Elisabeth
    Systems Engineering, 2005, 8 (01) : 15 - 28
  • [50] Data-driven analytics for cyber-threat intelligence and information sharing
    Qamar, Sara
    Anwar, Zahid
    Rahman, Mohammad Ashiqur
    Al-Shaer, Ehab
    Chu, Bei-Tseng
    COMPUTERS & SECURITY, 2017, 67 : 35 - 58