From Threat Data to Actionable Intelligence: An Exploratory Analysis of the Intelligence Cycle Implementation in Cyber Threat Intelligence Sharing Platforms

被引:3
|
作者
Sauerwein, Clemens [1 ]
Fischer, Daniel [2 ]
Rubsamen, Milena [2 ]
Rosenberger, Guido [2 ]
Stelzer, Dirk [2 ]
Breu, Ruth [1 ]
机构
[1] Univ Innsbruck, Innsbruck, Austria
[2] Tech Univ Ilmenau, Ilmenau, Germany
关键词
Threat Intelligence; Platforms; Intelligence Cycle; Functions; Literature Study; Case Study;
D O I
10.1145/3465481.3470048
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In the last couple of years, organizations have demonstrated an increasing willingness to share data, information and intelligence regarding emerging threats to collectively protect against today's sophisticated cyber attacks. Accordingly, several vendors started to implement software solutions that facilitate this exchange and appear under the name cyber threat intelligence sharing platforms. However, recent investigations have shown that these platforms differ significantly in their functional scope and often only provide threat data instead of the promised actionable intelligence. Moreover, it is unclear to what extent the platforms implement the expected intelligence cycle processes. In order to close this gap, we investigate the state-of-the-art in scientific literature and analyze the functional scope of nine threat intelligence sharing platforms with respect to the intelligence cycle. Our study provides a comprehensive list of software functions that should be implemented by cyber threat intelligence sharing platforms in order to support the intelligence cycle to generate actionable threat intelligence.
引用
收藏
页数:9
相关论文
共 50 条
  • [1] Data Sanitisation and Redaction for Cyber Threat Intelligence Sharing Platforms
    Yucel, Cagatay
    Chalkias, Ioannis
    Mallis, Dimitrios
    Cetinkaya, Deniz
    Henriksen-Bulmer, Jane
    Cooper, Alice
    [J]. PROCEEDINGS OF THE 2021 IEEE INTERNATIONAL CONFERENCE ON CYBER SECURITY AND RESILIENCE (IEEE CSR), 2021, : 343 - 347
  • [2] Trust and Quality Computation for Cyber Threat Intelligence Sharing Platforms
    Mavzer, Kadir Burak
    Konieczna, Ewa
    Alves, Henrique
    Yucel, Cagatay
    Chalkias, Ioannis
    Mallis, Dimitrios
    Cetinkaya, Deniz
    Sanchez, Luis Angel Galindo
    [J]. PROCEEDINGS OF THE 2021 IEEE INTERNATIONAL CONFERENCE ON CYBER SECURITY AND RESILIENCE (IEEE CSR), 2021, : 360 - 365
  • [3] Cyber Threat Intelligence Model: An Evaluation of Taxonomies, Sharing Standards, and Ontologies within Cyber Threat Intelligence
    Mavroeidis, Vasileios
    Bromander, Siri
    [J]. 2017 EUROPEAN INTELLIGENCE AND SECURITY INFORMATICS CONFERENCE (EISIC), 2017, : 91 - 98
  • [4] Actionable Cyber Threat Intelligence for Automated Incident Response
    Leite, Cristoffer
    den Hartog, Jerry
    dos Santos, Daniel Ricardo
    Costante, Elisa
    [J]. SECURE IT SYSTEMS, NORDSEC 2022, 2022, 13700 : 368 - 385
  • [5] Risk Assessment of Sharing Cyber Threat Intelligence
    Albakri, Adham
    Boiten, Eerke
    Smith, Richard
    [J]. COMPUTER SECURITY, ESORICS 2020 INTERNATIONAL WORKSHOPS, 2020, 12580 : 92 - 113
  • [6] The Role of Cyber Threat Intelligence Sharing in the Metaverse
    Dunnett, Kealan
    Pal, Shantanu
    Jadidi, Zahra
    Jurdak, Raja
    [J]. IEEE Internet of Things Magazine, 2023, 6 (01): : 154 - 160
  • [7] Data Collection and Exploratory Analysis for Cyber Threat Intelligence Machine Learning Processes
    Wolf, Shaya
    Foster, Rita
    Mack, Andrea
    Priest, Zachary
    Haile, Jed
    [J]. 2022 9TH SWISS CONFERENCE ON DATA SCIENCE (SDS), 2022, : 7 - 12
  • [8] Dark-Web Cyber Threat Intelligence: From Data to Intelligence to Prediction
    Shakarian, Paulo
    [J]. INFORMATION, 2018, 9 (12):
  • [9] A success model for cyber threat intelligence management platforms
    Zibak, Adam
    Sauerwein, Clemens
    Simpson, Andrew
    [J]. COMPUTERS & SECURITY, 2021, 111
  • [10] Decentralized Actionable Cyber Threat Intelligence for Networks and the Internet of Things
    Mena, Diego Mendez
    Yang, Baijian
    [J]. IOT, 2021, 2 (01): : 1 - 16