A Comparative Study on Cyber Threat Intelligence: The Security Incident Response Perspective

被引:38
|
作者
Schlette, Daniel [1 ]
Caselli, Marco [2 ]
Pernul, Gunther [1 ]
机构
[1] Univ Regensburg, Chair Informat Syst, D-93053 Regensburg, Germany
[2] Siemens AG, Dept Cybersecur Technol, D-81739 Munich, Germany
来源
基金
欧盟地平线“2020”;
关键词
Cyber threat intelligence; incident response; standardization; playbook format; INFORMATION;
D O I
10.1109/COMST.2021.3117338
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Cyber Threat Intelligence (CTI) is threat information intended for security purposes. However, use for incident response demands standardization. This study examines the broader security incident response perspective. Introducing 18 core concepts, we assist efforts to establish and assess current standardization approaches. We further provide the reader with a detailed analysis of 6 incident response formats. While we synthesize structural elements, we point to characteristics and show format deficiencies. Also, we describe how core concepts can be used to determine a suitable format for a given use case. Our surveys' findings indicate a consistent focus on incident response actions within all formats. Besides, playbooks are used to represent procedures. Different use cases suggest that organizations can leverage and combine multiple formats. Finally, we discuss open research challenges to fully realize incident response potentials.
引用
收藏
页码:2525 / 2556
页数:32
相关论文
共 50 条
  • [1] Actionable Cyber Threat Intelligence for Automated Incident Response
    Leite, Cristoffer
    den Hartog, Jerry
    dos Santos, Daniel Ricardo
    Costante, Elisa
    SECURE IT SYSTEMS, NORDSEC 2022, 2022, 13700 : 368 - 385
  • [2] Malware incident response(IR) informed by cyber threat intelligence(CTI)
    Ying HE
    Ellis INGLUT
    Cunjin LUO
    Science China(Information Sciences), 2022, 65 (07) : 256 - 258
  • [3] Malware incident response (IR) informed by cyber threat intelligence (CTI)
    Ying He
    Ellis Inglut
    Cunjin Luo
    Science China Information Sciences, 2022, 65
  • [4] Malware incident response (IR) informed by cyber threat intelligence (CTI)
    He, Ying
    Inglut, Ellis
    Luo, Cunjin
    SCIENCE CHINA-INFORMATION SCIENCES, 2022, 65 (07)
  • [5] Cyber Threat Intelligence Framework for Incident Response in an Energy Cloud Platform
    Gong, Seonghyeon
    Lee, Changhoon
    ELECTRONICS, 2021, 10 (03) : 1 - 19
  • [6] Cyber Security Threat Intelligence Monitoring and Classification
    Wang, Bo-Xiang
    Chen, Jiann-Liang
    Yu, Chiao-Lin
    2021 IEEE INTERNATIONAL CONFERENCE ON INTELLIGENCE AND SECURITY INFORMATICS (ISI), 2021, : 70 - 72
  • [7] Cyber threat intelligence for critical infrastructure security
    Osliak, Oleksii
    Saracino, Andrea
    Martinelli, Fabio
    Mori, Paolo
    CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2023, 35 (23):
  • [8] Using Cyber Threat Intelligence in SDN Security
    Yurekten, Ozgur
    Demirci, Mehmet
    2017 INTERNATIONAL CONFERENCE ON COMPUTER SCIENCE AND ENGINEERING (UBMK), 2017, : 377 - 382
  • [9] Rationality constraints in cyber defense: Incident handling, attribution and cyber threat intelligence
    Hettema, Hinne
    COMPUTERS & SECURITY, 2021, 109
  • [10] Cyber Security Decision Making Informed by Cyber Threat Intelligence (CYDETI)
    Aliyu, Aliyu
    He, Ying
    Yevseyeva, Iryna
    Luo, Cunjin
    2020 IEEE CONFERENCE ON COMMUNICATIONS AND NETWORK SECURITY (CNS), 2020,