Actionable threat intelligence for digital forensics readiness

被引:9
|
作者
Serketzis, Nikolaos [1 ]
Katos, Vasilios [2 ]
Ilioudis, Christos [3 ]
Baltatzis, Dimitrios [4 ]
Pangalos, George J. [1 ]
机构
[1] Aristotle Univ Thessaloniki, Sch Elect & Comp Engn, Thessaloniki, Greece
[2] Bournemouth Univ, Dept Comp, Poole, Dorset, England
[3] Technol Educ Inst Thessaloniki, Dept Informat Technol, Thessaloniki, Greece
[4] Int Hellen Univ, Thermi, Greece
关键词
Information security; Cybersecurity; Cyber threat intelligence; Digital forensic readiness; Digital forensics; Indicators of compromise;
D O I
10.1108/ICS-09-2018-0110
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Purpose The purpose of this paper is to formulate a novel model for enhancing the effectiveness of existing digital forensic readiness (DFR) schemes by leveraging the capabilities of cyber threat information sharing. Design/methodology/approach This paper uses a quantitative methodology to identify the most popular cyber threat intelligence (CTI) elements and introduces a lightweight approach to correlate those with potential forensic value, resulting in the quick and accurate triaging and identification of patterns of malicious activities. Findings While threat intelligence exchange steadily becomes a common practice for the prevention or detection of security incidents, the proposed approach highlights its usefulness for the digital forensics (DF) domain. Originality/value The proposed model can help organizations to improve their DFR posture, and thus minimize the time and cost of cybercrime incidents.
引用
收藏
页码:273 / 291
页数:19
相关论文
共 50 条
  • [1] Actionable Cyber Threat Intelligence for Automated Incident Response
    Leite, Cristoffer
    den Hartog, Jerry
    dos Santos, Daniel Ricardo
    Costante, Elisa
    [J]. SECURE IT SYSTEMS, NORDSEC 2022, 2022, 13700 : 368 - 385
  • [2] Explainable artificial intelligence for digital forensics
    Hall, Stuart W.
    Sakzad, Amin
    Choo, Kim-Kwang Raymond
    [J]. WILEY INTERDISCIPLINARY REVIEWS: FORENSIC SCIENCE, 2022, 4 (02):
  • [3] From Threat Data to Actionable Intelligence: An Exploratory Analysis of the Intelligence Cycle Implementation in Cyber Threat Intelligence Sharing Platforms
    Sauerwein, Clemens
    Fischer, Daniel
    Rubsamen, Milena
    Rosenberger, Guido
    Stelzer, Dirk
    Breu, Ruth
    [J]. ARES 2021: 16TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY, 2021,
  • [4] Decentralized Actionable Cyber Threat Intelligence for Networks and the Internet of Things
    Mena, Diego Mendez
    Yang, Baijian
    [J]. IOT, 2021, 2 (01): : 1 - 16
  • [5] TTPXHunter: Actionable Threat Intelligence Extraction as TTPs from Finished Cyber Threat Reports
    Rani, Nanda
    Saha, Bikash
    Maurya, Vikas
    Shukla, Sandeep Kumar
    [J]. Digital Threats: Research and Practice, 2024, 5 (04):
  • [6] Digital Forensics and Investigations Meet Artificial Intelligence
    Costantini, Stefania
    De Gasperis, Giovanni
    Olivieri, Raffaele
    [J]. ELECTRONIC PROCEEDINGS IN THEORETICAL COMPUTER SCIENCE, 2019, (306): : 355 - 357
  • [7] Cyber threat intelligence framework using advanced malware forensics
    Keim Y.
    Mohapatra A.K.
    [J]. International Journal of Information Technology, 2022, 14 (1) : 521 - 530
  • [8] Digital forensics and investigations meet artificial intelligence
    Stefania Costantini
    Giovanni De Gasperis
    Raffaele Olivieri
    [J]. Annals of Mathematics and Artificial Intelligence, 2019, 86 : 193 - 229
  • [9] Digital forensics and investigations meet artificial intelligence
    Costantini, Stefania
    De Gasperis, Giovanni
    Olivieri, Raffaele
    [J]. ANNALS OF MATHEMATICS AND ARTIFICIAL INTELLIGENCE, 2019, 86 (1-3) : 193 - 229
  • [10] Editorial for the Special Issue on Sustainable Cyber Forensics and Threat Intelligence
    Bianchi, Giuseppe
    Conti, Mauro
    Dargahi, Tooska
    Dehghantanha, Ali
    [J]. IEEE TRANSACTIONS ON SUSTAINABLE COMPUTING, 2021, 6 (02): : 182 - 183