Hunting Observable Objects for Indication of Compromise

被引:0
|
作者
Sykosch, Arnold [1 ,2 ]
Ohm, Marc [1 ]
Meier, Michael [1 ,2 ]
机构
[1] Univ Bonn, Comp Sci 4, Bonn, NRW, Germany
[2] Fraunhofer FKIE, Cyber Secur, Bonn, NRW, Germany
关键词
Threat Intelligence; Indicator of Compromise; Intrusion Detection; SIGNATURES; BEHAVIOR;
D O I
10.1145/3230833.3233282
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Shared Threat Intelligence is often imperfect. Especially so called Indicator of Compromise might not be well constructed. This might either be the case if the threat only appeared recently and recordings do not allow for construction of high quality Indicators or the threat is only observed by sharing partners lesser capable to model the threat. However, intrusion detection based on imperfect intelligence yields low quality results. Within this paper we illustrate how one is able to overcome these shortcomings in data quality and is able to achieve solid intrusion detection. This is done by assigning individual weights to observables listed in a STIX (TM) report to express their significance for detection. For evaluation, an automatized toolchain was developed to mimic the Threat Intelligence sharing ecosystem from initial detection over reporting, sharing, and determining compromise by STIXTM-formated data. Multiple strategies to detect and attribute a specific threat are compared using this data, leading up to an approach yielding a F1-Score of 0.79.
引用
收藏
页数:8
相关论文
共 50 条
  • [1] Duck hunting and wetland conservation: Compromise or synergy?
    Bennett, J
    Whitten, S
    [J]. CANADIAN JOURNAL OF AGRICULTURAL ECONOMICS-REVUE CANADIENNE D AGROECONOMIE, 2003, 51 (02): : 161 - 173
  • [2] The semantic transfer: questions of objects and observable
    Varkonyi, Zsofia
    [J]. 4E CONGRES MONDIAL DE LINGUISTIQUE FRANCAISE, 2014, 8 : 1201 - 1215
  • [3] OBSERVABLE BLUESHIFTS NEAR COMPACT OBJECTS
    COHEN, JM
    STRUBLE, MF
    PECHENICK, KR
    KUHARETZ, B
    [J]. ASTROPHYSICS AND SPACE SCIENCE, 1982, 88 (02) : 307 - 312
  • [4] Polarization - Spectral indication of the objects
    Lutsenko, V., I
    Popov, I., V
    [J]. SIXTH INT KHARKOV SYMPOSIUM ON PHYSICS AND ENGINEERING OF MICROWAVES, MILLIMETER AND SUBMILLIMETER WAVES/WORKSHOP ON TERAHERTZ TECHNOLOGIES, VOLS 1 AND 2, 2007, : 461 - +
  • [5] Observable objects, observers and the integral created by them
    Karami, Mehdi
    Molaei, MohammadReza
    Asgari, Navid
    [J]. EUROPEAN PHYSICAL JOURNAL PLUS, 2016, 131 (08):
  • [6] Describing Digital Objects: A Tale of Compromise
    Colati, Jessica Branco
    Dean, Robin
    Maull, Keith
    [J]. CATALOGING & CLASSIFICATION QUARTERLY, 2009, 47 (3-4) : 326 - 369
  • [7] COMMENT ON OBSERVABLE BLUESHIFTS NEAR COMPACT OBJECTS
    LAKE, K
    [J]. ASTROPHYSICS AND SPACE SCIENCE, 1983, 97 (01) : 203 - 203
  • [8] Observable objects, observers and the integral created by them
    Mehdi Karami
    MohammadReza Molaei
    Navid Asgari
    [J]. The European Physical Journal Plus, 131
  • [9] VARIABLE DECELERATIONS AND THE NONSTRESS TEST - AN INDICATION OF CORD COMPROMISE
    OLEARY, JA
    ANDRINOPOULOS, GC
    GIORDANO, PC
    [J]. AMERICAN JOURNAL OF OBSTETRICS AND GYNECOLOGY, 1980, 137 (06) : 704 - 706
  • [10] Ultra-resolution and indication of objects
    Terentiev, Evgeni N.
    Terentiev, Nikolay E.
    [J]. PASSIVE MILLIMETER-WAVE IMAGING TECHNOLOGY IX, 2006, 6211