An automated dynamic quality assessment method for cyber threat intelligence

被引:0
|
作者
Yang, Libin [1 ]
Wang, Menghan [1 ]
Lou, Wei [2 ]
机构
[1] Northwestern Polytech Univ, Sch Cybersecur, Xian 710129, Shaanxi, Peoples R China
[2] Hong Kong Polytech Univ, Dept Comp, Kowloon, Hong Kong 999077, Peoples R China
关键词
Cyber threat intelligence; Feed trustworthiness; Content availability; Data quality assessment; ADVANCED PERSISTENT THREATS; DECISION;
D O I
10.1016/j.cose.2024.104079
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The emergence of cyber threat intelligence (CTI) is a promising approach for alleviating malicious activities. However, the effectiveness of CTIs is heavily dependent on their quality. Current literature develops the CTI quality assessment ontology mainly from the perspective of CTI source or content separately, regardless of their availability in practice. In this paper, we propose an automated CTI quality assessment method that synthesizes the trustworthiness of CTI sources and the availability of CTI contents. Specifically, we model the interactions of CTI feeds as a correlation graph and propose an iterative algorithm to well discriminate the feeds' trustworthiness. We elaborate a CTI content assessment together with a machine learning algorithm to automatically classify CTIs' availability from a set of content metrics. A comprehensive CTI quality assessment is proposed by jointly considering the feed trustworthiness and content availability. Extensive experimental results on real datasets demonstrate that our proposed method can quantitatively as well as effectively assess CTI quality.
引用
收藏
页数:12
相关论文
共 50 条
  • [1] A Comprehensive Dynamic Quality Assessment Method for Cyber Threat Intelligence
    Wang, Menghan
    Yang, Libin
    Lou, Wei
    52ND ANNUAL IEEE/IFIP INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS WORKSHOP VOLUME (DSN-W 2022), 2022, : 178 - 181
  • [2] Automated Generation of Cyber Threat Intelligence
    Kakumaru, Takahiro
    Takahashi, Wataru
    Katsuse, Riku
    Siracusano, Giuseppe
    Sanvito, Davide
    Bifulco, Roberto
    1600, NEC Mediaproducts (17): : 33 - 37
  • [3] On the Automated Assessment of Open-Source Cyber Threat Intelligence Sources
    Tundis, Andrea
    Ruppert, Samuel
    Muehlhaeuser, Max
    COMPUTATIONAL SCIENCE - ICCS 2020, PT II, 2020, 12138 : 453 - 467
  • [4] A Quality Evaluation Method of Cyber Threat Intelligence in User Perspective
    Li Qiang
    Jiang Zhengwei
    Yang Zeming
    Liu Baoxu
    Wang Xin
    Zhang Yunan
    2018 17TH IEEE INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (IEEE TRUSTCOM) / 12TH IEEE INTERNATIONAL CONFERENCE ON BIG DATA SCIENCE AND ENGINEERING (IEEE BIGDATASE), 2018, : 269 - 276
  • [5] Actionable Cyber Threat Intelligence for Automated Incident Response
    Leite, Cristoffer
    den Hartog, Jerry
    dos Santos, Daniel Ricardo
    Costante, Elisa
    SECURE IT SYSTEMS, NORDSEC 2022, 2022, 13700 : 368 - 385
  • [6] Towards the adoption of automated cyber threat intelligence information sharing with integrated risk assessment
    Rios, Valeria Valdes
    Zaidi, Fatiha
    Cavalli, Ana Rosa
    Rego, Angel
    19TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY, AND SECURITY, ARES 2024, 2024,
  • [7] Quality Evaluation of Cyber Threat Intelligence Feeds
    Griffioen, Harm
    Booij, Tim
    Doerr, Christian
    APPLIED CRYPTOGRAPHY AND NETWORK SECURITY (ACNS 2020), PT II, 2020, 12147 : 277 - 296
  • [8] Measuring and visualizing cyber threat intelligence quality
    Daniel Schlette
    Fabian Böhm
    Marco Caselli
    Günther Pernul
    International Journal of Information Security, 2021, 20 : 21 - 38
  • [9] Measuring and visualizing cyber threat intelligence quality
    Schlette, Daniel
    Boehm, Fabian
    Caselli, Marco
    Pernul, Guenther
    INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2021, 20 (01) : 21 - 38
  • [10] Risk Assessment of Sharing Cyber Threat Intelligence
    Albakri, Adham
    Boiten, Eerke
    Smith, Richard
    COMPUTER SECURITY, ESORICS 2020 INTERNATIONAL WORKSHOPS, 2020, 12580 : 92 - 113