An automated dynamic quality assessment method for cyber threat intelligence

被引:0
作者
Yang, Libin [1 ]
Wang, Menghan [1 ]
Lou, Wei [2 ]
机构
[1] Northwestern Polytech Univ, Sch Cybersecur, Xian 710129, Shaanxi, Peoples R China
[2] Hong Kong Polytech Univ, Dept Comp, Kowloon, Hong Kong 999077, Peoples R China
关键词
Cyber threat intelligence; Feed trustworthiness; Content availability; Data quality assessment; ADVANCED PERSISTENT THREATS; DECISION;
D O I
10.1016/j.cose.2024.104079
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The emergence of cyber threat intelligence (CTI) is a promising approach for alleviating malicious activities. However, the effectiveness of CTIs is heavily dependent on their quality. Current literature develops the CTI quality assessment ontology mainly from the perspective of CTI source or content separately, regardless of their availability in practice. In this paper, we propose an automated CTI quality assessment method that synthesizes the trustworthiness of CTI sources and the availability of CTI contents. Specifically, we model the interactions of CTI feeds as a correlation graph and propose an iterative algorithm to well discriminate the feeds' trustworthiness. We elaborate a CTI content assessment together with a machine learning algorithm to automatically classify CTIs' availability from a set of content metrics. A comprehensive CTI quality assessment is proposed by jointly considering the feed trustworthiness and content availability. Extensive experimental results on real datasets demonstrate that our proposed method can quantitatively as well as effectively assess CTI quality.
引用
收藏
页数:12
相关论文
共 50 条
[1]   A Comprehensive Dynamic Quality Assessment Method for Cyber Threat Intelligence [J].
Wang, Menghan ;
Yang, Libin ;
Lou, Wei .
52ND ANNUAL IEEE/IFIP INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS WORKSHOP VOLUME (DSN-W 2022), 2022, :178-181
[2]   Towards the adoption of automated cyber threat intelligence information sharing with integrated risk assessment [J].
Rios, Valeria Valdes ;
Zaidi, Fatiha ;
Cavalli, Ana Rosa ;
Rego, Angel .
19TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY, AND SECURITY, ARES 2024, 2024,
[3]   Quality Evaluation of Cyber Threat Intelligence Feeds [J].
Griffioen, Harm ;
Booij, Tim ;
Doerr, Christian .
APPLIED CRYPTOGRAPHY AND NETWORK SECURITY (ACNS 2020), PT II, 2020, 12147 :277-296
[4]   Measuring and visualizing cyber threat intelligence quality [J].
Daniel Schlette ;
Fabian Böhm ;
Marco Caselli ;
Günther Pernul .
International Journal of Information Security, 2021, 20 :21-38
[5]   Measuring and visualizing cyber threat intelligence quality [J].
Schlette, Daniel ;
Boehm, Fabian ;
Caselli, Marco ;
Pernul, Guenther .
INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2021, 20 (01) :21-38
[6]   Risk Assessment of Sharing Cyber Threat Intelligence [J].
Albakri, Adham ;
Boiten, Eerke ;
Smith, Richard .
COMPUTER SECURITY, ESORICS 2020 INTERNATIONAL WORKSHOPS, 2020, 12580 :92-113
[7]   Weighted quality criteria for cyber threat intelligence: assessment and prioritisation in the MISP data modelWeighted quality criteria for cyber threat intelligence...D. Chatziamanetoglou, K. Rantos [J].
Dimitrios Chatziamanetoglou ;
Konstantinos Rantos .
International Journal of Information Security, 2025, 24 (4)
[8]   Automated Cyber Threat Intelligence Generation from Honeypot Data [J].
Sanjeev, Kumar ;
Janet, B. ;
Eswari, R. .
INVENTIVE COMMUNICATION AND COMPUTATIONAL TECHNOLOGIES, ICICCT 2019, 2020, 89 :591-598
[9]   A Business Process Oriented Dynamic Cyber Threat Intelligence Model [J].
Xu, Yuanchen ;
Yang, Yingjie ;
He, Ying .
2019 IEEE SMARTWORLD, UBIQUITOUS INTELLIGENCE & COMPUTING, ADVANCED & TRUSTED COMPUTING, SCALABLE COMPUTING & COMMUNICATIONS, CLOUD & BIG DATA COMPUTING, INTERNET OF PEOPLE AND SMART CITY INNOVATION (SMARTWORLD/SCALCOM/UIC/ATC/CBDCOM/IOP/SCI 2019), 2019, :648-653
[10]   Quality assessment of cyber threat intelligence knowledge graph based on adaptive joining of embedding model [J].
Chen, Bin ;
Li, Hongyi ;
Zhao, Di ;
Yang, Yitang ;
Pan, Chengwei .
COMPLEX & INTELLIGENT SYSTEMS, 2025, 11 (01)