Towards the adoption of automated cyber threat intelligence information sharing with integrated risk assessment

被引:0
作者
Rios, Valeria Valdes [1 ,2 ]
Zaidi, Fatiha [3 ]
Cavalli, Ana Rosa [1 ,4 ]
Rego, Angel [5 ]
机构
[1] Montimage EURL, Paris, France
[2] Univ Paris Saclay, Gif Sur Yvette, France
[3] Univ Paris Saclay, CNRS, ENS Paris Saclay, Lab Methodes Formelles, Gif Sur Yvette, France
[4] Telecom SudParis, Inst Polytech, Paris, France
[5] Basque Res & Technol Alliance BRTA, Tecnalia, Derio, Spain
来源
19TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY, AND SECURITY, ARES 2024 | 2024年
关键词
Cyber Threat Intelligence; Information Sharing; Cybersecurity; Cyber-Physical Systems; Automation; Standardized Threat Intelligence;
D O I
10.1145/3664476.3670444
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In the domain of cybersecurity, effective threat intelligence and information sharing are critical operations for ensuring appropriate and timely response against threats, but limited in automation, standardization, and ease of use in current platforms. This paper introduces a Cyber Threat Intelligence (CTI) Information Sharing platform, designed for critical infrastructures and cyber-physical systems. Our platform integrates existing cybersecurity tools and leverages digital twin technology, enhancing threat analysis and mitigation capabilities. It features an automated process for disseminating standardized and structured intelligence, utilizing the Malware Information Sharing Platform (MISP) for effective dissemination. A significant enhancement is the integration of risk assessment tools, which enriches the shared intelligence with detailed risk information, supporting an informed decision-making. The platform encompasses a user-friendly dashboard and a robust backend, streamlining the threat intelligence cycle and transforming raw data coming from diverse sources into actionable insights. Overall the CTI4BC platform presents a solution to overcome challenges in the CTI sharing, contributing to a more resilient cybersecurity domain.
引用
收藏
页数:9
相关论文
共 8 条
[1]   Cyber Meets Control: A Novel Federated Approach for Resilient CPS Leveraging Real Cyber Threat Intelligence [J].
Bou-Harb, Elias ;
Lucia, Walter ;
Forti, Nicola ;
Weerakkody, Sean ;
Ghani, Nasir ;
Sinopoli, Bruno .
IEEE COMMUNICATIONS MAGAZINE, 2017, 55 (05) :198-204
[2]   The Quest for the Appropriate Cyber-threat Intelligence Sharing Platform [J].
Chantzios, Thanasis ;
Koloveas, Paris ;
Skiadopoulos, Spiros ;
Kolokotronis, Nikos ;
Tryfonopoulos, Christos ;
Bilali, Vasiliki-Georgia ;
Kavallieros, Dimitris .
PROCEEDINGS OF THE 8TH INTERNATIONAL CONFERENCE ON DATA SCIENCE, TECHNOLOGY AND APPLICATIONS (DATA), 2019, :369-376
[3]  
Django Software Foundation, 2024, Django Documentation.
[4]  
Facebook Inc., 2024, React-A JavaScript library for building user interfaces.
[5]  
MISP Project, 2024, MISP-Malware Information Sharing Platform and Threat Sharing.
[6]   A Reference Model for Cyber Threat Intelligence (CTI) Systems [J].
Sakellariou, Georgios ;
Fouliras, Panagiotis ;
Mavridis, Ioannis ;
Sarigiannidis, Panagiotis .
ELECTRONICS, 2022, 11 (09)
[7]  
The Apache Software Foundation, 2024, Apache Kafka
[8]   MISP - The Design and Implementation of a Collaborative Threat Intelligence Sharing Platform [J].
Wagner, Cynthia ;
Dulaunoy, Alexandre ;
Wagener, Gerard ;
Iklody, Andras .
WISCS'16: PROCEEDINGS OF THE 2016 ACM WORKSHOP ON INFORMATION SHARING AND COLLABORATIVE SECURITY, 2016, :49-56