Practical Cyber Threat Intelligence in the UK Energy Sector

被引:0
作者
Paice, Alan [1 ]
McKeown, Sean [2 ]
机构
[1] EDF, London, England
[2] Edinburgh Napier Univ, Edinburgh, Midlothian, Scotland
来源
PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON CYBERSECURITY, SITUATIONAL AWARENESS AND SOCIAL MEDIA, CYBER SCIENCE 2022 | 2023年
关键词
Cyber Threat Intelligence; CTI; Information Sharing; Cybersecurity; Situational awareness;
D O I
10.1007/978-981-19-6414-5_1
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The UK energy sector is a prime target for cyber-attacks by foreign states, criminals, `hacktivist' groups, and terrorists. As Critical National Infrastructure (CNI), the industry needs to understand the threats it faces to mitigate risks and make efficient use of limited resources. Cyber Threat Intelligence (CTI) sharing is one means of achieving this, by leveraging sector-wide knowledge to combat ongoing mutual threats. However, being unable to segregate intelligence or to control what is disseminated to which parties, and by which means, has impeded industry cooperation thus far. The purpose of this study is to investigate the barriers to sharing and to add to the body of knowledge of CTI in the UK energy sector, while providing some level of assurance that existing tooling is fit-for-purpose. We achieve these aims by conducting a multivocal literature review and by experimentation using a simulated Malware Information Sharing Platform (MISP) community in a virtual environment. This work demonstrates that trust can be placed in the open-source MISP platform, with the caveat that the sharing models and tooling limitations are understood, while also taking care to create appropriate deployment taxonomies and sharing rules. It is hoped that some of the identified barriers are partially alleviated, helping to lay the foundations for a UK Energy sector CTI sharing community.
引用
收藏
页码:3 / 23
页数:21
相关论文
共 44 条
[1]  
Abu Md Sahrom, 2018, Indones. J. Electr. Eng. Comput. Sci., V10, P371, DOI 10.11591/ijeecs.v10.i1.pp371-379
[2]  
Al-Ibrahim O., 2017, Beyond free riding: Quality of indicators for assessing participation in information sharing for threat intelligence, P1, DOI DOI 10.1145/1235
[3]  
ANOMALI, 2019, DEF GUID SHAR THREAT
[4]  
[Anonymous], 2018, 2018 IEEE INT C INTE, DOI [10.1109/Cybermatics2018.2018.00240, DOI 10.1109/CYBERMATICS2018.2018.00240]
[5]  
[Anonymous], 2020, TRAFF LIGHT PROT TLP
[6]  
[Anonymous], 2017, Cyber Security in the Energy Sector-Recommendations for the European Commission on a European Strategic Framework and Potential Future Legislative Acts for the Energy Sector, P64
[7]  
Bakis B.J., 2017, BUILD NAT CYB INF SH
[8]  
Bauer S, 2020, PROCEEDINGS OF THE 53RD ANNUAL HAWAII INTERNATIONAL CONFERENCE ON SYSTEM SCIENCES, P1947
[9]  
Borden R.M., 2018, THREAT INF SHAR GDPR
[10]   Threat Intelligence Sharing Community: A countermeasure against Advanced Persistent Threat [J].
Chandel, Sonali ;
Yan, Mengdi ;
Chen, Shaojun ;
Jiang, Huan ;
Ni, Tian-Yi .
2019 2ND IEEE CONFERENCE ON MULTIMEDIA INFORMATION PROCESSING AND RETRIEVAL (MIPR 2019), 2019, :353-359