A Methodology to Evaluate Standards and Platforms within Cyber Threat Intelligence

被引:33
|
作者
de Melo e Silva, Alessandra [1 ]
Costa Gondim, Joao Jose [1 ,2 ]
Albuquerque, Robson de Oliveira [1 ,3 ]
Garcia Villalba, Luis Javier [3 ]
机构
[1] Univ Brasilia, Dept Elect Engn, Post Grad Elect Engn PPEE, BR-70910900 Brasilia, DF, Brazil
[2] Univ Brasilia UnB, Dept Comp Sci CIC, BR-70910900 Brasilia, DF, Brazil
[3] Univ Complutense Madrid UCM, Fac Comp Sci & Engn, Dept Software Engn & Artificial Intelligence DISI, Grp Anal Secur & Syst GASS, Off 431,Calle Prof Jose Garcia Santesmases 9, Madrid 28040, Spain
来源
FUTURE INTERNET | 2020年 / 12卷 / 06期
关键词
cyber security; cyber threat intelligence; threat intelligence platform; threat intelligence standard;
D O I
10.3390/fi12060108
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The cyber security landscape is fundamentally changing over the past years. While technology is evolving and new sophisticated applications are being developed, a new threat scenario is emerging in alarming proportions. Sophisticated threats with multi-vectored, multi-staged and polymorphic characteristics are performing complex attacks, making the processes of detection and mitigation far more complicated. Thus, organizations were encouraged to change their traditional defense models and to use and to develop new systems with a proactive approach. Such changes are necessary because the old approaches are not effective anymore to detect advanced attacks. Also, the organizations are encouraged to develop the ability to respond to incidents in real-time using complex threat intelligence platforms. However, since the field is growing rapidly, today Cyber Threat Intelligence concept lacks a consistent definition and a heterogeneous market has emerged, including diverse systems and tools, with different capabilities and goals. This work aims to provide a comprehensive evaluation methodology of threat intelligence standards and cyber threat intelligence platforms. The proposed methodology is based on the selection of the most relevant candidates to establish the evaluation criteria. In addition, this work studies the Cyber Threat Intelligence ecosystem and Threat Intelligence standards and platforms existing in state-of-the-art.
引用
收藏
页数:23
相关论文
共 50 条
  • [1] Cyber Threat Intelligence Model: An Evaluation of Taxonomies, Sharing Standards, and Ontologies within Cyber Threat Intelligence
    Mavroeidis, Vasileios
    Bromander, Siri
    2017 EUROPEAN INTELLIGENCE AND SECURITY INFORMATICS CONFERENCE (EISIC), 2017, : 91 - 98
  • [2] A success model for cyber threat intelligence management platforms
    Zibak, Adam
    Sauerwein, Clemens
    Simpson, Andrew
    COMPUTERS & SECURITY, 2021, 111
  • [3] Data Sanitisation and Redaction for Cyber Threat Intelligence Sharing Platforms
    Yucel, Cagatay
    Chalkias, Ioannis
    Mallis, Dimitrios
    Cetinkaya, Deniz
    Henriksen-Bulmer, Jane
    Cooper, Alice
    PROCEEDINGS OF THE 2021 IEEE INTERNATIONAL CONFERENCE ON CYBER SECURITY AND RESILIENCE (IEEE CSR), 2021, : 343 - 347
  • [4] Cyber Threat Intelligence in Risk Management A Survey of the Impact of Cyber Threat Intelligence on Saudi Higher Education Risk Management
    Aljuhami, Amira M.
    Bamasoud, Doaa M.
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2021, 12 (10) : 156 - 164
  • [5] Barriers to Adopting Interoperability Standards for Cyber Threat Intelligence Sharing: An Exploratory Study
    Gong, Nicole
    INTELLIGENT COMPUTING, VOL 2, 2019, 857 : 666 - 684
  • [6] Modeling Cyber Threat Intelligence
    Bromander, Siri
    Swimmer, Morton
    Eian, Martin
    Skjotskift, Geir
    Borg, Fredrik
    ICISSP: PROCEEDINGS OF THE 6TH INTERNATIONAL CONFERENCE ON INFORMATION SYSTEMS SECURITY AND PRIVACY, 2020, : 273 - 280
  • [7] A Shared Cyber Threat Intelligence Solution for SMEs
    van Haastrecht, Max
    Golpur, Guy
    Tzismadia, Gilad
    Kab, Rolan
    Priboi, Cristian
    David, Dumitru
    Racataian, Adrian
    Brinkhuis, Matthieu
    Spruit, Marco
    ELECTRONICS, 2021, 10 (23)
  • [8] Cyber threat intelligence challenges: Leveraging blockchain intelligence with possible solution
    Saxena, Rashi
    Gayathri, E.
    MATERIALS TODAY-PROCEEDINGS, 2022, 51 : 682 - 689
  • [9] Cyber Threat Intelligence on Blockchain: A Systematic Literature Review
    Chatziamanetoglou, Dimitrios
    Rantos, Konstantinos
    COMPUTERS, 2024, 13 (03)
  • [10] Towards Selecting Informative Content for Cyber Threat Intelligence
    Panagiotou, Panos
    Iliou, Christos
    Apostolou, Konstantinos
    Tsikrika, Theodora
    Vrochidis, Stefanos
    Chatzimisios, Periklis
    Kompatsiaris, Ioannis
    PROCEEDINGS OF THE 2021 IEEE INTERNATIONAL CONFERENCE ON CYBER SECURITY AND RESILIENCE (IEEE CSR), 2021, : 354 - 359