Cyber Threat Intelligence Architecture for Applied Cybersecurity Scenarios PhD Thesis Proposal in Web Science and Technology

被引:0
作者
Rosa, Ivo [1 ]
Batista, Ricardo [2 ]
Goncalves, Ramiro [1 ,5 ]
Martins, Jose [3 ,4 ]
Branco, Frederico [1 ,5 ]
机构
[1] Univ Tras Os Montes & Alto Douro, Vila Real, Portugal
[2] FEUP Univ Porto, Porto, Portugal
[3] Inst Politecn Braganca, Braganca, Portugal
[4] AquaValor Ctr Valorizacao & Transferencia Tecnol, Chaves, Portugal
[5] INESC TEC, Porto, Portugal
来源
2022 17TH IBERIAN CONFERENCE ON INFORMATION SYSTEMS AND TECHNOLOGIES (CISTI) | 2022年
关键词
Cybersecurity; Cyber Threat Intelligence; Security Feeds;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
When talking about Cybersecurity, particularly in security incident response plan and processes it is very common and relevant to talk about the ability to detect malicious or suspicious activities and behavior as soon as possible, in other words, in this domain, in Cybersecurity everyone wants to reduce the Mean time to detect (MTTD) or Mean time to respond (MTTR) a potential security incident. The use of Cyber Threat Intelligence CTI indicators can contribute to the reduction of the mean time to detect threats and consequently directly influence the time to response, however there are different types of Cyber Threat Intelligence that serve different purposes. The objective of the study is the development of a reference architecture to support and process data from the most diverse type of data sources in terms of Cyber Threat Intelligence, for example using the combination data from Open Source Intelligence - OSINT sources and honeypots, taking into consideration the advantages and disadvantages of each of these types of data sources to correlate them with each other in order to increase the trust and reliability of the relevant indicators that can be used by security analysts in incident response processes. This paper presents the proposed work for a PhD thesis in Web Science and Technology, scheduled for completion in July 2023. This doctoral thesis falls within the area of Computer Engineering, with applicability in the domain of Cybersecurity and consequently in the subdomain of Threat Intelligence. The research project is in the state-of-the-art study phase. It is expected that the participation in this Doctoral Symposium will provide potential comments that can enhance the growth and complement the ongoing research work.
引用
收藏
页数:6
相关论文
共 13 条
[1]   Cyber Threat Intelligence from Honeypot Data using Elasticsearch [J].
AL-Mohannadi, Hamad ;
Awan, Irfan ;
Al Hamar, Jassim ;
Cullen, Andrea ;
Disso, Jules Pagan ;
Armitage, Lorna .
PROCEEDINGS 2018 IEEE 32ND INTERNATIONAL CONFERENCE ON ADVANCED INFORMATION NETWORKING AND APPLICATIONS (AINA), 2018, :900-906
[2]  
Alves J., 2017, ECRIME2017EU APWGEU
[3]  
Alves J., 2017, THESIS U LISBOA
[4]  
[Anonymous], "ISO-ISO/IEC 27001-Information security management
[5]  
Branco E., 2017, THESIS U LISBOA
[6]  
Bravo R., 2021, SEGURABA INFORMACAO
[7]  
Bromiley M., 2016, Threat Intelligence: What It Is, and How to Use It Effectively
[8]  
Courtney F, 2016, C EUROPEAN C CYBER W
[9]  
Craigen D, 2014, TECHNOL INNOV MANAG, P13
[10]  
Dionisio N., 2018, THESIS U LISBOA