Efficient Incident Response System on Shared Cyber Threat Information Using SDN and STIX

被引:0
|
作者
Okada, Satoshi [1 ,2 ]
Fujiwara, Yoshiki [1 ]
Fujimoto, Mariko [2 ,3 ]
Matsuda, Wataru [4 ]
Mitsunaga, Takuho [2 ]
机构
[1] Univ Tokyo, Tokyo, Japan
[2] Toyo Univ, Tokyo, Japan
[3] Nagoya Inst Technol, Nagoya, Aichi, Japan
[4] NTT Social Informat Labs, Tokyo, Japan
来源
2021 IEEE INTERNATIONAL CONFERENCE ON COMPUTING (ICOCO) | 2021年
关键词
SDN; STIX; Cyber Security; Automation; Information Sharing;
D O I
10.1109/ICOCO53166.2021.9673536
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Cyber threat information sharing is an effective action to detect cyber attacks, especially against sophisticated attackers. For this reason, some organizations related to cyber security, such as ISACs, set up information-sharing schemes. These schemes provide cyber threat information (IP addresses or domains about malicious hosts) to critical infrastructure companies. When a company receives the shared information called indicators, it checks whether its employees' computers are communicating to the mentioned malicious hosts or not. If the communication to malicious hosts is found, it should be blocked to prevent further damage. Usually, this security workflow (receiving indicators, checking communication, and blocking malicious communication) is often done manually. Thus, the workload of the procedure becomes heavier as the number of indicators increases. In this paper, we propose an automated system for efficient indicator handling by combining Software Defined Networking (SDN) and STIX. When the system receives indicators in STIX format, it parses them and changes network configuration dynamically to block communication to malicious hosts. We also compare the required time for handling indicators manually and by using the proposed automated system to show the system's efficiency.
引用
收藏
页码:109 / 114
页数:6
相关论文
共 50 条
  • [21] The Research and Implementation of Incident Response Information System
    Chen, Zuyi
    Yong, Hua
    Zhao, Taixiang
    SOFTWARE ENGINEERING AND KNOWLEDGE ENGINEERING: THEORY AND PRACTICE, VOL 2, 2012, 115 : 875 - 880
  • [22] An efficient cyber threat prediction using a novel artificial intelligence technique
    Sharma, Pankaj
    Prasad, Jay Shankar
    Shaheen
    Ahamed, Shaik Khaleel
    MULTIMEDIA TOOLS AND APPLICATIONS, 2024, 83 (25) : 66757 - 66773
  • [23] SHARED AUDIO INFORMATION-SYSTEM USING NEW AUDIO RESPONSE UNIT
    IMAI, Y
    OHATA, I
    JAPAN TELECOMMUNICATIONS REVIEW, 1981, 23 (04): : 383 - 390
  • [24] Cyber Threat Information Classification and Life Cycle Management using Smart Contracts
    Graf, Roman
    King, Ross
    ICISSP: PROCEEDINGS OF THE 4TH INTERNATIONAL CONFERENCE ON INFORMATION SYSTEMS SECURITY AND PRIVACY, 2018, : 304 - 311
  • [25] Quantifying Degree of Cyber Bullying Using Level of Information Shared and Associated Trust
    Mishra, Manish Kumar
    Kumar, Sumit
    Vaish, Abhishek
    Prakash, Satya
    2015 ANNUAL IEEE INDIA CONFERENCE (INDICON), 2015,
  • [26] HinCTI: A Cyber Threat Intelligence Modeling and Identification System Based on Heterogeneous Information Network
    Gao, Yali
    Li, Xiaoyong
    Peng, Hao
    Fang, Binxing
    Yu, Philip S.
    IEEE TRANSACTIONS ON KNOWLEDGE AND DATA ENGINEERING, 2022, 34 (02) : 708 - 722
  • [27] Secure and Efficient Exchange of Threat Information Using Blockchain Technology
    Pahlevan, Maryam
    Ionita, Valentin
    INFORMATION, 2022, 13 (10)
  • [28] REQUIREMENTS TO SUPPORT A MANAGEMENT INFORMATION SYSTEM TO CONFRONT THE CYBER THREAT IN THE IRAQI TRADE BANK.
    Zbar, Salman Abood
    RUSSIAN LAW JOURNAL, 2023, 11 (03) : 736 - 759
  • [29] A System for Efficiently Hunting for Cyber Threats in Computer Systems Using Threat Intelligence
    Gao, Peng
    Shao, Fei
    Liu, Xiaoyuan
    Xiao, Xusheng
    Liu, Haoyuan
    Qin, Zheng
    Xu, Fengyuan
    Mittal, Prateek
    Kulkarni, Sanjeev R.
    Song, Dawn
    2021 IEEE 37TH INTERNATIONAL CONFERENCE ON DATA ENGINEERING (ICDE 2021), 2021, : 2705 - 2708
  • [30] Cyber Threat Analysis Using Natural Language Processing for a Secure Healthcare System
    Islam, Shareeful
    Papastergiou, Spyridon
    Silvestri, Stefano
    2022 27TH IEEE SYMPOSIUM ON COMPUTERS AND COMMUNICATIONS (IEEE ISCC 2022), 2022,