Improving Quality of Indicators of Compromise Using Stix Graphs
COMPUTERS & SECURITY(2024)
Abstract
Cybersecurity relies on Indicators of Compromise (IoCs) to detect and address threats. Although Threat Intelligence Platforms (TIPs) and Open Source Intelligence (OSINT) are common sources for gathering IoCs, their reliability varies. In our study, we enhance the management of IoCs and OSINT by introducing a novel method that reliably assesses IoC’s threat severity and confidence scores, focusing on Structured Threat Information eXpression (STIX) for threat associations. Our approach, implemented on OpenCTI, significantly enhances IoC value, as it aggregates threat intelligence from diverse sources utilizing a STIX graph-based approach, which is a unique feature among TIPs. Additionally, our method employs heuristic analysis to optimize IoC scoring. It takes into account factors such as relevance, completeness, timeliness, accuracy, and consistency while emphasizing the confidence of the source. Notably, the proposed method has enhanced the precision of the confidence score, achieving a 25.18% reduction in the average difference of confidence scores compared to the benchmarked platform. The Emotet and Medusa case studies underscore the importance of source credibility in confidence scores, emphasizing our TIP’s precision in cybersecurity threat assessment and defense enhancement.
MoreTranslated text
Key words
Indicators of Compromise (IoC),Threat Intelligence Platform (TIP),Cyber Threat Intelligence (CTI),Structured Threat Information eXpression (STIX),Open Source INTelligence (OSINT)
求助PDF
上传PDF
View via Publisher
AI Read Science
Must-Reading Tree
Example

Generate MRT to find the research sequence of this paper
Related Papers
2016
被引用127 | 浏览
2016
被引用355 | 浏览
2018
被引用22 | 浏览
2019
被引用47 | 浏览
2019
被引用127 | 浏览
2021
被引用21 | 浏览
2022
被引用86 | 浏览
2022
被引用4 | 浏览
2022
被引用6 | 浏览
Data Disclaimer
The page data are from open Internet sources, cooperative publishers and automatic analysis results through AI technology. We do not make any commitments and guarantees for the validity, accuracy, correctness, reliability, completeness and timeliness of the page data. If you have any questions, please contact us by email: report@aminer.cn
Chat Paper
Summary is being generated by the instructions you defined