arrow
Return

Data-driven analytics for cyber-threat intelligence and information sharing

delete2017-06-01
delete93
PRE
AI
S
Sara Qamar
Z
Zahid Anwar *
M
Mohammad Ashiqur Rahman
E
Ehab Al‐Shaer
B
Bei-Tseng Chu
DOI:10.1016/j.cose.2017.02.005delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Efficient analysis of shared Cyber Threat Intelligence (CTI) information is crucial for network risk assessment and security hardening. There is a growing interest in implementing a proactive line of defense through threat profiling. However, determining the resiliency of a particular network with respect to relevant threats reported in CTI shared data remains a challenge, largely due to the lack of semantics and contextual information present in textual representations of the threat knowledge. To overcome the limitations of existing CTI frameworks, we devise a threat analytics framework based on Web Ontology Language (OWL) for formal specification, semantic reasoning, and contextual analysis, allowing the derivation of network associated threats from large volumes of shared threat feeds. Our ontology represents constructs of Structured Threat Information eXpression (STIX) with the additional concepts of Cyber Observable eXpression (CybOX), network configurations, and Common Vulnerabilities and Exposure (CVE) for risk analysis and threat actor profiling. The framework provides an automated mechanism to investigate cyber threats targeting the network under question by classifying the threat relevance, determining threat likelihood, identifying the affected and exposed assets through formulated rules and inferences. We perform a comprehensive structural and conceptual evaluation of critical advanced persistent threats (APTs) collected from credible sources and determine their relevance and risk posed to realistic network case studies. Finally we show that the proposed framework is novel in the type of analytics it provides and outperforms other competing approaches in terms of efficiency and effectiveness. (C) 2017 Elsevier Ltd. All rights reserved.
Keywords:
Ontology
STIX
Network
Risk analysis
Impact
Reachability
Cyber threat intelligence
Attribution
Reasoning
OWL
AI Summary

AI Summary

Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.

Journal

C
Computers and Security
IF:
5.4
Papers:
4.6K
Citations:
1.4W

Organization

N
national university of sciences & technology - pakistan
Scholars:
7.8K
Papers: 6.6K
Citations: 6
U
university of north carolina
Scholars:
7.4W
Papers: 6.5W
Citations: 93
U
University of North Carolina Charlotte
Scholars:
3.0K
Papers: 2.5K
Citations: 2
researcher View more organizations