The Experts below are selected from a list of 1482 Experts worldwide ranked by ideXlab platform
Günther Pernul - One of the best experts on this subject based on the ideXlab platform.
-
Measuring and visualizing cyber Threat Intelligence quality
International Journal of Information Security, 2020Co-Authors: Daniel Schlette, Fabian Böhm, Marco Caselli, Günther PernulAbstract:The very raison d’être of cyber Threat Intelligence (CTI) is to provide meaningful knowledge about cyber security Threats. The exchange and collaborative generation of CTI by the means of sharing platforms has proven to be an important aspect of practical application. It is evident to infer that inaccurate, incomplete, or outdated Threat Intelligence is a major problem as only high-quality CTI can be helpful to detect and defend against cyber attacks. Additionally, while the amount of available CTI is increasing it is not warranted that quality remains unaffected. In conjunction with the increasing number of available CTI, it is thus in the best interest of every stakeholder to be aware of the quality of a CTI artifact. This allows for informed decisions and permits detailed analyses. Our work makes a twofold contribution to the challenge of assessing Threat Intelligence quality. We first propose a series of relevant quality dimensions and configure metrics to assess the respective dimensions in the context of CTI. In a second step, we showcase the extension of an existing CTI analysis tool to make the quality assessment transparent to security analysts. Furthermore, analysts’ subjective perceptions are, where necessary, included in the quality assessment concept.
-
measuring and visualizing cyber Threat Intelligence quality
International Journal of Information Security, 2020Co-Authors: Daniel Schlette, Fabian Böhm, Marco Caselli, Günther PernulAbstract:The very raison d’etre of cyber Threat Intelligence (CTI) is to provide meaningful knowledge about cyber security Threats. The exchange and collaborative generation of CTI by the means of sharing platforms has proven to be an important aspect of practical application. It is evident to infer that inaccurate, incomplete, or outdated Threat Intelligence is a major problem as only high-quality CTI can be helpful to detect and defend against cyber attacks. Additionally, while the amount of available CTI is increasing it is not warranted that quality remains unaffected. In conjunction with the increasing number of available CTI, it is thus in the best interest of every stakeholder to be aware of the quality of a CTI artifact. This allows for informed decisions and permits detailed analyses. Our work makes a twofold contribution to the challenge of assessing Threat Intelligence quality. We first propose a series of relevant quality dimensions and configure metrics to assess the respective dimensions in the context of CTI. In a second step, we showcase the extension of an existing CTI analysis tool to make the quality assessment transparent to security analysts. Furthermore, analysts’ subjective perceptions are, where necessary, included in the quality assessment concept.
-
unifying cyber Threat Intelligence
Trust and Privacy in Digital Business, 2019Co-Authors: Florian Menges, Christine Sperl, Günther PernulAbstract:The Threat landscape and the associated number of IT security incidents are constantly increasing. In order to address this problem, a trend towards cooperative approaches and the exchange of information on security incidents has been developing over recent years. Today, several different data formats with varying properties are available that allow to structure and describe incidents as well as cyber Threat Intelligence (CTI) information. Observed differences in data formats implicate problems in regard to consistent understanding and compatibility. This ultimately builds a barrier for efficient information exchange. Moreover, a common definition for the components of CTI formats is missing. In order to improve this situation, this work presents an approach for the description and unification of these formats. Therefore, we propose a model that describes the elementary properties as well as a common notation for entities within CTI formats. In addition, we develop a unified model to show the results of our work, to improve the understanding of CTI data formats and to discuss possible future research directions.
-
TrustBus - Unifying Cyber Threat Intelligence.
Trust Privacy and Security in Digital Business, 2019Co-Authors: Florian Menges, Christine Sperl, Günther PernulAbstract:The Threat landscape and the associated number of IT security incidents are constantly increasing. In order to address this problem, a trend towards cooperative approaches and the exchange of information on security incidents has been developing over recent years. Today, several different data formats with varying properties are available that allow to structure and describe incidents as well as cyber Threat Intelligence (CTI) information. Observed differences in data formats implicate problems in regard to consistent understanding and compatibility. This ultimately builds a barrier for efficient information exchange. Moreover, a common definition for the components of CTI formats is missing. In order to improve this situation, this work presents an approach for the description and unification of these formats. Therefore, we propose a model that describes the elementary properties as well as a common notation for entities within CTI formats. In addition, we develop a unified model to show the results of our work, to improve the understanding of CTI data formats and to discuss possible future research directions.
Daniel Schlette - One of the best experts on this subject based on the ideXlab platform.
-
Measuring and visualizing cyber Threat Intelligence quality
International Journal of Information Security, 2020Co-Authors: Daniel Schlette, Fabian Böhm, Marco Caselli, Günther PernulAbstract:The very raison d’être of cyber Threat Intelligence (CTI) is to provide meaningful knowledge about cyber security Threats. The exchange and collaborative generation of CTI by the means of sharing platforms has proven to be an important aspect of practical application. It is evident to infer that inaccurate, incomplete, or outdated Threat Intelligence is a major problem as only high-quality CTI can be helpful to detect and defend against cyber attacks. Additionally, while the amount of available CTI is increasing it is not warranted that quality remains unaffected. In conjunction with the increasing number of available CTI, it is thus in the best interest of every stakeholder to be aware of the quality of a CTI artifact. This allows for informed decisions and permits detailed analyses. Our work makes a twofold contribution to the challenge of assessing Threat Intelligence quality. We first propose a series of relevant quality dimensions and configure metrics to assess the respective dimensions in the context of CTI. In a second step, we showcase the extension of an existing CTI analysis tool to make the quality assessment transparent to security analysts. Furthermore, analysts’ subjective perceptions are, where necessary, included in the quality assessment concept.
-
measuring and visualizing cyber Threat Intelligence quality
International Journal of Information Security, 2020Co-Authors: Daniel Schlette, Fabian Böhm, Marco Caselli, Günther PernulAbstract:The very raison d’etre of cyber Threat Intelligence (CTI) is to provide meaningful knowledge about cyber security Threats. The exchange and collaborative generation of CTI by the means of sharing platforms has proven to be an important aspect of practical application. It is evident to infer that inaccurate, incomplete, or outdated Threat Intelligence is a major problem as only high-quality CTI can be helpful to detect and defend against cyber attacks. Additionally, while the amount of available CTI is increasing it is not warranted that quality remains unaffected. In conjunction with the increasing number of available CTI, it is thus in the best interest of every stakeholder to be aware of the quality of a CTI artifact. This allows for informed decisions and permits detailed analyses. Our work makes a twofold contribution to the challenge of assessing Threat Intelligence quality. We first propose a series of relevant quality dimensions and configure metrics to assess the respective dimensions in the context of CTI. In a second step, we showcase the extension of an existing CTI analysis tool to make the quality assessment transparent to security analysts. Furthermore, analysts’ subjective perceptions are, where necessary, included in the quality assessment concept.
K P Chow - One of the best experts on this subject based on the ideXlab platform.
-
A Framework for Dark Web Threat Intelligence Analysis
Cyber Warfare and Terrorism, 2020Co-Authors: Xuan Zhang, K P ChowAbstract:This article describes how the Dark Web is usually considered the dark side of the World Wide Web. Cyber criminals usually use specialized tools, e.g. TOR, to access the hidden services inside the Dark Web anonymously. Law enforcement officers have difficulty tracing the identity of these cyber criminals using traditional network investigation techniques that are based on IP addresses. The information available in the Dark Web, which includes BitCoin wallets, email addresses, hyperlinks, images and user behavior profiles, can be used for further analysis, such as a correlation analysis. Present within this artcile is a Threat Intelligence analysis framework to help analyze the crimes and criminals in the Dark Web and the framework is realized by the implementation of the Dark Web Threat Intelligence Analysis (DWTIA) Platform.
-
automatic tagging of cyber Threat Intelligence unstructured data using semantics extraction
Intelligence and Security Informatics, 2019Co-Authors: Tianyi Wang, K P ChowAbstract:Threat Intelligence, information about potential or current attacks to an organization, is an important component in cyber security territory. As new Threats consecutively occurring, cyber security professionals always keep an eye on the latest Threat Intelligence in order to continuously lower the security risks for their organizations. Cyber Threat Intelligence is usually conveyed by structured data like CVE entities and unstructured data like articles and reports. Structured data are always under certain patterns that can be easily analyzed, while unstructured data have more difficulties to find fixed patterns to analyze. There exists plenty of methods and algorithms on information extraction from structured data, but no current work is complete or suitable for semantics extraction upon unstructured cyber Threat Intelligence data. In this paper, we introduce an idea of automatic tagging applying JAPE feature within GATE framework to perform semantics extraction upon cyber Threat Intelligence unstructured data such as articles and reports. We extract token entities from each cyber Threat Intelligence article or report and evaluate the usefulness of them. A Threat Intelligence ontology then can be constructed with the useful entities extracted from related resources and provide convenience for professionals to find latest useful Threat Intelligence they need.
-
ISI - Automatic Tagging of Cyber Threat Intelligence Unstructured Data using Semantics Extraction
2019 IEEE International Conference on Intelligence and Security Informatics (ISI), 2019Co-Authors: Tianyi Wang, K P ChowAbstract:Threat Intelligence, information about potential or current attacks to an organization, is an important component in cyber security territory. As new Threats consecutively occurring, cyber security professionals always keep an eye on the latest Threat Intelligence in order to continuously lower the security risks for their organizations. Cyber Threat Intelligence is usually conveyed by structured data like CVE entities and unstructured data like articles and reports. Structured data are always under certain patterns that can be easily analyzed, while unstructured data have more difficulties to find fixed patterns to analyze. There exists plenty of methods and algorithms on information extraction from structured data, but no current work is complete or suitable for semantics extraction upon unstructured cyber Threat Intelligence data. In this paper, we introduce an idea of automatic tagging applying JAPE feature within GATE framework to perform semantics extraction upon cyber Threat Intelligence unstructured data such as articles and reports. We extract token entities from each cyber Threat Intelligence article or report and evaluate the usefulness of them. A Threat Intelligence ontology then can be constructed with the useful entities extracted from related resources and provide convenience for professionals to find latest useful Threat Intelligence they need.
Fabian Böhm - One of the best experts on this subject based on the ideXlab platform.
-
Measuring and visualizing cyber Threat Intelligence quality
International Journal of Information Security, 2020Co-Authors: Daniel Schlette, Fabian Böhm, Marco Caselli, Günther PernulAbstract:The very raison d’être of cyber Threat Intelligence (CTI) is to provide meaningful knowledge about cyber security Threats. The exchange and collaborative generation of CTI by the means of sharing platforms has proven to be an important aspect of practical application. It is evident to infer that inaccurate, incomplete, or outdated Threat Intelligence is a major problem as only high-quality CTI can be helpful to detect and defend against cyber attacks. Additionally, while the amount of available CTI is increasing it is not warranted that quality remains unaffected. In conjunction with the increasing number of available CTI, it is thus in the best interest of every stakeholder to be aware of the quality of a CTI artifact. This allows for informed decisions and permits detailed analyses. Our work makes a twofold contribution to the challenge of assessing Threat Intelligence quality. We first propose a series of relevant quality dimensions and configure metrics to assess the respective dimensions in the context of CTI. In a second step, we showcase the extension of an existing CTI analysis tool to make the quality assessment transparent to security analysts. Furthermore, analysts’ subjective perceptions are, where necessary, included in the quality assessment concept.
-
measuring and visualizing cyber Threat Intelligence quality
International Journal of Information Security, 2020Co-Authors: Daniel Schlette, Fabian Böhm, Marco Caselli, Günther PernulAbstract:The very raison d’etre of cyber Threat Intelligence (CTI) is to provide meaningful knowledge about cyber security Threats. The exchange and collaborative generation of CTI by the means of sharing platforms has proven to be an important aspect of practical application. It is evident to infer that inaccurate, incomplete, or outdated Threat Intelligence is a major problem as only high-quality CTI can be helpful to detect and defend against cyber attacks. Additionally, while the amount of available CTI is increasing it is not warranted that quality remains unaffected. In conjunction with the increasing number of available CTI, it is thus in the best interest of every stakeholder to be aware of the quality of a CTI artifact. This allows for informed decisions and permits detailed analyses. Our work makes a twofold contribution to the challenge of assessing Threat Intelligence quality. We first propose a series of relevant quality dimensions and configure metrics to assess the respective dimensions in the context of CTI. In a second step, we showcase the extension of an existing CTI analysis tool to make the quality assessment transparent to security analysts. Furthermore, analysts’ subjective perceptions are, where necessary, included in the quality assessment concept.
Marco Caselli - One of the best experts on this subject based on the ideXlab platform.
-
Measuring and visualizing cyber Threat Intelligence quality
International Journal of Information Security, 2020Co-Authors: Daniel Schlette, Fabian Böhm, Marco Caselli, Günther PernulAbstract:The very raison d’être of cyber Threat Intelligence (CTI) is to provide meaningful knowledge about cyber security Threats. The exchange and collaborative generation of CTI by the means of sharing platforms has proven to be an important aspect of practical application. It is evident to infer that inaccurate, incomplete, or outdated Threat Intelligence is a major problem as only high-quality CTI can be helpful to detect and defend against cyber attacks. Additionally, while the amount of available CTI is increasing it is not warranted that quality remains unaffected. In conjunction with the increasing number of available CTI, it is thus in the best interest of every stakeholder to be aware of the quality of a CTI artifact. This allows for informed decisions and permits detailed analyses. Our work makes a twofold contribution to the challenge of assessing Threat Intelligence quality. We first propose a series of relevant quality dimensions and configure metrics to assess the respective dimensions in the context of CTI. In a second step, we showcase the extension of an existing CTI analysis tool to make the quality assessment transparent to security analysts. Furthermore, analysts’ subjective perceptions are, where necessary, included in the quality assessment concept.
-
measuring and visualizing cyber Threat Intelligence quality
International Journal of Information Security, 2020Co-Authors: Daniel Schlette, Fabian Böhm, Marco Caselli, Günther PernulAbstract:The very raison d’etre of cyber Threat Intelligence (CTI) is to provide meaningful knowledge about cyber security Threats. The exchange and collaborative generation of CTI by the means of sharing platforms has proven to be an important aspect of practical application. It is evident to infer that inaccurate, incomplete, or outdated Threat Intelligence is a major problem as only high-quality CTI can be helpful to detect and defend against cyber attacks. Additionally, while the amount of available CTI is increasing it is not warranted that quality remains unaffected. In conjunction with the increasing number of available CTI, it is thus in the best interest of every stakeholder to be aware of the quality of a CTI artifact. This allows for informed decisions and permits detailed analyses. Our work makes a twofold contribution to the challenge of assessing Threat Intelligence quality. We first propose a series of relevant quality dimensions and configure metrics to assess the respective dimensions in the context of CTI. In a second step, we showcase the extension of an existing CTI analysis tool to make the quality assessment transparent to security analysts. Furthermore, analysts’ subjective perceptions are, where necessary, included in the quality assessment concept.