Cargando…

Contextualized Filtering for Shared Cyber Threat Information

Cyber threat information sharing is an imperative process towards achieving collaborative security, but it poses several challenges. One crucial challenge is the plethora of shared threat information. Therefore, there is a need to advance filtering of such information. While the state-of-the-art in...

Descripción completa

Detalles Bibliográficos
Autores principales: Dimitriadis, Athanasios, Prassas, Christos, Flores, Jose Luis, Kulvatunyou, Boonserm, Ivezic, Nenad, Gritzalis, Dimitris A., Mavridis, Ioannis K.
Formato: Online Artículo Texto
Lenguaje:English
Publicado: MDPI 2021
Materias:
Acceso en línea:https://www.ncbi.nlm.nih.gov/pmc/articles/PMC8309719/
https://www.ncbi.nlm.nih.gov/pubmed/34300629
http://dx.doi.org/10.3390/s21144890
_version_ 1783728587265802240
author Dimitriadis, Athanasios
Prassas, Christos
Flores, Jose Luis
Kulvatunyou, Boonserm
Ivezic, Nenad
Gritzalis, Dimitris A.
Mavridis, Ioannis K.
author_facet Dimitriadis, Athanasios
Prassas, Christos
Flores, Jose Luis
Kulvatunyou, Boonserm
Ivezic, Nenad
Gritzalis, Dimitris A.
Mavridis, Ioannis K.
author_sort Dimitriadis, Athanasios
collection PubMed
description Cyber threat information sharing is an imperative process towards achieving collaborative security, but it poses several challenges. One crucial challenge is the plethora of shared threat information. Therefore, there is a need to advance filtering of such information. While the state-of-the-art in filtering relies primarily on keyword- and domain-based searching, these approaches require sizable human involvement and rarely available domain expertise. Recent research revealed the need for harvesting of business information to fill the gap in filtering, albeit it resulted in providing coarse-grained filtering based on the utilization of such information. This paper presents a novel contextualized filtering approach that exploits standardized and multi-level contextual information of business processes. The contextual information describes the conditions under which a given threat information is actionable from an organization perspective. Therefore, it can automate filtering by measuring the equivalence between the context of the shared threat information and the context of the consuming organization. The paper directly contributes to filtering challenge and indirectly to automated customized threat information sharing. Moreover, the paper proposes the architecture of a cyber threat information sharing ecosystem that operates according to the proposed filtering approach and defines the characteristics that are advantageous to filtering approaches. Implementation of the proposed approach can support compliance with the Special Publication 800-150 of the National Institute of Standards and Technology.
format Online
Article
Text
id pubmed-8309719
institution National Center for Biotechnology Information
language English
publishDate 2021
publisher MDPI
record_format MEDLINE/PubMed
spelling pubmed-83097192021-07-25 Contextualized Filtering for Shared Cyber Threat Information Dimitriadis, Athanasios Prassas, Christos Flores, Jose Luis Kulvatunyou, Boonserm Ivezic, Nenad Gritzalis, Dimitris A. Mavridis, Ioannis K. Sensors (Basel) Article Cyber threat information sharing is an imperative process towards achieving collaborative security, but it poses several challenges. One crucial challenge is the plethora of shared threat information. Therefore, there is a need to advance filtering of such information. While the state-of-the-art in filtering relies primarily on keyword- and domain-based searching, these approaches require sizable human involvement and rarely available domain expertise. Recent research revealed the need for harvesting of business information to fill the gap in filtering, albeit it resulted in providing coarse-grained filtering based on the utilization of such information. This paper presents a novel contextualized filtering approach that exploits standardized and multi-level contextual information of business processes. The contextual information describes the conditions under which a given threat information is actionable from an organization perspective. Therefore, it can automate filtering by measuring the equivalence between the context of the shared threat information and the context of the consuming organization. The paper directly contributes to filtering challenge and indirectly to automated customized threat information sharing. Moreover, the paper proposes the architecture of a cyber threat information sharing ecosystem that operates according to the proposed filtering approach and defines the characteristics that are advantageous to filtering approaches. Implementation of the proposed approach can support compliance with the Special Publication 800-150 of the National Institute of Standards and Technology. MDPI 2021-07-18 /pmc/articles/PMC8309719/ /pubmed/34300629 http://dx.doi.org/10.3390/s21144890 Text en © 2021 by the authors. https://creativecommons.org/licenses/by/4.0/Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (https://creativecommons.org/licenses/by/4.0/).
spellingShingle Article
Dimitriadis, Athanasios
Prassas, Christos
Flores, Jose Luis
Kulvatunyou, Boonserm
Ivezic, Nenad
Gritzalis, Dimitris A.
Mavridis, Ioannis K.
Contextualized Filtering for Shared Cyber Threat Information
title Contextualized Filtering for Shared Cyber Threat Information
title_full Contextualized Filtering for Shared Cyber Threat Information
title_fullStr Contextualized Filtering for Shared Cyber Threat Information
title_full_unstemmed Contextualized Filtering for Shared Cyber Threat Information
title_short Contextualized Filtering for Shared Cyber Threat Information
title_sort contextualized filtering for shared cyber threat information
topic Article
url https://www.ncbi.nlm.nih.gov/pmc/articles/PMC8309719/
https://www.ncbi.nlm.nih.gov/pubmed/34300629
http://dx.doi.org/10.3390/s21144890
work_keys_str_mv AT dimitriadisathanasios contextualizedfilteringforsharedcyberthreatinformation
AT prassaschristos contextualizedfilteringforsharedcyberthreatinformation
AT floresjoseluis contextualizedfilteringforsharedcyberthreatinformation
AT kulvatunyouboonserm contextualizedfilteringforsharedcyberthreatinformation
AT ivezicnenad contextualizedfilteringforsharedcyberthreatinformation
AT gritzalisdimitrisa contextualizedfilteringforsharedcyberthreatinformation
AT mavridisioannisk contextualizedfilteringforsharedcyberthreatinformation