Actionable Intelligence-Oriented Cyber Threat Modeling Framework
| dc.contributor.author | Shin, Bongsik | |
| dc.contributor.author | Elkins, Aaron | |
| dc.contributor.author | Larson, Lance | |
| dc.contributor.author | Cameron, Lance | |
| dc.contributor.author | Perez, Marc | |
| dc.date.accessioned | 2021-12-24T18:21:54Z | |
| dc.date.available | 2021-12-24T18:21:54Z | |
| dc.date.issued | 2022-01-04 | |
| dc.description.abstract | Amid the growing challenges of cybersecurity, the new paradigm of cyber threat intelligence (or CTI) has gained momentum to better deal with cyber threats. There, however, has been one fundamental and very practical problem of information overload organizations face in constructing an effective CTI program. We developed a cyber threat intelligence prototype that automatically and dynamically performs the correlation of business assets, vulnerabilities, and cyber threat information in a scoped setting to remediate the challenge of information overload. Conveniently called TIME (for Threat Intelligence Modeling Environment), it repeats the cycle of: (1) collect internal asset data; (2) gather vulnerability and threat data; (3) correlate vulnerabilities with assets; and (4) derive CTI and alerts significant internal asset-related vulnerabilities in a timely manner. For this, it takes advantage of CTI reports produced by online sites and several NIST standards intended to formalize vulnerability and threat management. | |
| dc.format.extent | 10 pages | |
| dc.identifier.doi | https://doi.org/10.24251/HICSS.2022.820 | |
| dc.identifier.isbn | 978-0-9981331-5-7 | |
| dc.identifier.uri | http://hdl.handle.net/10125/80160 | |
| dc.language.iso | eng | |
| dc.relation.ispartof | Proceedings of the 55th Hawaii International Conference on System Sciences | |
| dc.rights | Attribution-NonCommercial-NoDerivatives 4.0 International | |
| dc.rights.uri | https://creativecommons.org/licenses/by-nc-nd/4.0/ | |
| dc.subject | Organizational Cybersecurity: Advanced Cyber Defense, Cyber Analytics, and Security Operations | |
| dc.subject | cybersecurity | |
| dc.subject | cyber threat intelligence | |
| dc.subject | information security | |
| dc.subject | threat intelligence | |
| dc.title | Actionable Intelligence-Oriented Cyber Threat Modeling Framework | |
| dc.type.dcmi | text |
Files
Original bundle
1 - 1 of 1
