Reading the Tea leaves: A Comparative Analysis of Threat Intelligence

Reading the Tea leaves: A Comparative Analysis of Threat Intelligence
复制标题

DOI:
--
复制
发表时间:
2019
期刊:
2020 IEEE International Conference on Big Data (Big Data)
影响因子:
--
通讯作者:
Vector Guo Li;M. Dunn;P. Pearce;Damon McCoy;G. Voelker;S. Savage
Vector Guo Li;M. Dunn;P. Pearce;Damon McCoy;G. Voelker;S. Savage
中科院分区:
其他
文献类型:
--
作者:
Vector Guo Li;M. Dunn;P. Pearce;Damon McCoy;G. Voelker;S. Savage

文献摘要

被引文献

相似文献

“威胁情报”一词已迅速成为计算机安全行业的主要流行语。完全合理的前提是,通过汇编有关已知威胁的最新信息(即,IP地址、域名、文件散列等),这样的信息的接收者能够更好地保护他们的系统免受未来的攻击。因此,今天广泛的公共和商业来源分发威胁情报数据源以支持这一目的。然而,我们对这些数据的理解、其特征及其能够有意义地支持其预期用途的程度仍然相当有限。在本文中,我们通过正式定义一组用于表征威胁情报数据源的指标,并使用这些指标系统地表征广泛的公共和商业来源,来解决这些差距。此外,我们使用外部测量来定性调查覆盖范围和准确性问题。不幸的是,我们的测量结果表明,在使用现有的威胁情报数据实现其预期目标方面存在重大限制和挑战。
The term “threat intelligence” has swiftly become a staple buzzword in the computer security industry. The entirely reasonable premise is that, by compiling up-to-date information about known threats (i.e., IP addresses, domain names, file hashes, etc.), recipients of such information may be able to better defend their systems from future attacks. Thus, today a wide array of public and commercial sources distribute threat intelligence data feeds to support this purpose. However, our understanding of this data, its characterization and the extent to which it can meaningfully support its intended uses, is still quite limited. In this paper, we address these gaps by formally defining a set of metrics for characterizing threat intelligence data feeds and using these measures to systematically characterize a broad range of public and commercial sources. Further, we ground our quantitative assessments using external measurements to qualitatively investigate issues of coverage and accuracy. Unfortunately, our measurement results suggest that there are significant limitations and challenges in using existing threat intelligence data for its purported goals.