Applied Cryptography and Network Security Workshops - ACNS 2023 Satellite Workshops, ADSC, AIBlock, AIHWS, AIoTS, CIMSS, Cloud S&P, SCI, SecMT, SiMLA, Kyoto, Japan, June 19-22, 2023, Proceedings

Applied Cryptography and Network Security Workshops - ACNS 2023 Satellite Workshops, ADSC, AIBlock, AIHWS, AIoTS, CIMSS, Cloud S&P, SCI, SecMT, SiMLA, Kyoto, Japan, June 19-22, 2023, Proceedings
复制标题

应用密码学和网络安全研讨会 - ACNS 2023 卫星研讨会、ADSC、AIBlock、AIHWS、AIoTS、CIMSS、Cloud S

DOI:
10.1007/978-3-031-41181-6_18
复制
发表时间:
2023
期刊:
--
影响因子:
--
通讯作者:
Kumar M
Kumar M
中科院分区:
--
文献类型:
--
作者:
Kumar M

文献摘要

相似文献

增材制造(AM)提供了许多好处,例如快速、经济高效地制造复杂和定制的设计,减少材料浪费,并实现按需生产。然而,与AM相关的一些安全挑战使其对从个人黑客到有组织犯罪团伙和民族国家行为者的攻击者越来越有吸引力。本文提出了一种新的基于语义的威胁优先级系统,用于识别,提取和排名指标的妥协(IOC)的AM攻击者的网络风险。该系统利用异构信息网络(HIN),自动提取高层次的IOCs从多源威胁文本,并确定IOCs之间的语义关系。它用包含不同元路径和元图的HIN对IOCs进行建模,以描述不同IOCs之间的语义关系。我们引入了一个特定于领域的识别器,它在三个领域中识别IOC:organization_specific,regional_source-specific和regional_target-specific。威胁评估使用基于元路径和元图的相似性度量来评估IOC之间的语义关系。它通过基于攻击频率、IOC生命周期和每个域中被利用的漏洞来衡量其严重性,从而确定IOC的优先级。
Additive manufacturing (AM) offers numerous benefits, such as manufacturing complex and customised designs quickly and cost-effectively, reducing material waste, and enabling on-demand production. However, several security challenges are associated with AM, making it increasingly attractive to attackers ranging from individual hackers to organised criminal gangs and nation-state actors. This paper addresses the cyber risk in AM to attackers by proposing a novel semantic-based threat prioritisation system for identifying, extracting and ranking indicators of compromise (IOC). The system leverages the heterogeneous information networks (HINs) that automatically extract high-level IOCs from multi-source threat text and identifies semantic relations among the IOCs. It models IOCs with a HIN comprising different meta-paths and meta-graphs to depict semantic relations among diverse IOCs. We introduce a domain-specific recogniser that identifies IOCs in three domains:organisation_specific,regional_source-specific, andregional_target-specific. A threat assessment uses similarity measures based on meta-paths and meta-graphs to assess semantic relations among IOCs. It prioritises IOCs by measuring their severity based on the frequency of attacks, IOC lifetime, and exploited vulnerabilities in each domain.