STIXGEN - A novel framework for Automatic Generation of Structured Cyber Threat Information

被引:7
|
作者
Iqbal, Zafar [1 ]
Anwar, Zahid [1 ,2 ]
Mumtaz, Rafia [1 ]
机构
[1] NUST, Islamabad, Pakistan
[2] Fontbonne Univ, St Louis, MO USA
关键词
Advanced Persistent Threat; STIX; TAXII; OpenIOC; Point of Sale; Tactics Techniques; Training and Procedures; Domain Names (DN);
D O I
10.1109/FIT.2018.00049
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
A large number of Advanced Persistent Threats (APTs) are being launched by nation-states, organizations and individuals within and across borders. It has been observed that APTs launched against an organization subsequently succeeded with high probability against other similar organizations. Therefore, it has become a need of the time that organizations accumulate and share Cyber Threat Information (CTI) with peers in a structured form for timely prevention and recovery of an attack. Although a large volume of cyber threat data is available on different security blogs, however this data is mostly distributed and unstructured. Presently, there is a lack of easy to use frameworks, which produce and share CTI in a structured form. Furthermore, publicly available structured data is sparse and is mostly redundant, irrelevant and erroneous. Ironically, no method has yet been devised to generate the distinct, meaningful and error-free structured data from text. In this regard, we used the standard "Structured Threat Information eXpression (STIX)". Although, STIX is a comprehensive effort, it is slow in adoption. This is due to a largely manual STIX generation process, which is naturally difficult and produces errors. We take all these deficits as a barrier in STIX utilization and these shortcomings have become a motivation for our research work. We not only proposed the STIXGEN framework, but also developed its prototype for a proof of concept. We perform evaluation of our proposed solution in terms of accuracy and effectiveness. At first, we collected different text reports, generated their STIXs via online tools and by using STIXGEN, then we compared and shared their results with domain experts. It was found that our proposed solution's results are better than other tools and are distinct, threat relevant, and error-free. Subsequently, we presented a comparative analysis of the features provided by different STIX generator tools. At the end, we provide a comprehensive STIX dataset of APTs launched against renowned industries on github, so that researchers and analysts can use it for their research.
引用
收藏
页码:241 / 246
页数:6
相关论文
共 50 条
  • [1] SmartValidator: A framework for automatic identification and classification of cyber threat data
    Islam, Chadni
    Babar, M. Ali
    Croft, Roland
    Janicke, Helge
    JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2022, 202
  • [2] An Automatic Generation Approach of the Cyber Threat Intelligence Records Based on Multi-Source Information Fusion
    Sun, Tianfang
    Yang, Pin
    Li, Mengming
    Liao, Shan
    FUTURE INTERNET, 2021, 13 (02): : 1 - 19
  • [3] CYBER THREAT MODELING FRAMEWORK
    Raposo de Melo, Renato Carvalho
    Albuquerque, Robson de Oliveira
    Lopes de Mendonca, Fabio Lficio
    2022 17TH IBERIAN CONFERENCE ON INFORMATION SYSTEMS AND TECHNOLOGIES (CISTI), 2022,
  • [4] An Online Detection Framework for Cyber Attacks on Automatic Generation Control
    Huang, Tong
    Satchidanandan, Bharadwaj
    Kumar, P. R.
    Xie, Le
    IEEE TRANSACTIONS ON POWER SYSTEMS, 2018, 33 (06) : 6816 - 6827
  • [5] An Evolutionary Game-Theoretic Framework for Cyber-threat Information Sharing
    Tosh, Deepak
    Sengupta, Shamik
    Kamhoua, Charles
    Kwiat, Kevin
    Martin, Andrew
    2015 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2015, : 7341 - 7346
  • [6] APT-scope: A novel framework to predict advanced persistent threat groups from enriched heterogeneous information network of cyber threat intelligence
    Gulbay, Burak
    Demirci, Mehmet
    ENGINEERING SCIENCE AND TECHNOLOGY-AN INTERNATIONAL JOURNAL-JESTECH, 2024, 57
  • [7] Automated Generation of Cyber Threat Intelligence
    Kakumaru, Takahiro
    Takahashi, Wataru
    Katsuse, Riku
    Siracusano, Giuseppe
    Sanvito, Davide
    Bifulco, Roberto
    1600, NEC Mediaproducts (17): : 33 - 37
  • [8] Real-Time Automatic Framework for IRC Threat Information Detection
    Shao, Sicong
    2017 IEEE 2ND INTERNATIONAL WORKSHOPS ON FOUNDATIONS AND APPLICATIONS OF SELF* SYSTEMS (FAS*W), 2017, : 382 - 384
  • [9] A Novel Automatic Content Generation and Optimization Framework
    Yu, Zixiao
    Wang, Haohong
    Katsaggelos, Aggelos K.
    Ren, Jian
    IEEE INTERNET OF THINGS JOURNAL, 2023, 10 (14) : 12338 - 12351
  • [10] A novel framework for automatic caption and audio generation
    Kulkarni, Chaitanya
    Monika, P.
    Preeti, B.
    Shruthi, S.
    MATERIALS TODAY-PROCEEDINGS, 2022, 65 : 3248 - 3252