网络威胁情报共享与融合技术综述
收稿日期: 2024-03-15
网络出版日期: 2024-07-08
基金资助
鹏城实验室重大攻关项目(PCL2022A03);浙江省自然科学基金(LZ22F020007)
版权
A survey of cyber threat intelligence sharing and fusion technologies
Received date: 2024-03-15
Online published: 2024-07-08
Copyright
随着网络空间新生威胁日趋复杂多变,攻击方式从单一化向协作化、隐蔽化发展,传统被动式网络安全防御体系受到极大挑战,其面临的一个主要难题是信息获取能力的不对称,导致防御方难以及时掌握和检测协作形式的规模化网络攻击。网络威胁情报(Cyber Threat Intelligence,CTI)记录攻击者的行为特征,通过对攻击线索进行关联分析能够有效地检测和研判复杂网络攻击,是主动协同网络安全防御体系的关键。然而,在威胁情报应用过程中需要提高情报共享的安全性和性能,并解决多源情报格式异构和概念冲突等问题,这引起了学术界和产业界的众多关注。深入调研近年来的相关成果,从情报共享和情报融合两个角度整理已有工作并进行总结,最后指出该领域未来的研究方向。通过梳理和分析现有威胁情报共享和融合的研究概况,推进我国威胁情报应用工作的发展,进一步提升网络空间主动协同防御的能力。
向夏雨 , 顾钊铨 , 曾丽仪 . 网络威胁情报共享与融合技术综述[J]. 网络空间安全科学学报, 2024 , 2(2) : 2 -17 . DOI: 10.20172/j.issn.2097-3136.240201
With the increasingly complex and variable new threats in cyberspace, the attack methods have developed from simplification to collaboration and concealment, and the traditional passive network security defense system has been greatly challenged. One of the foremost challenges is the asymmetry of information acquisition ability, which impedes the timely identification and detection of collaborative cyber-attacks. Cyber threat intelligence (CTI) not only records the behavioral characteristics of attackers but also enables effective detection and diagnosis of complex cyber attacks through correlation analysis of these clues, serving as a crucial component of proactive collaborative network security defense systems. However, enhancing security and performance of intelligence sharing while addressing data heterogeneity and conceptual differences across various sources remain challenges in utilizing CTI. This issue has garnered attention from both academics and industry professionals. Research on relevant achievements in recent years was conducted deeply, existing work was summarized from the perspectives of intelligence sharing and fusion, and future research directions in this field were outlined finally. By reviewing and analyzing the current research on threat intelligence sharing and fusion, it is helpful to advance the application of threat intelligence in China, further enhancing the capabilities of proactive and collaborative defense in cyberspace.
| 1 |
方滨兴, 时金桥, 王忠儒, 等. 人工智能赋能网络攻击的安全威胁及应对策略[J]. 中国工程科学, 2021, 23 (3): 60- 66.
FANG B X, SHI J Q, WANG Z R, et al. AI-enabled cyberspace attacks: security risks and countermeasures[J]. Strategic Study of CAE, 2021, 23 (3): 60- 66.
|
| 2 |
武琼. 乌克兰危机中网络空间对抗的影响及启示[J]. 俄罗斯东欧中亚研究,2023 (3):84-104.
WU Q. The impact and enlightenment of cyberspace confrontation in the Ukraine crisis[J]. Russian,East European & Central Asian Studies,2023 (3):84-104.
|
| 3 |
刘国山, 吕玮. 2021 年全球活跃黑客组织掠影[J]. 信息安全与通信保密, 2022, 20 (1): 17- 31.
LIU G S, LÜ W. Overview of active hacker groups around the world in 2021[J]. Information Security and Communications Privacy, 2022, 20 (1): 17- 31.
|
| 4 |
贾焰, 方滨兴, 李爱平, 等. 基于人工智能的网络空间安全防御战略研究[J]. 中国工程科学, 2021, 23 (3): 98- 105.
JIA Y, FANG B X, LI A P, et al. Artificial intelligence enabled cyberspace security defense[J]. Strategic Study of CAE, 2021, 23 (3): 98- 105.
|
| 5 |
田志宏, 方滨兴, 廖清, 等. 从自卫到护卫: 新时期网络安全保障体系构建与发展建议[J]. 中国工程科学, 2023, 25 (6): 1- 10.
TIAN Z H, FANG B X, LIAO Q, et al. Cybersecurity assurance system in the new era and development suggestions thereof: from self-defense to guard[J]. Strategic Study of CAE, 2023, 25 (6): 1- 10.
|
| 6 |
SCHLETTE D, CASELLI M, PERNUL G. A comparative study on cyber threat intelligence: the security incident response perspective[J]. IEEE Communications Surveys & Tutorials, 2021, 23 (4): 2525- 2556.
|
| 7 |
GAO P,SHAO F,LIU X,et al. Enabling efficient cyber threat hunting with cyber threat intelligence[C]//2021 IEEE 37th International Conference on Data Engineering(ICDE),April 19-22, 2021,Chania,Greece. New York:IEEE,2021:193-204.
|
| 8 |
熊钢, 葛雨玮, 褚衍杰, 等. 基于跨域协同的网络空间威胁预警模式[J]. 网络与信息安全学报, 2020, 6 (6): 88- 96.
XIONG G, GE Y W, CHU Y J, et al. Model of cyberspace threat early warning based on cross-domain and collaboration[J]. Chinese Journal of Network and Information Security, 2020, 6 (6): 88- 96.
|
| 9 |
KUEHN P, RIEBE T, APELT L, et al. Sharing of cyber threat intelligence between states[J]. Sicherheit und Frieden, 2020, 38 (1): 22- 28.
|
| 10 |
GRO S. Research directions in cyber threat intelligence[EB]. arXiv preprint arXiv:2001. 06616,2020. [2024-02-24]. https://arxiv.org/abs/2001.06616.
|
| 11 |
Gartner Inc. Gartner market guide [EB/OL]. (2014-04-08) [2024-03-01]. https://www.gartner.com/en/research/methodologies/market-guide.
|
| 12 |
崔琳, 杨黎斌, 何清林, 等. 基于开源信息平台的威胁情报挖掘综述[J]. 信息安全学报, 2022, 7 (1): 1- 26.
CUI L, YANG L B, HE Q L, et al. Survey of cyber threat intelligence mining based on open source information platform[J]. Journal of Cyber Security, 2022, 7 (1): 1- 26.
|
| 13 |
NCSC. National cyber security centre [EB/OL]. (2024-02-04)[2024-03-01]. https://www.ncsc.gov.uk/content/files/protected_files/guidance_files/MWR_Threat_Intelligence_whitepaper-2015.pdf.
|
| 14 |
BIANCO D. The pyramid of pain [EB/OL]. (2013-03-01) [2024-03-01]. https://detect-respond.blogspot.com/2013/03/the-pyramid-of-pain.html.
|
| 15 |
BARNUM S. Standardizing cyber threat intelligence information with the Structured Threat Information Expression (STIX)[J]. Mitre Corporation, 2012, 11, 1- 22.
|
| 16 |
CONNOLLY J,DAVIDSON M,SCHMIDT C. The Trusted Automated Exchange of Indicator Information ( TAXII)[EB/OL]. (2014-05-02)[2024-03-01]. https://taxii.mitre.org/about/documents/Introduction_to_TAXII_White_Paper_May_2014.pdf.
|
| 17 |
BARNUM S,MARTIN R,WORRELL B,et al. The cybox language specification[EB/OL]. (2012-04-13)[2024-03-01]. https://cybox.mitre.org/language/specifications/CybOX_Language_Defined_Objects_Specification_v1.0.pdf.
|
| 18 |
Mandiant Inc. The OpenIOC framework [EB/OL]. (2013-10-01) [2024-03-01]. http://www.openioc.org.
|
| 19 |
全国信息安全标准化技术委员会. 信息安全技术 网络安全威胁信息格式规范:GB/T 36643—2018 [S]. 北京:中国标准出版社,2019.
China Information Security Standardization Technical Committee. Information security technology—Cyber security threat information format:GB/T 36643—2018 [S]. Beijing:Standard Press of China,2019.
|
| 20 |
石志鑫, 马瑜汝, 张悦, 等. 威胁情报相关标准综述[J]. 信息安全研究, 2019, 5 (7): 560- 569.
SHI Z X, MA Y R, ZHANG Y, et al. Overview of threat intelligence standards[J]. Journal of Information Security Research, 2019, 5 (7): 560- 569.
|
| 21 |
USSATH M, JAEGER D, CHENG F, et al. Pushing the limits of cyber threat intelligence:extending STIX to support complex patterns[C]//Information Technology:New Generations:13th International Conference on Information Technology,April, 2016,Las Vegas,NV USA.Berlin:Springer,2016:213-225.
|
| 22 |
RAMSDALE A, SHIAELES S, KOLOKOTRONIS N. A comparative analysis of cyber-threat intelligence sources, formats and languages[J]. Electronics, 2020, 9 (5): 824.
|
| 23 |
The MITRE Corporation. Cyber information-sharing models:an overview by MITRE[EB/OL]. (2024-02-25) [2024-03-01]. https://www.mitre.org/sites/default/files/pdf/cyber_info_sharing.pdf.
|
| 24 |
CISA. Automated Indicator Sharing (AIS)[EB/OL]. (2024-01-13)[2024-03-08]. https://www.cisa.gov/topics/cyber-threats-and-advisories/information-sharing/automated-indicator-sharing-ais.
|
| 25 |
MISP. MISP threat sharing[EB/OL]. (2024-02-15) [2024-03-08]. https://www.misp-project.org/.
|
| 26 |
STOJKOVSKI B. What’ s in a cyber threat intelligence sharing platform? a mixed-methods user experience investigation of MISP[C]//Annual Computer Security Applications Conference,December 5-9, 2022,Austin, TX. New York:ACM,2021:385-398.
|
| 27 |
Filigran. OpenCTI [EB/OL]. (2024-02-20) [2024-03-10]. https://docs.opencti.io/latest/.
|
| 28 |
CRITs. CRITs-collaborative research into threats [EB/OL]. (2024-03-01) [2024-03-10]. https://github.com/crits/crits.
|
| 29 |
DAVIS K. LookingGlass introduces Open Threat Partner eXchange (OpenTPX) to foster enhanced exchange of network security intelligence [EB/OL]. (2024-02-16)[2024-03-10]. https://www.businesswire.com/news/home/20151020005120/en/LookingGlass-Introduces-Open-Threat-Partner-eXchange-OpenTPX-to-Foster-Enhanced-Exchange-of-Network-Security-Intelligence.
|
| 30 |
RAINS T. Microsoft Interflow:a new security and threat information exchange platform [EB/OL]. (2024-02-01)[2024-03-10]. https://www.microsoft.com/en-us/security/blog/2014/06/23/microsoft-interflow-a-new-security-and-threat-information-exchange-platform/.
|
| 31 |
Meta. Get started with ThreatExchange [EB/OL]. (2024-03-02)[2024-03-11]. https://developers.facebook.com/docs/threat-exchange/getting-started/.
|
| 32 |
IBM. IBM Security X-Force Threat Intelligence [EB/OL]. (2024-02-09) [2024-03-11]. https://www.ibm.com/cn-zh/products/xforce-exchange.
|
| 33 |
NAKAMOTO S. Bitcoin: a peer-to-peer electronic cash system[J]. SSRN Electronic Journal, 2008, 4 (2): 15.
|
| 34 |
Wikipedia. Proof of work[EB/OL]. (2024-01-14) [2024-03-13]. https://en.wikipedia.org/wiki/Proof_of_work.
|
| 35 |
McKinsey. What is proof of stake (PoS) [EB/OL]. (2024-01-21) [2024-03-13]. https://www.mckinsey.com/featured-insights/mckinsey-explainers/what-is-proof-of-stake.
|
| 36 |
MUKHERJEE P,PRADHAN C. Blockchain 1.0 to blockchain 4.0—the evolutionary transformation of blockchain technology[M]//Blockchain Technology:Applications and Challenges. Cham:Springer International Publishing,2021:29-49.
|
| 37 |
GRAF R, KING R. Neural network and blockchain based technique for cyber threat intelligence and situational awareness[C]//2018 10th International Conference on Cyber Conflict (CyCon),May 29-June 1,2018,Estonia. New York: IEEE,2018:409-426.
|
| 38 |
WU Y,QIAO Y,YE Y,et al. Towards improved trust in threat intelligence sharing using blockchain and trusted com puting[C]//2019 6th International Conference on Internet of Things:Systems,Management and Security (IOTSMS),October 22-25, 2019,Granada,Spain. New York:IEEE,2019:474-481.
|
| 39 |
HOMAN D,SHIEL I,THORPE C. A new network model for cyber threat intelligence sharing using blockchain technology[C]//2019 10th IFIP International Conference on New Technologies,Mobility and Security (NTMS). IEEE,2019:1-6.
|
| 40 |
Traffic light protocol (TLP) [EB/OL]. (2023-12-12) [2024-03-13]. https://www.first.org/tlp/.
|
| 41 |
XUAN S,TANG H,WANG W,et al. Application of block chain technology in constructing network threat intelligence system[C]//Proceedings of the 2020 2nd International Conference on Blockchain Technology. ACM,2020:144-149.
|
| 42 |
Wikipedia. InterPlanetary File System [EB/OL]. (2024-01-23)[2024-03-14]. https://en.wikipedia.org/wiki/InterPlanetary_File_System.
|
| 43 |
GONG S,LEE C. BLOCIS:blockchain-based cyber threat intelligence sharing framework for sybil-resistance[J]. Electronics,2020,9(3):521.
|
| 44 |
Wikipedia. Sybil attack [EB/OL]. (2024-02-20)[2024-03-14]. https://en.wikipedia.org/wiki/Sybil_attack.
|
| 45 |
CHA J,SINGH S K,PAN Y,et al. Blockchain-based cyber threat intelligence system architecture for sustainable computing[J]. Sustainability,2020:6401.
|
| 46 |
PREUVENEERS D,JOOSEN W,BERNAL J,et al. Distributed security framework for reliable threat intelligence sharing[J]. Security and Communication Networks,2020,2020:1-15.
|
| 47 |
BADSHA S,VAKILINIA I,SENGUPTA S. BloCyNfo-Share:blockchain based cybersecurity information sharing with fine grained access control[C]//2020 10th Annual Computing and Communication Workshop and Conference (CCWC). IEEE,2020:317-323.
|
| 48 |
PUROHIT S,CALYAM P,WANG S,et al. DefenseChain:consortium blockchain for cyber threat intelligence sharing and defense[C]//2020 2nd Conference on Blockchain Research & Applications for Innovative Networks and Services (BRAINS). IEEE,2020:112-129.
|
| 49 |
MENGES F, PUTZ B, PERNUL G. DEALER: decentralized incentives for threat intelligence reporting and exchange[J]. International Journal of Information Security, 2021, 20 (5): 741- 761.
|
| 50 |
CHATZIAMANETOGLOU D,RANTOS K. CTI blockchain-based sharing using proof-of-quality consensus algorithm[C]//2021 IEEE International Conference on Cyber Security and Resilience (CSR). IEEE,2021:331-336.
|
| 51 |
ALI H,PAPADOPOULOS P,AHMAD J,et al. Privacy-preserving and trusted threat intelligence sharing using distributed ledgers[C]//2021 14th International Conference on Security of Information and Networks (SIN). IEEE,2021:1-6.
|
| 52 |
HUFF P,LI Q. A distributed ledger for non-attributable cyber threat intelligence exchange[C]//Security and Privacy in Communication Networks:17th EAI International Conference,SecureComm. 2021:164-184.
|
| 53 |
ALLOUCHE Y,TAPAS N,LONGO F,et al. TRADE:trusted anonymous data exchange:threat sharing using blockchain technology[EB]. arXiv preprint arXiv:2103. 13158,2021.
|
| 54 |
SARHAN M, LO W, LAYEGHY S, et al. HBFL: a hierarchical blockchain-based federated learning framework for a collaborative iot intrusion detection[J]. Computers and Electrical Engineering, 2022, 103, 108379.
|
| 55 |
DUNNETT K,PAL S,PUTRA G,et al. A trusted,verifiable and differential cyber threat intelligence sharing framework using blockchain[C]//2022 IEEE International Conference on Trust,Security and Privacy in Computing and Communications (TrustCom). IEEE,2022:1107-1114.
|
| 56 |
SHI H,WANG W,LIU L,et al. Threat intelligence sharing model and profit distribution based on blockchain and smart contracts[C]//11th International Conference on Computer Engineering and Networks,Lecture Notes in Electrical Engineering. 2022:645-654.
|
| 57 |
ALI H, AHMAD J, JAROUCHEH Z, et al. Trusted threat intelligence sharing in practice and performance benchmarking through the hyperledger fabric platform[J]. Entropy, 2022, 24 (10): 1379.
|
| 58 |
DUY P T,QUYEN N H,KHOA N H,et al. FedChain-Hunter:a reliable and privacy-preserving aggregation for federated threat hunting framework in SDN-based IIoT[J]. Internet of Things,2023(24):100966.
|
| 59 |
HOSEN A S M S, SHARMA P K, PUTHAL D, et al. SECBlock-IIoT: a secure blockchain-enabled edge computing framework for industrial internet of things[C]//Proceedings of the 3rd International Symposium on Advanced Security on Software and Systems. New York:ACM,2023:1-14.
|
| 60 |
DUNNETT K,PAL S,JADIDI Z,et al. A blockchain-based framework for scalable and trustless delegation of cyber threat intelligence[C]//2023 IEEE International Conference on Blockchain and Cryptocurrency (ICBC). IEEE,2023:1-9.
|
| 61 |
DHIFALLAH W, MOULAHI T, TARHOUNI M, et al. Intellig_block: enhancing IoT security with blockchain-based adversarial machine learning protection[J]. International Journal of Advanced Technology and Engineering Exploration, 2023, 10 (106): 1167.
|
| 62 |
MA X, YU D, DU Y, et al. A blockchain-based incentive mechanism for sharing cyber threat intelligence[J]. Electronics, 2023, 12 (11): 2454.
|
| 63 |
AL-SHARU W N, QABALIN M K, NASER M, et al. A secure framework for blockchain transactions protection[J]. Computer System Science Engineering, 2023, 45 (2): 1095- 111.
|
| 64 |
IANNACONE M ,BOHN S ,NAKAMURA G ,et al. Developing an ontology for cyber security knowledge graphs[C]//10th Annual Cyber and Information Security Research Conference. ACM,2015:1-4.
|
| 65 |
SYED Z,PADIA A,FININ T,et al. UCO:a unified cybersecurity ontology[C]// Workshops at the 13th AAAI Conference on Artificial Intelligence. ACM,2016:1-8.
|
| 66 |
NOEL S,HARLEY E,TAM K H,et al. CyGraph:graphbased analytics and visualization for cybersecurity[M]//Hand book of Statistics.Amsterdam:Amsterdam:Elsevier,2016.
|
| 67 |
HEMBERG E,KELLY J,SHLAPENTOKH-ROTHMAN M,et al. Linking threat tactics,techniques,and patterns with defensive weaknesses,vulnerabilities and affected platform configurations for cyber hunting[EB]. arXiv preprint arXiv:2010. 00533,2020.
|
| 68 |
ZHAO Y,LANG B,LIU M. Ontology-based unified model for heterogeneous threat intelligence integration and sharing[C]//2017 11th IEEE International Conference on Anti-counterfeiting,Security,and Identification (ASID). IEEE,2017:11-15.
|
| 69 |
黄克振,连一峰,冯登国,等. 一种基于图模型的网络攻击溯源方法[J]. 软件学报,2021,33(2):683-698.
HUANG K Z,LIAN Y F,FENG D G,et al. Method of cyber attack attribution based on graph model[J]. Journal of Software,2021,33(2):683-698.
|
| 70 |
REN Y, XIAO Y, ZHOU Y, et al. CSKG4APT: a cybersecurity knowledge graph for advanced persistent threat organization attribution[J]. IEEE Transactions on Knowledge and Data Engineering, 2022, 35 (6): 5695- 5709.
|
| 71 |
MARTINS C, MEDEIROS I. Generating quality threat intelligence leveraging OSINT and a cyber threat unified taxonomy[J]. ACM Transactions on Privacy and Security, 2022, 25 (3): 1- 39.
|
| 72 |
GUO Y, LIU Z, HUANG C, et al. A framework for threat intelligence extraction and fusion[J]. Computers & Security, 2023, 132, 103371.
|
| 73 |
GRÉGIO A,BONACIN R,NABUCO O,et al. Ontology for malware behavior:a core model proposal[C]//2014 IEEE 23rd International WETICE Conference. IEEE,2014:453-458.
|
| 74 |
RASTOGI N,DUTTA S,ZAKI M J,et al. MALOnt:an ontology for malware threat intelligence[C]//International Workshop on Deployable Machine Learning for Security Defense. Springer International Publishing,2020:28-44.
|
| 75 |
DING Y, WU R, ZHANG X. Ontology-based knowledge representation for malware individuals and families[J]. Computers & Security, 2019, 87, 101574.
|
| 76 |
HAN W, XUE J, WANG Y, et al. APTMalInsight: identify and cognize APT malware based on system call information and ontology knowledge framework[J]. Information Sciences, 2021, 546, 633- 664.
|
| 77 |
HUANG H D,CHUANG T Y,TSAI Y L,et al. Ontology-based intelligent system for malware behavioral analysis[C]//International Conference on Fuzzy Systems. IEEE,2010:1-6.
|
| 78 |
KOKAR M M, MATHEUS C J, BACLAWSKI K. Ontology-based situation awareness[J]. Information Fusion, 2009, 10 (1): 83- 98.
|
| 79 |
BAUMGARTNER N, GOTTESHEIM W, MITSCH S, et al. BeAware!—situation awareness, the ontology-driven way[J]. Data & Knowledge Engineering, 2010, 69 (11): 1181- 1193.
|
| 80 |
PAI F P, YANG L J, CHUNG Y C. Multi-layer ontology based information fusion for situation awareness[J]. Applied Intelligence, 2017, 46, 285- 307.
|
| 81 |
KIM J, KONG J, SOHN M, et al. Layered ontology-based multi-sourced information integration for situation awareness[J]. The Journal of Supercomputing, 2021, 77, 9780- 9809.
|
| 82 |
MOHSIN M,ANWAR Z. Where to kill the cyber kill-chain:an ontology-driven framework for IOT security analytics[C]//2016 International Conference on Frontiers of Information Technology (FIT). IEEE,2016:23-28.
|
| 83 |
CHOI C, CHOI J. Ontology-based security context reasoning for power IoT-cloud security service[J]. IEEE Access, 2019, 7, 110510- 110517.
|
| 84 |
GONZALEZ-GIL P, MARTINEZ J A, SKARMETA A F. Lightweight data-security ontology for IoT[J]. Sensors, 2020, 20 (3): 801.
|
| 85 |
ZHANG S, BAI G, LI H, et al. Multi-source knowledge reasoning for data-driven IoT security[J]. Sensors, 2021, 21 (22): 7579.
|
| 86 |
YEBOAH-OFORI A,MOURATIDIS H,ISMAI U,et al. Cyber supply chain threat analysis and prediction using machine learning and ontology[C]//Artificial Intelligence Applications and Innovations:17th IFIP WG 12.5 International Conference,AIAI. Springer International Publishing,2021:518-530.
|
| 87 |
MOZZAQUATRO B A, AGOSTINHO C, GONCALVES D, et al. An ontology-based cybersecurity framework for the internet of things[J]. Sensors, 2018, 18 (9): 3053.
|
| 88 |
NVD. National vulnerability database [EB/OL]. (2024-02-28)[2024-03-03]. https://nvd.nist.gov/vuln.
|
| 89 |
CHEIKES B A,CHEIKES B A,KENT K A,et al. Common platform enumeration:naming specification version 2.3[M]. Gaithersburg,MD:US Department of Commerce,National Institute of Standards and Technology,2011.
|
| 90 |
The MITRE Corporation. Common attack pattern enumerations and classifications [EB/OL]. (2024-02-25) [2024-03-03]. https://capec.mitre.org/.
|
| 91 |
The MITRE Corporation. Adversarial tactics techniques and common knowledge [EB/OL]. (2024-02-27) [2024-03-03]. https://attack.mitre.org/.
|
| 92 |
MODI A,SUN Z,PANWAR A,et al. Towards automated threat intelligence fusion[C]//2016 IEEE 2nd International Conference on Collaboration and Internet Computing (CIC). IEEE,2016:408-416.
|
| 93 |
AZEVEDO R,MEDEIROS I,BESSANI A. PURE:generating quality threat intelligence by clustering and correlating OSINT[C]//2019 18th IEEE International Conference on Trust,Security and Privacy in Computing and Communications/13th IEEE International Conference on Big Data Science and Engineering (TrustCom/BigDataSE). IEEE,2019:483-490.
|
| 94 |
FAIELLA M,GRANADILLO G G,MEDEIROS I,et al. Enriching threat intelligence platforms capabilities[C]//16th International Joint Conference on e-Business and Telecommunications. IEEE,2019:37-48.
|
| 95 |
GONZÁLEZ-GRANADILLO G, FAIELLA M, MEDEIROS I, et al. ETIP: an enriched threat intelligence platform for improving OSINT correlation, analysis, visualization and sharing capabilities[J]. Journal of Information Security and Applications, 2021, 58, 102715.
|
| 96 |
ALVES F, BETTINI A, FERREIRA P M, et al. Processing tweets for cybersecurity threat awareness[J]. Information Systems, 2021, 95, 101586.
|
| 97 |
YASMEEN A,ULLAH K K,MUHAMMADA. HDA-TIP:a framework for heterogeneous data aggregation for threat intelligence platform[C]//2023 17th International Conference on Ubiquitous Information Management and Communication (IMCOM). IEEE,2023:1-7.
|
| 98 |
ZANG X, GONG J, ZHANG X, et al. Attack scenario reconstruction via fusing heterogeneous threat intelligence[J]. Computers & Security, 2023, 133, 103420.
|
| 99 |
ZHAO J,YAN Q,LIU X,et al. Cyber threat intelligence modeling based on heterogeneous graph convolutional network[C]//23rd International Symposium on Research in Attacks,Intrusions and Defenses (RAID 2020). 2020:241-256.
|
| 100 |
GAO Y, LI X, PENG H, et al. HinCTI: a cyber threat intelligence modeling and identification system based on heterogeneous information network[J]. IEEE Transactions on Knowledge and Data Engineering, 2020, 34 (2): 708- 722.
|
| 101 |
LIU L,CHEN C,PEI Q,et al. Vehicular edge computing and networking:a survey[J]. Mobile Networks and Applications,2021(26):1145-1168.
|
| 102 |
MEIER R,SCHERRER C,GUGELMANN D,et al. FeedRank:a tamper-resistant method for the ranking of cyber threat intelligence feeds[C]//2018 10th International Conference on Cyber Conflict (CyCon). IEEE,2018:321-344.
|
| 103 |
FRANCESCHET M. PageRank: standing on the shoulders of giants[J]. Communications of the ACM, 2011, 54 (6): 92- 101.
|
/
| 〈 |
|
〉 |