首页> 外文会议>IEEE International Conference on Anti-counterfeiting, Security, and Identification >Ontology-based unified model for heterogeneous threat intelligence integration and sharing
【24h】

Ontology-based unified model for heterogeneous threat intelligence integration and sharing

机译:基于本体的异构威胁情报集成与共享统一模型

获取原文

摘要

Threat intelligence contains valuable information for cyber security; however, usually the intelligence is from multiple sources and is described with different data formats and schemas, which not only leads to the inefficiency of intelligence integration and analysis, but also makes threat intelligence sharing difficult. Therefore, the unified representation of the threat intelligence becomes a crucial challenge. This paper presents an ontology-based unified model for describing the multi-source and heterogeneous threat intelligence. In our model, we first propose the cyber security ontology and the unified model. Hence, the threat intelligence from different sources can be mapped to our unified model to achieve unified representation, which makes threat intelligence sharing and analysis more efficient. Furthermore, we propose and implement an intelligence integration framework based on our unified intelligence model and the open source intelligence collection tool IntelMQ. The feasibility and effectiveness of our model is verified by the performance of this framework.
机译:威胁情报包含有关网络安全的宝贵信息;但是,情报通常来自多个来源,并以不同的数据格式和架构进行描述,这不仅导致情报集成和分析效率低下,而且使威胁情报共享变得困难。因此,威胁情报的统一表示成为一项严峻的挑战。本文提出了一种基于本体的统一模型,用于描述多源异构异构威胁情报。在我们的模型中,我们首先提出了网络安全本体和统一模型。因此,可以将来自不同来源的威胁情报映射到我们的统一模型以实现统一表示,这使得威胁情报共享和分析更加有效。此外,我们基于统一的情报模型和开源情报收集工具IntelMQ提出并实现了情报集成框架。该框架的性能验证了我们模型的可行性和有效性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号