首页> 外文期刊>Journal of information security and applications >ETIP: An Enriched Threat Intelligence Platform for improving OSINT correlation, analysis, visualization and sharing capabilities
【24h】

ETIP: An Enriched Threat Intelligence Platform for improving OSINT correlation, analysis, visualization and sharing capabilities

机译:ETIP:一种丰富的威胁情报平台,用于改善overInt相关,分析,可视化和共享能力

获取原文
获取原文并翻译 | 示例
       

摘要

Open Source Intelligence (OSINT) data is collected by publicly available sources to be used by intelligence contexts among which Threat Intelligence Platforms (TIPs) are the main consumers. These platforms help organizations aggregate, correlate, and analyze threat data from multiple sources in real-time to support defensive actions. However, considering the unstructured nature of the collected data, TIPs require the data to be correlated with real-time information coming from the monitored infrastructure, before being further analyzed and shared. This paper presents ETIP, an Enriched Threat Intelligence Platform with extended capabilities in terms of import, quality assessment processes, visualization and information sharing in current TIPs. The platform receives structured cyber threat information from multiple sources and performs the correlation among them with static and dynamic data coming from external sources and the monitored infrastructure. This allows the evaluation of a threat score through heuristic-based analysis, used to enrich the information received from OSINT and other sources. The final result is sent to external entities, such as SIEMs, to be further used for a more in-depth analysis, and to be shared with trusted organizations.
机译:开源智能(OSINT)数据由可被威胁情报平台(提示)所在的智能环境来收集的可公开可用来源,是主要消费者。这些平台在实时帮助组织聚合,关联和分析来自多个来源的威胁数据,以支持防御行动。然而,考虑到收集数据的非结构化性质,在进一步分析和共享之前,提示要求数据与来自受监控基础设施的实时信息相关联。本文介绍了ETIP,一个丰富的威胁情报平台,在当前提示中的进口,质量评估流程,可视化和信息共享方面具有扩展功能。该平台从多个来源接收结构化网络威胁信息,并使用来自外部源和监控基础设施的静态和动态数据进行相关性。这允许通过基于启发式的分析评估威胁评分,用于丰富从索坦和其他来源收到的信息。最终结果被发送到外部实体,例如SIEMS,进一步用于更深入的分析,并与可信组织共享。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号