Strategic Cyber Threat Intelligence Sharing: A Case Study of IDS Logs

Spike E Dog, Alex Tweed, LeRoy Rouse, Bill Chu, Qi Duan, Yueqi Hu, Jing Yang, Ehab S. Al-Shaer · 2016

Cyber threat intelligence sharing is emerging as an important tool for network security as it can identify evolving threat patterns and prevent attackers from replicating their early success across the Internet. However the types of information sharing being practiced today are at the tactical level focusing on specific attacks, e.g. characteristics of a piece of malware, and black listed IP addresses and domains. In this paper we argue sharing cyber intelligence at a more strategic level is needed. By strategic information we mean information about salient common features of groups of attacks and attackers. Strategic information allows us to take actions that are much closer to the source of the attacks. For example instead of block an IP address as opposed to shutting down the botnet. We propose at set of strategic cyber threat indicators and show how they can be derived using an IDS log from a large commercial enterprise.

Read the paper · More papers on PaperTik