Mining Attributed Graphs for Threat Intelligence

Hugo Gascón, Bernd Grobauer, Thomas Schreck, Lukas Rist, Daniel J. Arp, Konrad Rieck · 2017

Understanding and fending off attack campaigns against organizations, companies and individuals, has become a global struggle. As today's threat actors become more determined and organized, isolated efforts to detect and reveal threats are no longer effective. Although challenging, this situation can be significantly changed if information about security incidents is collected, shared and analyzed across organizations. To this end, different exchange data formats such as STIX, CyBOX, or IODEF have been recently proposed and numerous CERTs are adopting these threat intelligence standards to share tactical and technical threat insights. However, managing, analyzing and correlating the vast amount of data available from different sources to identify relevant attack patterns still remains an open problem.

Read the paper · More papers on PaperTik