Automated Structured Threat Information Expression (STIX) Document Generation with Privacy Preservation

Farhan Sadique, Sui Cheung, Iman Vakilinia, Shahriar Badsha, Shamik Sengupta · 2018

The traditional approach to cybersecurity is struggling to defend against modern, dynamic and rapidly evolving cyber-attacks. Automated generation of cyber-threat intelligence (CTI) along with effective and real-time sharing of the CTI is required by organizations to prevent major cyber-attacks. It is nearly impossible to achieve comparable defense individually without cybersecurity information sharing. The first step towards this end is to collect cyber threat data and to represent that data in a standardized format. There is plenty of raw cyber threat data available to organizations in the form of firewall logs, malware signatures, spam emails, etc. However, the automated conversion of these data into a standard format has not been studied before. In this paper, we introduce a novel, privacy-preserving, mechanism to represent raw cyber threat-data in Structured Threat Information Expression (STIX) format in an automated manner. A complexity analysis shows that this process is suitable for large-scale deployments. This general guideline can be followed to represent all types of threat data in a standardized format. This will help the security administrators get a broad picture of the threat landscape and enable them to share these data with a cybersecurity information sharing platform for advanced analytics.

Read the paper · More papers on PaperTik