Improving Maliciousness Estimation of Indicator of Compromise Using Graph Convolutional Networks

Yuta Kazato, Yoshihide Nakagawa, Yuichi Nakatani · 2020

Cyber threat intelligence (CTI) sharing is growing in popularity and has become one of the key functions to protect end-users and network services from sophisticated cyber attacks. However, since CTI is not always guaranteed to be correct and trustworthy, security operators spend much time in analyzing CTI and estimating the maliciousness of the indicators of compromise (IoCs) in CTI, such as domain names, URLs, and IP addresses. Previous studies did not estimate such maliciousness sufficiently. They did not approach maliciousness estimation by using both types of IoC characteristics; individual IoC features and relations among IoCs. In this paper, we propose a novel method of estimating the maliciousness of IoCs more accurately through a graph convolutional network (GCN)-based approach, which can use both IoC characteristics. We evaluated the performance of the proposed method by comparing it to conventional methods. The proposed method exhibited an 86.3% accuracy rate and 0.883 recall rate, which are better than those from the conventional methods.

Read the paper · More papers on PaperTik