Cyber-Threat Intelligence from European-wide Sensor Network in SISSDEN

Edgardo Montes de, Jart Armin, Angelo Consoli · River Publishers eBooks · 2022

SISSDEN is a project aimed at improving the cyber security posture of EU entities and end users through development of situational awareness and sharing of actionable information. It builds on the experience of Shadowserver, a non-profit organization well known in the security community for its efforts in mitigation of botnet and malware propagation, free of charge victim notification services, and close collaboration with Law Enforcement Agencies (LEAs), national CERTs, and network providers. The core of SISSDEN is a worldwide sensor network which is deployed and operated by the project consortium. This passive threat data collection mechanism is complemented by behavioural analysis of malware and multiple external data sources. Actionable information produced by SISSDEN provides no-cost victim notification and remediation via organizations such as CERTs, ISPs, hosting providers and LEAs such as EC3. It will benefit SMEs and citizens which do not have the capability to resist threats alone, allowing them to participate in this global effort, and profit from the improved analysis and exchange of security intelligence, to effectively prevent and counter security breaches. The main goal of the project is the creation of multiple high-quality feeds of actionable security information that can be used for remediation purposes and for proactive tightening of computer defences. This is achieved through the development and deployment of a distributed sensor network based on state-of-the-art honeypot and darknet technologies, the creation of a high-throughput data processing centre, and provisioning of in-depth analytics, metrics and reference datasets of the collected data.

Read the paper · More papers on PaperTik