Enterprise Intranet Threat Intelligence Processing Framework Based on Open Source Community
Wenjing Zeng, Peng Lu, Hao Wang, Fang Lou · 2023
Network attack tactics, techniques, procedures, and IOC are being updated more and more rapidly. Defenders need to obtain such threat intelligence in a timely manner, to identify whether the enterprise intranet is under attack, and take corresponding protective measures. Before the official disclosure of the details of the attack, the open source community often already has users in the discussion of the attack, if we can extract threat intelligence that strong related to the enterprise from the open source community in a timely manner. It will be a great help in monitoring the enterprise intranet. However, new posts are published every day in the open source community, and some of the posts may have nothing to do with network security, and the threat intelligence disclosed in the posts may not be useful to the enterprise intranet. To bridge the gap, we propose EITIP, a framework for automated enterprise intranet threat intelligence processing. EITIP automatically collects new posts from open source community, classifies posts related to cyber security, obtains effective threat intelligence, and keep it updated. To address multiple challenges, EITIP provides: (1) effective threat entities, which can help obtain richer threat intelligence. (2) a method for obtaining strongly correlated threat intelligence on an enterprise intranet. (3) a complete threat intelligence processing framework.