No Time to Choose: Leveraging Internet Scans to Determine IoC Lifetimes
Hugo L. J. Bijmans, M.S.C. van Leuken · 2024
Sharing Indicators of Compromise (IoCs) containing IP addresses used by attackers for command-and-control (C2) through threat intelligence feeds is an everyday practice within the cyber security industry. Once a new IP address is added to a feed, the question arises of when exactly this IP address was under the attacker’s control. Has the attacker been utilizing it for a matter of hours, or has this usage persisted for days? And how long will the attacker maintain control over this IP after being blocklisted? In this work, we delve into the issue of IoC lifetime estimation. We demonstrate and quantify the problems that arise from static retention times, which prompted the introduction of a novel, data-driven technique for C2 IP address lifetime estimation to optimize their retention times, thereby improving the use of threat intelligence in security operations. A combination of datasets conferred historic IP profiles for 1,968 infections associated with four types of malware. Validation through ground truth data labeling revealed a 14 times improvement in false discovery rates compared to a static retention time of 40 days at the expense of a 2.5 times higher false negative rate. We publish our technique and encourage the (scientific) security community to build upon our work to make it more accurate and applicable for real-world use.