错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

An Empirical Evaluation of Cyber Threat Intelligence Sharing in the ECHO Early Warning System

  • Ioannis Chalkias,
  • Cagatay Yucel,
  • Dimitrios Mallis,
  • Jyri Rajamaki,
  • Fabrizio De Vecchis,
  • Peter Hagstrom,
  • Vasilis Katos

摘要

This paper reports on the information sharing practices of cyber competency centres representing different sectors and constituencies. The cyber competency centres participated in the form of CSIRTs employed the ECHO Early Warning System. Through a structured tabletop exercise, over 10 CSIRTS were engaged and a number of features were captured and monitored. A key research question was to determine the factors that can potentially hinder or amplify Cyber Threat Intelligence information sharing. The exercise imitated real attack scenarios using state-of-the-art tactics techniques and procedures as observed by real-world APT groups and daily incidents. The findings revealed differences in terms of timeliness, response time and handling tickets with different Traffic Light Protocol classifications, duration of handling a ticket and intention to disclose.