Threat intelligence is a cybersecurity discipline that focusses on extracting actionable insights from cybersecurity events. This process involves handling large volumes of heterogeneous data with intricate interconnections between different pieces of data. Complex networks is a branch of science closely related to mathematics that study structures made of large amounts of nodes and their relationships, modeled as edges or hyperedges. The modeling of threat intelligence data using complex networks enables the usage of their properties to extract relevant information that can be used for cybersecurity decision making. In this paper we present a model based on a weighted multiplex hypergraph able to select and prioritize the most relevant adversaries for a given organization based on a set of significant characteristics previously selected. This model can be used to support threat intelligence analysts’ work, by automating the selection of the short list of relevant adversaries to put focus on, and providing objective measures to the analysis process.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Hypergraph-Based Model for Adversary Threat Intelligence Analysis

  • Juan Manuel Matalobos,
  • Regino Criado,
  • Santiago Moral

摘要

Threat intelligence is a cybersecurity discipline that focusses on extracting actionable insights from cybersecurity events. This process involves handling large volumes of heterogeneous data with intricate interconnections between different pieces of data. Complex networks is a branch of science closely related to mathematics that study structures made of large amounts of nodes and their relationships, modeled as edges or hyperedges. The modeling of threat intelligence data using complex networks enables the usage of their properties to extract relevant information that can be used for cybersecurity decision making. In this paper we present a model based on a weighted multiplex hypergraph able to select and prioritize the most relevant adversaries for a given organization based on a set of significant characteristics previously selected. This model can be used to support threat intelligence analysts’ work, by automating the selection of the short list of relevant adversaries to put focus on, and providing objective measures to the analysis process.