On the Integration of Course of Action Playbooks into Shareable Cyber Threat Intelligence


연구 분야: Safety



학회: 2021 IEEE International Conference on Big Data (Big Data)


초록

Motivated by the introduction of CACAO, the first open standard that harmonizes the way we document courses of action in a machine-readable format for interoperability, and the benefits for cybersecurity operations derived from utilizing, and coupling and sharing course of action playbooks with cyber threat intelligence, we introduce a uniform metadata template that supports managing and integrating course of action playbooks into knowledge representation and knowledge management systems. We demonstrate the applicability of our approach through two use-case implementations. We utilize the playbook metadata template to introduce functionality and integrate course of action playbooks, such as CACAO, into the MISP threat intelligence platform and the OASIS Threat Actor Context ontology.


Author Profile
Vasileios Mavroeidis

University of Oslo Norway

Norway
Author Profile
Pavel Eis

Cesnet Czech Republic

Czech Republic
Author Profile
Martin Zadnik

Cesnet Czech Republic

Czech Republic

📄 논문 정보

발행 연도 2021년
인용수 13
출판 국가 Germany, Norway, United States, Czech Republic
사이트 IEEE
좋아요 수 0

연관 논문 목록 (531건)