Follow the Blue Bird: A Study on Threat Data Published on Twitter


연구 분야: Strategies



학회: European Symposium on Research in Computer Security


초록

Open Source Intelligence (OSINT) has taken the interest of cybersecurity practitioners due to its completeness and timeliness. In particular, Twitter has proven to be a discussion hub regarding the latest vulnerabilities and exploits. In this paper, we present a study comparing vulnerability databases between themselves and against Twitter. Although there is evidence of OSINT advantages, no methodological studies have addressed the quality and benefits of the sources available. We compare the publishing dates of more than nine-thousand vulnerabilities in the sources considered. We show that NVD is not the most timely or the most complete vulnerability database, that Twitter provides timely and impactful security alerts, that using diverse OSINT sources provides better completeness and timeliness of vulnerabilities, and provide insights on how to capture cybersecurity-relevant tweets.


Author Profile
Fernando Alves

LASIGE Faculdade de Ciências Universidade de Lisboa Lisbon Portugal

Germany
Author Profile
Ambrose Andongabo

Centre for Software Reliability City University of London London UK

정보 없음
Author Profile
Ilir Gashi

Centre for Software Reliability City University of London London UK

정보 없음

📄 논문 정보

발행 연도 2020년
인용수 0
출판 국가 Germany
사이트 Springer
좋아요 수 0

연관 논문 목록 (373건)