UNI-CERT: A Unified Computer Emergency Response Teams Model for Malware Information Sharing Platform

Eman Aljbour, Abdelnoor Dabit,Mustafa Al-Fayoumi,Qasem Abu Al-Haija

2023 IEEE 5th International Conference on Power, Intelligent Computing and Systems (ICPICS)(2023)

引用 0|浏览1
暂无评分
摘要
Sharing and exchanging information on threats and incidents among Educational institutions is a significant block of the cybersecurity strategy in the Educational sector in Jordan. Usually, this security workflow (receiving Indicators of compromise (IoCs), checking traffic, and blocking harmful traffic) is processed manually. Thus, the workload of the workflow becomes a lot heavier as the number of IoCs increases. In this paper, we propose an automated system for the efficient indicator to store, normalize, correlate, and share IoCs of targeted attacks, threat intelligence, educational fraud information, and vulnerability information handling by combining Trusted Automated Exchange of Indicator Information (TAXII) and Systematic Threat Information Expression (STIX). As the system receives indicators in STIX format, it modifies them and updates network configuration dynamically to block traffic to malicious hosts.
更多
查看译文
关键词
STIX,TAXII,MISP,IOC,CERT
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要