Abstract:
“In recent years, the field of Cyber Threat Intelligence (CTI) has undergone rapid development, primarily due to the emergence of various organizations and platforms dedi...Show MoreMetadata
Abstract:
“In recent years, the field of Cyber Threat Intelligence (CTI) has undergone rapid development, primarily due to the emergence of various organizations and platforms dedicated to threat intelligence. Through automated analysis and real-time information sharing, companies can now more effectively identify and manage the risks associated with cyber threats and attacks. One of the most commonly used types of threat data is Indicators of Compromise (IOCs), which play a crucial role in early cyber intrusion detection and prevention. However, the quality of the collected data is often limited, and the sheer volume of real-time data can overwhelm security analysts, leading to IOC data fatigue. To address this challenge, a new scoring mechanism called FOCUS has been proposed. FOCUS utilizes various attributes and relationships provided by the VirusTotal online scanning engine analysis results to prioritize a set of IOCs. By concentrating on properly analyzed and ranked IOCs from a vast dataset, FOCUS can assist organizations in allocating resources and efforts more effectively. Ultimately, FOCUS can enhance the accuracy and efficiency of IOC analysis, strengthening an organization's ability to respond to cybersecurity threats.
Date of Conference: 14-17 November 2023
Date Added to IEEE Xplore: 25 December 2023
ISBN Information:
ISSN Information:
Conference Location: Abu Dhabi, United Arab Emirates