作者
Mohammed Almukaynizi, Ericsson Marin, Eric Nunes, Paulo Shakarian, Gerardo I Simari, Dipsy Kapoor, Timothy Siedlecki
发表日期
2018/11/9
研讨会论文
2018 IEEE International Conference on Intelligence and Security Informatics (ISI)
页码范围
31-36
出版商
IEEE
简介
Recent incidents of data breaches call for organizations to proactively identify cyber attacks on their systems. Darkweb/Deepweb (D2web) forums and marketplaces provide environments where hackers anonymously discuss existing vulnerabilities and commercialize malicious software to exploit those vulnerabilities. These platforms offer security practitioners a threat intelligence environment that allows to mine for patterns related to organization-targeted cyber attacks. In this paper, we describe a system (called DARKMENTION) that learns association rules correlating indicators of attacks from D2web to real-world cyber incidents. Using the learned rules, DARKMENTION generates and submits warnings to a Security Operations Center (SOC) prior to attacks. Our goal was to design a system that automatically generates enterprise-targeted warnings that are timely, actionable, accurate, and transparent. We show that …
引用总数
20182019202020212022202320242577642
学术搜索中的文章
M Almukaynizi, E Marin, E Nunes, P Shakarian… - 2018 IEEE International Conference on Intelligence …, 2018