Visible to the public Evaluation and Enhancement of the Actionability of Publicly Available Cyber Threat Information in Digital Forensics

TitleEvaluation and Enhancement of the Actionability of Publicly Available Cyber Threat Information in Digital Forensics
Publication TypeConference Paper
Year of Publication2021
AuthorsDimitriadis, Athanasios, Lontzetidis, Efstratios, Mavridis, Ioannis
Conference Name2021 IEEE International Conference on Cyber Security and Resilience (CSR)
Date Publishedjul
KeywordsActionable Cyber Threat Information, Autopsy, compositionality, Conferences, digital forensics, Electronic mail, Incident Investigation, information forensics, Information Reuse, Object recognition, phishing, pubcrawl, Resiliency, security, STIX, Tools
Abstract

Cyber threat information can be utilized to investigate incidents by leveraging threat-related knowledge from prior incidents with digital forensic techniques and tools. However, the actionability of cyber threat information in digital forensics has not yet been evaluated. Such evaluation is important to ascertain that cyber threat information is as actionable as it can be and to reveal areas of improvement. In this study, a dataset of cyber threat information products was created from well-known cyber threat information sources and its actionability in digital forensics was evaluated. The evaluation results showed a high level of cyber threat information actionability that still needs enhancements in supporting some widely present types of attacks. To further enhance the provision of actionable cyber threat information, the development of the new TREVItoSTIX Autopsy module is presented. TREVItoSTIX allows the expression of the findings of an incident investigation in the structured threat information expression format in order to be easily shared and reused in future digital forensics investigations.

DOI10.1109/CSR51186.2021.9527934
Citation Keydimitriadis_evaluation_2021