Data Quality Challenges and Future Research Directions in Threat Intelligence Sharing Practice
Title | Data Quality Challenges and Future Research Directions in Threat Intelligence Sharing Practice |
Publication Type | Conference Paper |
Year of Publication | 2016 |
Authors | Sillaber, Christian, Sauerwein, Clemens, Mussmann, Andrea, Breu, Ruth |
Conference Name | Proceedings of the 2016 ACM on Workshop on Information Sharing and Collaborative Security |
Date Published | October 2016 |
Publisher | ACM |
Conference Location | New York, NY, USA |
ISBN Number | 978-1-4503-4565-1 |
Keywords | composability, compositionality, Computational Intelligence, cryptography, cyber security operations center, data quality challenges, expert systems, human factors, privacy, pubcrawl, Scalability, threat intelligence data, threat intelligence sharing data quality |
Abstract | In the last couple of years, organizations have demonstrated an increased willingness to participate in threat intelligence sharing platforms. The open exchange of information and knowledge regarding threats, vulnerabilities, incidents and mitigation strategies results from the organizations' growing need to protect against today's sophisticated cyber attacks. To investigate data quality challenges that might arise in threat intelligence sharing, we conducted focus group discussions with ten expert stakeholders from security operations centers of various globally operating organizations. The study addresses several factors affecting shared threat intelligence data quality at multiple levels, including collecting, processing, sharing and storing data. As expected, the study finds that the main factors that affect shared threat intelligence data stem from the limitations and complexities associated with integrating and consolidating shared threat intelligence from different sources while ensuring the data's usefulness for an inhomogeneous group of participants.Data quality is extremely important for shared threat intelligence. As our study has shown, there are no fundamentally new data quality issues in threat intelligence sharing. However, as threat intelligence sharing is an emerging domain and a large number of threat intelligence sharing tools are currently being rushed to market, several data quality issues - particularly related to scalability and data source integration - deserve particular attention. |
URL | https://dl.acm.org/doi/10.1145/2994539.2994546 |
DOI | 10.1145/2994539.2994546 |
Citation Key | sillaber_data_2016 |