Visible to the public Data Quality Challenges and Future Research Directions in Threat Intelligence Sharing Practice

TitleData Quality Challenges and Future Research Directions in Threat Intelligence Sharing Practice
Publication TypeConference Paper
Year of Publication2016
AuthorsSillaber, Christian, Sauerwein, Clemens, Mussmann, Andrea, Breu, Ruth
Conference NameProceedings of the 2016 ACM on Workshop on Information Sharing and Collaborative Security
Date PublishedOctober 2016
PublisherACM
Conference LocationNew York, NY, USA
ISBN Number978-1-4503-4565-1
Keywordscomposability, compositionality, Computational Intelligence, cryptography, cyber security operations center, data quality challenges, expert systems, human factors, privacy, pubcrawl, Scalability, threat intelligence data, threat intelligence sharing data quality
Abstract

In the last couple of years, organizations have demonstrated an increased willingness to participate in threat intelligence sharing platforms. The open exchange of information and knowledge regarding threats, vulnerabilities, incidents and mitigation strategies results from the organizations' growing need to protect against today's sophisticated cyber attacks. To investigate data quality challenges that might arise in threat intelligence sharing, we conducted focus group discussions with ten expert stakeholders from security operations centers of various globally operating organizations. The study addresses several factors affecting shared threat intelligence data quality at multiple levels, including collecting, processing, sharing and storing data. As expected, the study finds that the main factors that affect shared threat intelligence data stem from the limitations and complexities associated with integrating and consolidating shared threat intelligence from different sources while ensuring the data's usefulness for an inhomogeneous group of participants.Data quality is extremely important for shared threat intelligence. As our study has shown, there are no fundamentally new data quality issues in threat intelligence sharing. However, as threat intelligence sharing is an emerging domain and a large number of threat intelligence sharing tools are currently being rushed to market, several data quality issues - particularly related to scalability and data source integration - deserve particular attention.

URLhttps://dl.acm.org/doi/10.1145/2994539.2994546
DOI10.1145/2994539.2994546
Citation Keysillaber_data_2016