Leveraging Semantic Relationships to Prioritise Indicators of Compromise in Additive Manufacturing Systems

Mahender Kumar, G. Epiphaniou, C. Maple
{"title":"Leveraging Semantic Relationships to Prioritise Indicators of Compromise in Additive Manufacturing Systems","authors":"Mahender Kumar, G. Epiphaniou, C. Maple","doi":"10.48550/arXiv.2305.04102","DOIUrl":null,"url":null,"abstract":"Additive manufacturing (AM) offers numerous benefits, such as manufacturing complex and customised designs quickly and cost-effectively, reducing material waste, and enabling on-demand production. However, several security challenges are associated with AM, making it increasingly attractive to attackers ranging from individual hackers to organised criminal gangs and nation-state actors. This paper addresses the cyber risk in AM to attackers by proposing a novel semantic-based threat prioritisation system for identifying, extracting and ranking indicators of compromise (IOC). The system leverages the heterogeneous information networks (HINs) that automatically extract high-level IOCs from multi-source threat text and identifies semantic relations among the IOCs. It models IOCs with a HIN comprising different meta-paths and meta-graphs to depict semantic relations among diverse IOCs. We introduce a domain-specific recogniser that identifies IOCs in three domains: organisation-specific, regional source-specific, and regional target-specific. A threat assessment uses similarity measures based on meta-paths and meta-graphs to assess semantic relations among IOCs. It prioritises IOCs by measuring their severity based on the frequency of attacks, IOC lifetime, and exploited vulnerabilities in each domain.","PeriodicalId":406001,"journal":{"name":"ACNS Workshops","volume":"11 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2023-05-06","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"ACNS Workshops","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.48550/arXiv.2305.04102","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

Additive manufacturing (AM) offers numerous benefits, such as manufacturing complex and customised designs quickly and cost-effectively, reducing material waste, and enabling on-demand production. However, several security challenges are associated with AM, making it increasingly attractive to attackers ranging from individual hackers to organised criminal gangs and nation-state actors. This paper addresses the cyber risk in AM to attackers by proposing a novel semantic-based threat prioritisation system for identifying, extracting and ranking indicators of compromise (IOC). The system leverages the heterogeneous information networks (HINs) that automatically extract high-level IOCs from multi-source threat text and identifies semantic relations among the IOCs. It models IOCs with a HIN comprising different meta-paths and meta-graphs to depict semantic relations among diverse IOCs. We introduce a domain-specific recogniser that identifies IOCs in three domains: organisation-specific, regional source-specific, and regional target-specific. A threat assessment uses similarity measures based on meta-paths and meta-graphs to assess semantic relations among IOCs. It prioritises IOCs by measuring their severity based on the frequency of attacks, IOC lifetime, and exploited vulnerabilities in each domain.
利用语义关系对增材制造系统中的损害指标进行优先排序
增材制造(AM)提供了许多好处,例如快速且经济高效地制造复杂的定制设计,减少材料浪费,并实现按需生产。然而,与AM相关的一些安全挑战使其对从个人黑客到有组织犯罪团伙和民族国家行为者的攻击者越来越有吸引力。本文通过提出一种新的基于语义的威胁优先级系统来识别,提取和排名妥协指标(IOC),从而解决了AM对攻击者的网络风险。该系统利用异构信息网络(HINs)从多源威胁文本中自动提取高级ioc,并识别ioc之间的语义关系。它使用包含不同元路径和元图的HIN对ioc进行建模,以描述不同ioc之间的语义关系。我们引入了一个特定于领域的识别器,用于识别三个领域中的ioc:特定于组织、特定于区域源和特定于区域目标。威胁评估使用基于元路径和元图的相似性度量来评估ioc之间的语义关系。它根据攻击频率、IOC生命周期和每个域中被利用的漏洞来衡量IOC的严重程度,从而对IOC进行优先级排序。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信