{"title":"Analysis of Digital Forensic Artifacts Data Enrichment Mechanism for Cyber Threat Intelligence","authors":"Hyung-Woo Lee","doi":"10.1145/3587828.3587857","DOIUrl":null,"url":null,"abstract":"Cyber attack targeting heterogeneous devices in large-scale network environments through advanced persistent threat (APT) attacks are on the rise. Therefore, in order to improve the effectiveness of the cyber incident response system, it is necessary to apply a data enrichment mechanism for the collected digital forensic artifacts data to reinforce threat analysis and detection performance. Therefore, we designed and implemented the data enrichment mechanism for cyber threat intelligent system by analyzing the existing cyber incident response framework such as SIEM, CTI based on the aggregated digital forensic artifacts. Through this, it is expected to improve the detection performance and effectiveness when using artifact data enrichment process for analyzing cyber incidents collected from heterogeneous devices.","PeriodicalId":340917,"journal":{"name":"Proceedings of the 2023 12th International Conference on Software and Computer Applications","volume":"128 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2023-02-23","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings of the 2023 12th International Conference on Software and Computer Applications","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/3587828.3587857","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0
Abstract
Cyber attack targeting heterogeneous devices in large-scale network environments through advanced persistent threat (APT) attacks are on the rise. Therefore, in order to improve the effectiveness of the cyber incident response system, it is necessary to apply a data enrichment mechanism for the collected digital forensic artifacts data to reinforce threat analysis and detection performance. Therefore, we designed and implemented the data enrichment mechanism for cyber threat intelligent system by analyzing the existing cyber incident response framework such as SIEM, CTI based on the aggregated digital forensic artifacts. Through this, it is expected to improve the detection performance and effectiveness when using artifact data enrichment process for analyzing cyber incidents collected from heterogeneous devices.