M. Ammi, Oluwasegun A. Adedugbe, Fahad M. Al-Harby, E. Benkhelifa
{"title":"Taxonomical Challenges for Cyber Incident Response Threat Intelligence: A Review","authors":"M. Ammi, Oluwasegun A. Adedugbe, Fahad M. Al-Harby, E. Benkhelifa","doi":"10.4018/ijcac.300770","DOIUrl":null,"url":null,"abstract":"As attackers continue to devise new means of exploiting vulnerabilities in computer systems,security personnel are doing their best to identify loopholes and threats.Analysis of threats to come up with effective mitigation techniques requires all-encompassing information about them.Security analysts can represent and share cyber threat information with semantic knowledge graphs within cyber security space to access. However, there should be no conflicting information because the response to threats must be immediate.This calls for a standardized taxonomy that is generally accepted within the cybersecurity space to represent information,ultimately making cyber threat intelligence (CTI) credible.This review looks into existing CTI-based ontologies,taxonomies,and knowledge graphs.The absence of standardized taxonomy identified could be responsible for limited taxonomy encoding and integration among existing CTI-based ontologies, as well as missing interconnections between taxonomies and existing ontologies. Hence, the development of a standardized taxonomy will enhance CTI effectiveness","PeriodicalId":442336,"journal":{"name":"Int. J. Cloud Appl. Comput.","volume":"48 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2022-01-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Int. J. Cloud Appl. Comput.","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.4018/ijcac.300770","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2
Abstract
As attackers continue to devise new means of exploiting vulnerabilities in computer systems,security personnel are doing their best to identify loopholes and threats.Analysis of threats to come up with effective mitigation techniques requires all-encompassing information about them.Security analysts can represent and share cyber threat information with semantic knowledge graphs within cyber security space to access. However, there should be no conflicting information because the response to threats must be immediate.This calls for a standardized taxonomy that is generally accepted within the cybersecurity space to represent information,ultimately making cyber threat intelligence (CTI) credible.This review looks into existing CTI-based ontologies,taxonomies,and knowledge graphs.The absence of standardized taxonomy identified could be responsible for limited taxonomy encoding and integration among existing CTI-based ontologies, as well as missing interconnections between taxonomies and existing ontologies. Hence, the development of a standardized taxonomy will enhance CTI effectiveness