paper-with-me

Papers

Mining Threat Intelligence about Open-Source Projects and Libraries from Code Repository Issues and Bug Reports

2018-08-09 · Lorenzo Neil, Sudip Mittal, Anupam Joshi

Open-Source Projects and Libraries are being used in software development while also bearing multiple security vulnerabilities. This use of third party ecosystem creates a new kind of attack surface for a product in development. An intelligent attacker can attack a product by exploiting one of the vulnerabilities present in linked projects and libraries. In this paper, we mine threat intelligence about open source projects and libraries from bugs and issues reported on public code repositories. We also track library and project dependencies for installed software on a client machine. We represent and store this threat intelligence, along with the software dependencies in a security knowledge graph. Security analysts and developers can then query and receive alerts from the knowledge graph if any threat intelligence is found about linked libraries and projects, utilized in their products.

📄 PDF Abstract BibTeX arXiv:1808.04673

Code (0)

등록된 구현이 없습니다.

Similar Papers 제목 키워드 기반

A System for Automated Open-Source Threat Intelligence Gathering and Management

2021-01-19 · Peng Gao, Xiaoyuan Liu, Edward Choi, Bhavna Soman 외

To remain aware of the fast-evolving cyber threat landscape, open-source Cyber Threat Intelligence (OSCTI) has received growing attention from the community. Commonly, knowledge about threats is presented in a vast numbe…

Management

MALOnt: An Ontology for Malware Threat Intelligence

2020-06-20 · Nidhi Rastogi, Sharmishtha Dutta, Mohammed J. Zaki, Alex Gittens 외

Malware threat intelligence uncovers deep information about malware, threat actors, and their tactics, Indicators of Compromise(IoC), and vulnerabilities in different platforms from scattered threat sources. This collect…

Decision MakingGraph GenerationKnowledge Graphs

A System for Efficiently Hunting for Cyber Threats in Computer Systems Using Threat Intelligence

2021-01-17 · Peng Gao, Fei Shao, Xiaoyuan Liu, Xusheng Xiao 외

Log-based cyber threat hunting has emerged as an important solution to counter sophisticated cyber attacks. However, existing approaches require non-trivial efforts of manual query construction and have overlooked the ri…

Mining Temporal Attack Patterns from Cyberthreat Intelligence Reports

2024-01-03 · Md Rayhanur Rahman, Brandon Wroblewski, Quinn Matthews, Brantley Morgan 외

Defending from cyberattacks requires practitioners to operate on high-level adversary behavior. Cyberthreat intelligence (CTI) reports on past cyberattack incidents describe the chain of malicious actions with respect to…

TINKER: A framework for Open source Cyberthreat Intelligence

2021-02-10 · Nidhi Rastogi, Sharmishtha Dutta, Mohammed J. Zaki, Alex Gittens 외

Threat intelligence on malware attacks and campaigns is increasingly being shared with other security experts for a cost or for free. Other security analysts use this intelligence to inform them of indicators of compromi…

Information RetrievalIntrusion DetectionKnowledge GraphsNamed Entity Recognition (NER)+1