Research on University’s Cyber Threat Intelligence Sharing Platform Based on New Types of STIX and TAXII Standards
- 1 Information Construction and Management Center, Inner Mongolia University of Technology, Hohhot, China
- 2 Department of Information Engineering, Inner Mongolia University of Technology, Hohhot, China
- 3 Faculty of Engineering, Environment & Computing, Coventry University, Coventry, UK
Abstract
With the systematization of cyber threats, the variety of intrusion tools and intrusion methods has greatly reduced the cost of attackers’ threats to network security. Due to a large number of colleges and universities, teachers and students are highly educated and the Internet access rate is nearly 100%. The social status makes the university network become the main target of threat. The traditional defense method cannot cope with the current complex network attacks. In order to solve this problem, the threat intelligence sharing platform based on various threat intelligence sharing standards is established, which STIX and TAXII It is a widely used sharing standard in various sharing platforms. This paper analyzes the existing standards of STIX and TAXII, improves the STIX and TAXII standards based on the analysis results, and proposes a new type of STIX and TAXII based on the improved results. The standard design scheme of threat intelligence sharing platform suitable for college network environment features. The experimental results show that the threat intelligence sharing platform designed in this paper can be effectively applied to the network environment of colleges and universities.
- Ministry of Education of the People’s Republic of China (2019) 2019 National Higher Education List. http://www.moe.gov.cn/jyb_xxgk/s5743/s5744/201906/t20190617_386200.html
- Yang, Z.-M., Li, Q., Liu, J.-R., et al. (2015) Research on Threat Intelligence Sharing and Utilization for Attack Source Tracing. Information Security Research, 1, 31-36.
- Thomas, R.K., et al. (2019) System and Method for Modeling and Analyzing the Impact of Cyber-Security Events on Cyber-Physical Systems. U.S. Patent Application No. 15/264,028.
- Xu, L.-P. and Hao, W.-J. (2016) The Status Quo of Threat Intelligence in US Government and Enterprise Networks and Its Enlightenment to China. Information Network Security, No. 9, 278-284.
- Elchin, A. and Burger, E. (2016) Semantic Ontologies for Cyber Threat Sharing Standards. 2016 IEEE Symposium on Technologies for Homeland Security, Waltham, MA, 10-11 May 2016, 1-6. https://doi.org/10.1109/THS.2016.7568896
- Gong, Y. (2017) Research on Threat Intelligence Usage and Sharing Method. Chinese Computer Society. Proceedings of the 32nd National Computer Security Academic Exchange Conference, 4.
- Liu, Y., Zhang, H.-F., Zhang, L., et al. (2018) Study on a Penetration Testing Collaboration Scheme Based on STIX Information Interaction. Information Technology and Network Security, 37, 1-5.
- Kim, E., Kim, K., Shin, D., Jin, B. and Kim, H. (2018) CyTIME: Cyber Threat Intelligence ManagEment Framework for Automatically Generating Security Rules. Proceedings of the 13th International Conference on Future Internet Technologies, Seoul, 20-22 June 2018, Article No. 7.
- Haass, J.C., Ahn, G.-J. and Grimmelmann, F. (2015) ACTRA: A Case Study for Threat Information Sharing. Proceedings of the 2nd ACM Workshop on Information Sharing and Collaborative Security, Denver, CO, 12 October 2015, 23-26. https://doi.org/10.1145/2808128.2808135
- Frank, F., Smulders, A. and Kerkdijk, R. (2015) Cyber Security Information Exchange to Gain Insight into the Effects of Cyber Threats and Incidents. e & i Elektrotechnik und Informationstechnik, 132, 106-112. https://doi.org/10.1007/s00502-015-0289-2
- Bedini, I., Matheus, C., Boran, A., Patel-Schneider, P.F. and Nguyen, B. (2011) Transforming XML Schema to OWL Using Patterns. 2011 IEEE 5th International Conference on Semantic Computing, Palo Alto, CA, 18-21 September 2011, 102-109. https://doi.org/10.1109/ICSC.2011.77