Skip to main navigation Skip to search Skip to main content

Ontology-based unified model for heterogeneous threat intelligence integration and sharing

  • Yishuai Zhao*
  • , Bo Lang
  • , Ming Liu
  • *Corresponding author for this work
  • Beihang University

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Threat intelligence contains valuable information for cyber security; however, usually the intelligence is from multiple sources and is described with different data formats and schemas, which not only leads to the inefficiency of intelligence integration and analysis, but also makes threat intelligence sharing difficult. Therefore, the unified representation of the threat intelligence becomes a crucial challenge. This paper presents an ontology-based unified model for describing the multi-source and heterogeneous threat intelligence. In our model, we first propose the cyber security ontology and the unified model. Hence, the threat intelligence from different sources can be mapped to our unified model to achieve unified representation, which makes threat intelligence sharing and analysis more efficient. Furthermore, we propose and implement an intelligence integration framework based on our unified intelligence model and the open source intelligence collection tool IntelMQ. The feasibility and effectiveness of our model is verified by the performance of this framework.

Original languageEnglish
Title of host publicationProceedings of 2017 11th IEEE International Conference on Anti-Counterfeiting, Security, and Identification, ASID 2017
EditorsJianyang Zhou, Donghui Guo, Jiyang Dong
PublisherIEEE Computer Society
Pages11-15
Number of pages5
ISBN (Electronic)9781538605325
DOIs
StatePublished - 2 Jul 2017
Event11th IEEE International Conference on Anti-Counterfeiting, Security, and Identification, ASID 2017 - Xiamen, China
Duration: 27 Oct 201729 Oct 2017

Publication series

NameProceedings of the International Conference on Anti-Counterfeiting, Security and Identification, ASID
Volume2017-October
ISSN (Print)2163-5048
ISSN (Electronic)2163-5056

Conference

Conference11th IEEE International Conference on Anti-Counterfeiting, Security, and Identification, ASID 2017
Country/TerritoryChina
CityXiamen
Period27/10/1729/10/17

Keywords

  • Intelligence integration
  • Ontology
  • Threat intelligence
  • Unified model

Fingerprint

Dive into the research topics of 'Ontology-based unified model for heterogeneous threat intelligence integration and sharing'. Together they form a unique fingerprint.

Cite this