@inproceedings{ee0a0e9bfc624ea3afeedbb704b3c31c,
title = "Ontology-based unified model for heterogeneous threat intelligence integration and sharing",
abstract = "Threat intelligence contains valuable information for cyber security; however, usually the intelligence is from multiple sources and is described with different data formats and schemas, which not only leads to the inefficiency of intelligence integration and analysis, but also makes threat intelligence sharing difficult. Therefore, the unified representation of the threat intelligence becomes a crucial challenge. This paper presents an ontology-based unified model for describing the multi-source and heterogeneous threat intelligence. In our model, we first propose the cyber security ontology and the unified model. Hence, the threat intelligence from different sources can be mapped to our unified model to achieve unified representation, which makes threat intelligence sharing and analysis more efficient. Furthermore, we propose and implement an intelligence integration framework based on our unified intelligence model and the open source intelligence collection tool IntelMQ. The feasibility and effectiveness of our model is verified by the performance of this framework.",
keywords = "Intelligence integration, Ontology, Threat intelligence, Unified model",
author = "Yishuai Zhao and Bo Lang and Ming Liu",
note = "Publisher Copyright: {\textcopyright} 2017 IEEE.; 11th IEEE International Conference on Anti-Counterfeiting, Security, and Identification, ASID 2017 ; Conference date: 27-10-2017 Through 29-10-2017",
year = "2017",
month = jul,
day = "2",
doi = "10.1109/ICASID.2017.8285734",
language = "英语",
series = "Proceedings of the International Conference on Anti-Counterfeiting, Security and Identification, ASID",
publisher = "IEEE Computer Society",
pages = "11--15",
editor = "Jianyang Zhou and Donghui Guo and Jiyang Dong",
booktitle = "Proceedings of 2017 11th IEEE International Conference on Anti-Counterfeiting, Security, and Identification, ASID 2017",
address = "美国",
}