Published January 30, 2025 | Version v1
Journal Open

AI-based Holistic Framework for Cyber Threat Intelligence Management

Description

Cyber Threat Intelligence (CTI) is an important asset for organisations to facilitate the safeguarding of their systems against new and emerging cyber threats. CTI continuously provides up-to-date information which enables the design and implementation of better security measures and mitigation strategies. Organisations gather data from different sources either internal or external to the organisation, which are analysed, resulting in CTI. Nevertheless, the gathered data usually contain a large amount of content that is irrelevant to CTI or even to cybersecurity. Furthermore, most approaches concerning CTI management (e.g., gathering, analysis) involve simply gathering and storing the information without any enrichment such as classification or correlation. However, in order to obtain the optimal results, organisations should be able to utilise all capabilities of CTI. Therefore, in this work, we propose ThreatWise AI, a novel framework which enables the gathering, analysis, enrichment, storing and sharing of CTI in an efficient and secure manner. In particular, we have developed a novel pipeline in ThreatWise AI which incorporates different advanced tools, with distinct capabilities that interact with each other to provide a complete set of functionalities for the administration of the overall CTI lifecycle. The developed tools integrate various Python scripts and provide gathering and analysis functionalities of CTI. Furthermore, the proposed framework leverages the MISP platform for storing, enriching and sharing while it also integrates Artificial Intelligence (AI) and Machine Learning (ML) algorithms for advanced data enrichment.

Files

AI-based Holistic Framework for Cyber Threat Intelligence Management.pdf

Additional details

Funding

European Commission
IRIS – artificial Intelligence threat Reporting and Incident response System 101021727
European Commission
SECANT – SECurity And privacy protectioN in Internet of Things devices 101019645
European Commission
ENCRYPT – A SCALABLE AND PRACTICAL PRIVACY-PRESERVING FRAMEWORK 101070670