Threat Intelligence Platforms evaluation
Master Thesis
Συγγραφέας
Papaioannou, Filippos
Παπαϊωάννου, Φίλιππος
Ημερομηνία
2021-02Επιβλέπων
Dadoyan, ChristoforosΝταντογιάν, Χριστόφορος
Προβολή/ Άνοιγμα
Λέξεις κλειδιά
Threat intelligenceΠερίληψη
This thesis focuses in the evaluation of Threat Intelligence Platforms (TIPs). TIPs are security tools that use global
security data to help proactively identify, mitigate and remediate security threats. New and continually evolving
sophisticated threats are surfacing every day making the processes of detection and mitigation far more complicated
than some years ago. So it’s obvious that the need for more and more intelligent security tools has become
imperative. Thus, organizations were encouraged to change their traditional defence models and to use and to
develop new systems with a proactive approach. Such changes are necessary because the old approaches are not
effective anymore to detect advanced attacks. Also, the organizations are encouraged to develop the ability to
respond to incidents in real-time using complex threat intelligence platforms.
This thesis is separated in three big sections. In the beginning we are going to discuss what threat intelligence is and
how it is used by researchers and organisations. Subsequently a concise analysis and description of four open source
and widespread TIPs will be presented. The platforms I chose are: MISP (Malware Information Sharing
Platform), OpenCTI (Open Cyber Threat Intelligence Platform), CIF (Collective Intelligence Framework) and
CRITs (Collaborative Reasearch Into Threats). Finally, at the last section I will present the evaluation of these
platforms according to specific criteria along with some key findings and limitations that extracted from the analysis.