Towards Cyber Threat Intelligence for the IoT

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Iacovazzi, Alfonso, Wang, Han, Butun, Ismail, Raza, Shahid
Natura: Preprint
Pubblicazione: 2024
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866911926589587456
author Iacovazzi, Alfonso
Wang, Han
Butun, Ismail
Raza, Shahid
author_facet Iacovazzi, Alfonso
Wang, Han
Butun, Ismail
Raza, Shahid
contents With the proliferation of digitization and its usage in critical sectors, it is necessary to include information about the occurrence and assessment of cyber threats in an organization's threat mitigation strategy. This Cyber Threat Intelligence (CTI) is becoming increasingly important, or rather necessary, for critical national and industrial infrastructures. Current CTI solutions are rather federated and unsuitable for sharing threat information from low-power IoT devices. This paper presents a taxonomy and analysis of the CTI frameworks and CTI exchange platforms available today. It proposes a new CTI architecture relying on the MISP Threat Intelligence Sharing Platform customized and focusing on IoT environment. The paper also introduces a tailored version of STIX (which we call tinySTIX), one of the most prominent standards adopted for CTI data modeling, optimized for low-power IoT devices using the new lightweight encoding and cryptography solutions. The proposed CTI architecture will be very beneficial for securing IoT networks, especially the ones working in harsh and adversarial environments.
format Preprint
id arxiv_https___arxiv_org_abs_2406_13543
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Towards Cyber Threat Intelligence for the IoT
Iacovazzi, Alfonso
Wang, Han
Butun, Ismail
Raza, Shahid
Cryptography and Security
With the proliferation of digitization and its usage in critical sectors, it is necessary to include information about the occurrence and assessment of cyber threats in an organization's threat mitigation strategy. This Cyber Threat Intelligence (CTI) is becoming increasingly important, or rather necessary, for critical national and industrial infrastructures. Current CTI solutions are rather federated and unsuitable for sharing threat information from low-power IoT devices. This paper presents a taxonomy and analysis of the CTI frameworks and CTI exchange platforms available today. It proposes a new CTI architecture relying on the MISP Threat Intelligence Sharing Platform customized and focusing on IoT environment. The paper also introduces a tailored version of STIX (which we call tinySTIX), one of the most prominent standards adopted for CTI data modeling, optimized for low-power IoT devices using the new lightweight encoding and cryptography solutions. The proposed CTI architecture will be very beneficial for securing IoT networks, especially the ones working in harsh and adversarial environments.
title Towards Cyber Threat Intelligence for the IoT
topic Cryptography and Security
url https://arxiv.org/abs/2406.13543