Abstract
Threat intelligence sharing is an important countermeasure against the increasing number of security threats to which companies and governments are exposed. Its objective is the cross-organizational exchange of information about actual and potential threats. In recent years, a heterogeneous market of threat intelligence sharing platforms (TISPs) has emerged. These platforms are inter-organizational systems that support collaborative collection, aggregation, analysis and dissemination of threat-related information. Organizations that consider using TISPs are often faced with the challenge of selecting suitable platforms. To facilitate the evaluation of TISPs, we present a framework for analyzing and comparing relevant TISPs. Our framework provides a set of 25 functional and non-functional criteria that support potential users in selecting suitable platforms. We demonstrate the applicability of our evaluation framework by assessing three platforms: MISP, OTX and ThreatQ. We describe common features and differences between the three platforms.
Cite
CITATION STYLE
Bauer, S., Fischer, D., Sauerwein, C., Latzel, S., Stelzer, D., & Breu, R. (2020). Towards an evaluation framework for threat intelligence sharing platforms. In Proceedings of the Annual Hawaii International Conference on System Sciences (Vol. 2020-January, pp. 1947–1956). IEEE Computer Society. https://doi.org/10.24251/hicss.2020.239
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.