Browse wiki

From Navigators

Jump to: navigation, search
Publication:Alves21synapse
Abstract Receiving timely and relevant security inf Receiving timely and relevant security information is crucial for maintaining a high-security level on an IT infrastructure. This information can be extracted from Open Source Intelligence published daily by users, security organisations, and researchers. In particular, Twitter has become an information hub for obtaining cutting-edge information about many subjects, including cybersecurity. This work proposes SYNAPSE, a Twitter-based streaming threat monitor that generates a continuously updated summary of the threat landscape related to a monitored infrastructure. SYNAPSE is designed to accurately select any kind of cybersecurity events and summarise them for the convenience of security analysts. Its tweet-processing pipeline is composed of filtering, feature extraction, binary classification, an innovative clustering strategy, and generation of Indicators of Compromise (IoCs). A quantitative evaluation considering over 195.000 tweets from 80 accounts over more than 8 months, shows that our approach successfully finds the majority of security-related tweets concerning an example IT infrastructure (true positive rate above 90%), incorrectly selects a small number of tweets as relevant (false positive rate under 10%), and summarises the results in few IoCs per day. A qualitative evaluation of the IoCs generated by SYNAPSE demonstrates their relevance, and timeliness. Finally, we provide some highlights of a real-world integration of SYNAPSE with the Security Operation Center of a nation-wide electric utility. Center of a nation-wide electric utility.
Author Fernando Alves + , Aurélien Bettini + , Pedro M. Ferreira + , Alysson Bessani +
Journal Information Systems  +
Key Alves21synapse  +
Month jan  +
NumPubDate 2,021.01  +
Project Project:DiSIEM + , Project:IRCoC +
ResearchLine Fault and Intrusion Tolerance in Open Distributed Systems (FIT) +
Title Processing Tweets for Cybersecurity Threat Awareness  +
Type article  +
Url https://doi.org/10.1016/j.is.2020.101586  +
Volume 95  +
Year 2021  +
Categories Publication  +
Modification dateThis property is a special property in this wiki. 29 September 2021 16:30:23  +
show properties that link here 

 

Enter the name of the page to start browsing from.
Views
Personal tools
Toolbox
Navigators toolbox