Cyber Threat Intelligence Reliability Update via Social Feedback
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cyber threat intelligence systems do not effectively reflect the reliability of user evaluations from social networking services (SNS) on cyber threat intelligence, limiting the efficiency and accuracy of analysis.
Innovation Solution
A cyber attack information processing apparatus and method that associates and updates the reliability of cyber threat intelligence based on the source of the information and user evaluations, using a system that integrates user terminals, a storage device, and a cyber threat intelligence management system to register, manage, and analyze cyber threat intelligence in a standardized format like STIX, incorporating user feedback to adjust reliability values.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Quantity of substance
If cyber threat intelligence is collected from multiple sources including social networking services, then the quantity and diversity of threat information increases, but the reliability and accuracy of the intelligence decreases due to unverified user evaluations
Solution Approach 1:
The system implements feedback mechanisms where user evaluations of cyber threat intelligence are collected, processed, and used to update reliability scores. The reliability information is then fed back into the system to influence future information collection and validation processes, creating a continuous improvement loop that balances quantity and quality of threat intelligence
Solution Approach 2:
The system enables self-service evaluation where users can independently assess and rate the reliability of cyber threat intelligence they encounter. This distributed evaluation approach allows the system to maintain reliability standards while scaling information collection across multiple sources including social networking services
2Measurement precision
If user evaluations from social networking services are incorporated into reliability assessment, then the accuracy of threat intelligence improves, but the system complexity increases due to integration requirements
Solution Approach 1:
The system introduces intermediary components including reliability information management units and evaluation processing modules that act as mediators between user evaluations from social networking services and the core threat intelligence system. These intermediaries standardize and process incoming evaluations, reducing the complexity of direct integration while maintaining measurement precision
Solution Approach 2:
The system segments the reliability assessment process into distinct functional modules: evaluation collection, validation, scoring, and updating. This segmentation allows each component to handle specific tasks independently, reducing overall system complexity while improving the precision of reliability measurements through specialized processing at each stage
3Loss of time
If reliability is updated dynamically based on posted information, then the timeliness of threat intelligence improves, but the computational resources and time required for processing increase
Solution Approach 1:
The system implements periodic action by updating reliability information at scheduled intervals and triggering updates based on specific events such as new posted information or threshold crossings. This approach maintains timeliness of threat intelligence while avoiding continuous processing, thereby preserving computational efficiency and productivity
Data Source
AI summary
A cyber attack information processing apparatus includes one or more memories, and one or more processors coupled to the one or more memories and the one or more processors configured to, when acquiring information regarding a first cyber attack, store the information in the one or more memories in association with reliability based on an acquisition source of the information, and when detecting that posted information related to the information is uploaded from a terminal, perform update of the reliability associated with the information in accordance with first reliability of the posted information.


