Serketzis, N., Katos, V., Ilioudis, C., Baltatzis, D and Pangalos, G., 2019. Improving Forensic Triage Efficiency through Cyber Threat Intelligence. Future Internet, 11 (7), 0162.
Full text available as:
|
PDF (OPEN ACCESS ARTICLE)
futureinternet-11-00162.pdf - Published Version Available under License Creative Commons Attribution. 3MB | |
Copyright to original material in this document is with the original owner(s). Access to this content through BURO is granted on condition that you use it only for research, scholarly or other non-commercial purposes. If you wish to use it for any other purposes, you must contact BU via BURO@bournemouth.ac.uk. Any third party copyright material in this document remains the property of its respective owner(s). BU grants no licence for further use of that third party material. |
DOI: 10.3390/fi11070162
Abstract
The complication of information technology and the proliferation of heterogeneous security devices that produce increased volumes of data coupled with the ever-changing threat landscape challenges have an adverse impact on the efficiency of information security controls and digital forensics, as well as incident response approaches. Cyber Threat Intelligence (CTI)and forensic preparedness are the two parts of the so-called managed security services that defendants can employ to repel, mitigate or investigate security incidents. Despite their success, there is no known effort that has combined these two approaches to enhance Digital Forensic Readiness (DFR) and thus decrease the time and cost of incident response and investigation. This paper builds upon and extends a DFR model that utilises actionable CTI to improve the maturity levels of DFR. The effectiveness and applicability of this model are evaluated through a series of experiments that employ malware-related network data simulating real-world attack scenarios. To this extent, the model manages to identify the root causes of information security incidents with high accuracy (90.73%), precision (96.17%) and recall (93.61%), while managing to decrease significantly the volume of data digital forensic investigators need to examine. The contribution of this paper is twofold. First, it indicates that CTI can be employed by digital forensics processes. Second, it demonstrates and evaluates an efficient mechanism that enhances operational DFR.
Item Type: | Article |
---|---|
ISSN: | 1999-5903 |
Uncontrolled Keywords: | digital forensics; digital forensic readiness; threat intelligence; threat hunting; forensic triage |
Group: | Faculty of Science & Technology |
ID Code: | 32570 |
Deposited By: | Symplectic RT2 |
Deposited On: | 24 Jul 2019 07:42 |
Last Modified: | 14 Mar 2022 14:17 |
Downloads
Downloads per month over past year
Repository Staff Only - |