USENIX Security2020Top-tier venue
A different cup of TI? The added value of commercial threat intelligence
Xander Bouwman, Harm Griffioen, Jelle Egbers, Christian Doerr, Bram Klievink, Michel van Eeten
Abstract
Commercial threat intelligence is thought to provide unmatched coverage on attacker behavior, but it is out of reach for many organizations due to its hefty price tag. This paper presents the first empirical assessment of the services of commercial threat intelligence providers. For two leading vendors, we describe what these services consist of and compare their indicators with each other. There is almost no overlap between them, nor with four large open threat intelligence feeds. Even for 22 specific threat actors -which both vendors claim to track -we find an average overlap of only 2.5% to 4.0% between the indicator feeds. The small number of overlapping indicators show up in the feed of the other vendor with a delay of, on average, a month. These findings raise questions on the coverage and timeliness of paid threat intelligence. We also conducted 14 interviews with security professionals that use paid threat intelligence. We find that value in this market is understood differently than prior work on quality metrics has assumed. Poor coverage and small volume appear less of a problem to customers. They seem to be optimizing for the workflow of their scarce resource -analyst timerather than for the detection of threats. Respondents evaluate TI mostly through informal processes and heuristics, rather than the quantitative metrics that research has proposed.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 61462f87-5e75-4346-bfe4-fbb2af1f8f34Cited by top-tier papers20
- Hopper: Modeling and Detecting Lateral MovementGrant Ho, Mayank Dhiman, Devdatta Akhawe, Vern Paxson et al.USENIX Security 2021 · 41 citations
- Everyone for Themselves? A Qualitative Study about Individual Security Setups of Open Source Software ContributorsSabrina Amft, Sandra Höltervennhoff, Rebecca Panskus, Karola Marky et al.S&P 2024 · 21 citations
- "We've Disabled MFA for You": An Evaluation of the Security and Usability of Multi-Factor Authentication Recovery DeploymentsSabrina Amft, Sandra Höltervennhoff, Nicolas Huaman, Alexander Krause et al.CCS 2023 · 14 citations
- A Qualitative Study of Adoption Barriers and Challenges for Passwordless Authentication in German Public AdministrationsJan-Ulrich Holtgrave, Sabrina Klivan, Karola Marky, Sascha FahlCHI 2025 · 9 citations
- How does Endpoint Detection use the MITRE ATT&CK Framework?Apurva Virkud, Muhammad Adil Inam, Andy Riddle, Jason Liu et al.USENIX Security 2024 · 9 citations
Builds on3
- Hackers vs. Testers: A Comparison of Software Vulnerability Discovery ProcessesDaniel Votipka, Rock Stevens, Elissa M. Redmiles, Jeremy Hu et al.S&P 2018 · 151 citations
- Matched and Mismatched SOCs: A Qualitative Study on Security Operations Center IssuesFaris Bugra Kokulu, Ananta Soneji, Tiffany Bao, Yan Shoshitaishvili et al.CCS 2019 · 134 citations
- Reading the Tea leaves: A Comparative Analysis of Threat IntelligenceVector Guo Li, Matthew Dunn, Paul Pearce, Damon McCoy et al.USENIX Security 2019 · 123 citations
Related papers
- APT to Disagree: A Comparative Analysis of Attribution in Commercial TIAksel Ethembabaoglu, Rolf van Wegberg, Yury Zhauniarovich, Michel van EetenS&P 2026 · 2 citations
- Can IOCs Impose Cost? The Effects of Publishing Threat Intelligence on Adversary BehaviorXander Bouwman, Aksel Ethembabaoglu, Bart Hermans, Carlos Gañán et al.CCS 2025
- #Twiti: Social Listening for Threat IntelligenceHyejin Shin, WooChul Shim, Saebom Kim, Sol Lee et al.WWW 2021 · 32 citations
- Sharing cyber threat intelligence: Does it really help?Beomjin Jin, Eunsoo Kim, Hyunwoo Lee, Elisa Bertino et al.NDSS 2024
- Detecting Credential Spearphishing in Enterprise SettingsGrant Ho, Aashish Sharma, Mobin Javed, Vern Paxson et al.USENIX Security 2017 · 94 citations
