USENIX Security2022Top-tier venue
Helping hands: Measuring the impact of a large threat intelligence sharing community
Xander Bouwman, Victor Le Pochat, Pawel Foremski, Tom van Goethem, Carlos Hernandez Gañán, Giovane C. M. Moura, Samaneh Tajalizadehkhoob, Wouter Joosen, Michel van Eeten
Abstract
We tracked the largest volunteer security information sharing community known to date: the COVID-19 Cyber Threat Coalition, with over 4,000 members. This enabled us to address long-standing questions on threat information sharing. First, does collaboration at scale lead to better coverage? And second, does making threat data freely available improve the ability of defenders to act? We found that the CTC mostly aggregated existing industry sources of threat information. User-submitted domains often did not make it to the CTC's blocklist as a result of the high threshold posed by its automated quality assurance using VirusTotal. Although this ensured a low false positive rate, it also caused the focus of the blocklist to drift away from domains related to COVID-19 (1.4%-3.6%) to more generic abuse, such as phishing, for which established mitigation mechanisms already exist. However, in the slice of data that was related to COVID-19, we found promising evidence of the added value of a community like the CTC: just 25.1% of these domains were known to existing abuse detection infrastructures at time of listing, as compared to 58.4% of domains on the overall blocklist. From the unique experiment that the CTC represented, we draw three lessons for future threat data sharing initiatives.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext aacc4154-31bf-4b59-89ef-eca7d549a050Cited by top-tier papers8
- Actively Understanding the Dynamics and Risks of the Threat Intelligence EcosystemTillson Galloway, Omar Alrawi, Allen Chang, Athanasios Avgetidis et al.NDSS 2026 · 2 citations
- Credible Threat Detection? Measuring Contribution Dynamics and Quality Control in a Crowdsourced Threat Detection EcosystemApurva Virkud, Gang Wang, Adam BatesUSENIX Security 2026 · 1 citation
- Selling the Dream: How Intimate Insiders and Identity-Based Attackers Disrupt Micro-businessesNazanin Sabri, Arkaprabha Bhattacharya, Sterling Williams-Ceci, Daniel V. Bailey et al.USENIX Security 2026
- Ctrl+Alt+Deceive: Quantifying User Exposure to Online ScamsPlaton Kotzias, Michalis Pachilakis, Javier Aldana-Iuit, Juan Caballero et al.NDSS 2025
- Understanding the Implementation and Security Implications of Protective DNS ServicesMingxuan Liu, Yiming Zhang, Xiang Li, Chaoyi Lu et al.NDSS 2024
Builds on7
- PhishFarm: A Scalable Framework for Measuring the Effectiveness of Evasion Techniques against Browser Phishing BlacklistsAdam Oest, Yeganeh Safaei, Adam Doupé, Gail-Joon Ahn et al.S&P 2019 · 129 citations
- Reading the Tea leaves: A Comparative Analysis of Threat IntelligenceVector Guo Li, Matthew Dunn, Paul Pearce, Damon McCoy et al.USENIX Security 2019 · 123 citations
- Cracking the Wall of Confinement: Understanding and Analyzing Malicious Domain Take-downsEihal Alowaisheq, Peng Wang, Sumayah A. Alrwais, Xiaojing Liao et al.NDSS 2019 · 48 citations
- Compromised or Attacker-Owned: A Large Scale Classification and Study of Hosting Domains of Malicious URLsRavindu De Silva, Mohamed Nabeel, Charith Elvitigala, Issa Khalil et al.USENIX Security 2021 · 45 citations
- A Practical Approach for Taking Down Avalanche Botnets Under Real-World ConstraintsVictor Le Pochat, Tim Van hamme, Sourena Maroofi, Tom van Goethem et al.NDSS 2020
Related papers
- Sharing cyber threat intelligence: Does it really help?Beomjin Jin, Eunsoo Kim, Hyunwoo Lee, Elisa Bertino et al.NDSS 2024
- MANTIS: Detection of Zero-Day Malicious Domains Leveraging Low Reputed Hosting InfrastructureFatih Deniz, Mohamed Nabeel, Ting Yu, Issa KhalilS&P 2025
- Don't Let One Rotten Apple Spoil the Whole Barrel: Towards Automated Detection of Shadowed DomainsDaiping Liu, Zhou Li, Kun Du, Haining Wang et al.CCS 2017 · 60 citations
- Measuring and Modeling the Label Dynamics of Online Anti-Malware EnginesShuofei Zhu, Jianjun Shi, Limin Yang, Boqin Qin et al.USENIX Security 2020
- Understanding the Status and Strategies of the Code Signing Abuse EcosystemHanqing Zhao, Yiming Zhang, Lingyun Ying, Mingming Zhang et al.NDSS 2026
