Sharing cyber threat intelligence: Does it really help?
Beomjin Jin, Eunsoo Kim, Hyunwoo Lee, Elisa Bertino, Doowon Kim, Hyoungshick Kim
Abstract
—The sharing of Cyber Threat Intelligence (CTI) across organizations is gaining traction, as it can automate threat analysis and improve security awareness. However, limited empirical studies exist on the prevalent types of cybersecurity threat data and their effectiveness in mitigating cyber attacks. We propose a framework named CTI-Lense to collect and analyze the volume, timeliness, coverage, and quality of Structured Threat Information eXpression (STIX) data, a de facto standard CTI format, from a list of publicly available CTI sources. We collected about 6 million STIX data objects from October 31, 2014 to April 10, 2023 from ten data sources and analyzed their characteristics. Our analysis reveals that STIX data sharing has steadily increased in recent years, but the volume of STIX data shared is still relatively low to cover all cyber threats. Additionally, only a few types of threat data objects have been shared, with malware signatures and URLs accounting for more than 90% of the collected data. While URLs are usually shared promptly, with about 72% of URLs shared earlier than or on the same day as VirusTotal, the sharing of malware signatures is significantly slower. Furthermore, we found that 19% of the Threat actor data contained incorrect information, and only 0.09% of the Indicator data provided security rules to detect cyber attacks. Based on our findings, we recommend practical considerations for effective and scalable STIX data sharing among organizations.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext f733fa8c-004e-43ed-a1de-8666a16155f6Cited by top-tier papers4
- Actively Understanding the Dynamics and Risks of the Threat Intelligence EcosystemTillson Galloway, Omar Alrawi, Allen Chang, Athanasios Avgetidis et al.NDSS 2026 · 2 citations
- BlockMeNot: Automatic Selection of Domain and URL Blocking Granularity to Minimize Collateral Damage and EvasionDaud Ahmed, Srdjan Matic, Platon Kotzias, Emiliano Carlesi et al.USENIX Security 2026
- From Texts to Rules: Generating Sigma Rules with Large Language Models from Cyber Threat ReportsYongxin Cai, Jing Qiu, Qingming Li, Du Cheng et al.USENIX Security 2026
- High Stakes, Low Certainty: Evaluating the Efficacy of High-Level Indicators of Compromise in Ransomware AttributionMax van der Horst, Ricky Kho, Olga Gadyatskaya, Michel Mollema et al.USENIX Security 2025
Builds on7
- Understanding the Mirai BotnetManos Antonakakis, Tim April, Michael D. Bailey, Matt Bernhard et al.USENIX Security 2017 · 2,003 citations
- Phishpedia: A Hybrid Deep Learning Based Approach to Visually Identify Phishing WebpagesYun Lin, Ruofan Liu, Dinil Mon Divakaran, Jun Yang Ng et al.USENIX Security 2021 · 164 citations
- Reading the Tea leaves: A Comparative Analysis of Threat IntelligenceVector Guo Li, Matthew Dunn, Paul Pearce, Damon McCoy et al.USENIX Security 2019 · 123 citations
- Effective and Light-Weight Deobfuscation and Semantic-Aware Attack Detection for PowerShell ScriptsZhenyuan Li, Qi Alfred Chen, Chunlin Xiong, Yan Chen et al.CCS 2019 · 38 citations
- Exposing the Rat in the Tunnel: Using Traffic Analysis for Tor-based Malware DetectionPriyanka Dodia, Mashael AlSabah, Omar Alrawi, Tao WangCCS 2022 · 31 citations
Related papers
- Helping hands: Measuring the impact of a large threat intelligence sharing communityXander Bouwman, Victor Le Pochat, Pawel Foremski, Tom van Goethem et al.USENIX Security 2022
- SoK: Automated TTP Extraction from CTI Reports - Are We There Yet?Marvin Büchel, Tommaso Paladini, Stefano Longari, Michele Carminati et al.USENIX Security 2025
- LLMCloudHunter: Harnessing LLMs for Automated Extraction of Detection Rules from Cloud-Based CTIYuval Schwartz, Lavi Ben-Shimol, Dudu Mimran, Yuval Elovici et al.WWW 2025 · 38 citations
- A different cup of TI? The added value of commercial threat intelligenceXander Bouwman, Harm Griffioen, Jelle Egbers, Christian Doerr et al.USENIX Security 2020
- Do You Play It by the Books? A Study on Incident Response Playbooks and Influencing FactorsDaniel Schlette, Philip Empl, Marco Caselli, Thomas Schreck et al.S&P 2024 · 13 citations
