Credible Threat Detection? Measuring Contribution Dynamics and Quality Control in a Crowdsourced Threat Detection Ecosystem
Apurva Virkud, Gang Wang, Adam Bates
摘要
Abstract Community exchange serves as a critical component of modern day security operations. Commercial security vendors often draw from crowdsourced intelligence and rules to power their proprietary systems. Additionally, Managed Security Service Providers (MSSPs) and Managed Detection and Response (MDR) solutions leverage both crowdsourced and commercial feeds to provide security services to organizations without their own security infrastructure. However, there is no systematic understanding of how these crowdsourced detection rules are developed or vetted. In this work, we explore the open-source and crowdsourced Sigma repository as a window into the development of threat detection rules. We find that the Sigma repository continuously iterates upon its rules, especially with tuning of false positives based on feedback from an active downstream userbase. Through an investigation of the quality control process, we observe evidence of informal rule evaluation, but also of inexperienced contributions from the broader community. Finally, we perform a comparative analysis of rules that have migrated between Sigma and other commercial Security Information and Event Management (SIEM) vendors (and vice versa) and observe divergences across platforms. Although crowdsourcing allows the community to iterate on commercial rules, we anecdotally observe that such contributions can introduce increased risk of rule evasion from the adversary. While Sigma is an active resource for vendors and the broader security community, it can benefit from more systematic and automated quality control procedures. As a first step, we introduce a tool to identify incoming duplicate rules to aid in the review process.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper19
- A Large-Scale Empirical Study of Security PatchesFrank Li, Vern PaxsonCCS 2017 · 被引用 273 次
- Understanding the Reproducibility of Crowd-reported Security VulnerabilitiesDongliang Mu, Alejandro Cuevas, Limin Yang, Hang Hu 等USENIX Security 2018 · 被引用 138 次
- Reading the Tea leaves: A Comparative Analysis of Threat IntelligenceVector Guo Li, Matthew Dunn, Paul Pearce, Damon McCoy 等USENIX Security 2019 · 被引用 123 次
- Phishing in Organizations: Findings from a Large-Scale and Long-Term StudyDaniele Lain, Kari Kostiainen, Srdjan CapkunS&P 2022 · 被引用 92 次
- Committed to Trust: A Qualitative Study on Security & Trust in Open Source Software ProjectsDominik Wermke, Noah Wöhler, Jan H. Klemmer, Marcel Fourné 等S&P 2022 · 被引用 54 次
相关 Paper
- Alert Alchemy: SOC Workflows and Decisions in the Management of NIDS RulesMathew Vermeer, Natalia Kadenko, Michel van Eeten, Carlos Gañán 等CCS 2023 · 被引用 16 次
- From Texts to Rules: Generating Sigma Rules with Large Language Models from Cyber Threat ReportsYongxin Cai, Jing Qiu, Qingming Li, Du Cheng 等USENIX Security 2026
- Catch Me If You Can: Detector-Resistant Evasion via Semantics-Preserving Command Re-RealizationMuhammad Shoaib, Hare Sudhan Muthusamy, Tareq Alkhatib, Wajih Ul HassanS&P 2026 · 被引用 2 次
- How does Endpoint Detection use the MITRE ATT&CK Framework?Apurva Virkud, Muhammad Adil Inam, Andy Riddle, Jason Liu 等USENIX Security 2024 · 被引用 9 次
- You Cannot Escape Me: Detecting Evasions of SIEM Rules in Enterprise NetworksRafael Uetz, Marco Herzog, Louis Hackländer, Simon Schwarz 等USENIX Security 2024 · 被引用 23 次
