A different cup of TI? The added value of commercial threat intelligence
Xander Bouwman, Harm Griffioen, Jelle Egbers, Christian Doerr, Bram Klievink, Michel van Eeten
摘要
Commercial threat intelligence is thought to provide unmatched coverage on attacker behavior, but it is out of reach for many organizations due to its hefty price tag. This paper presents the first empirical assessment of the services of commercial threat intelligence providers. For two leading vendors, we describe what these services consist of and compare their indicators with each other. There is almost no overlap between them, nor with four large open threat intelligence feeds. Even for 22 specific threat actors -which both vendors claim to track -we find an average overlap of only 2.5% to 4.0% between the indicator feeds. The small number of overlapping indicators show up in the feed of the other vendor with a delay of, on average, a month. These findings raise questions on the coverage and timeliness of paid threat intelligence. We also conducted 14 interviews with security professionals that use paid threat intelligence. We find that value in this market is understood differently than prior work on quality metrics has assumed. Poor coverage and small volume appear less of a problem to customers. They seem to be optimizing for the workflow of their scarce resource -analyst timerather than for the detection of threats. Respondents evaluate TI mostly through informal processes and heuristics, rather than the quantitative metrics that research has proposed.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper20
- Hopper: Modeling and Detecting Lateral MovementGrant Ho, Mayank Dhiman, Devdatta Akhawe, Vern Paxson 等USENIX Security 2021 · 被引用 41 次
- Everyone for Themselves? A Qualitative Study about Individual Security Setups of Open Source Software ContributorsSabrina Amft, Sandra Höltervennhoff, Rebecca Panskus, Karola Marky 等S&P 2024 · 被引用 21 次
- "We've Disabled MFA for You": An Evaluation of the Security and Usability of Multi-Factor Authentication Recovery DeploymentsSabrina Amft, Sandra Höltervennhoff, Nicolas Huaman, Alexander Krause 等CCS 2023 · 被引用 14 次
- A Qualitative Study of Adoption Barriers and Challenges for Passwordless Authentication in German Public AdministrationsJan-Ulrich Holtgrave, Sabrina Klivan, Karola Marky, Sascha FahlCHI 2025 · 被引用 9 次
- How does Endpoint Detection use the MITRE ATT&CK Framework?Apurva Virkud, Muhammad Adil Inam, Andy Riddle, Jason Liu 等USENIX Security 2024 · 被引用 9 次
它引用的顶会 Paper3
- Hackers vs. Testers: A Comparison of Software Vulnerability Discovery ProcessesDaniel Votipka, Rock Stevens, Elissa M. Redmiles, Jeremy Hu 等S&P 2018 · 被引用 151 次
- Matched and Mismatched SOCs: A Qualitative Study on Security Operations Center IssuesFaris Bugra Kokulu, Ananta Soneji, Tiffany Bao, Yan Shoshitaishvili 等CCS 2019 · 被引用 134 次
- Reading the Tea leaves: A Comparative Analysis of Threat IntelligenceVector Guo Li, Matthew Dunn, Paul Pearce, Damon McCoy 等USENIX Security 2019 · 被引用 123 次
相关 Paper
- APT to Disagree: A Comparative Analysis of Attribution in Commercial TIAksel Ethembabaoglu, Rolf van Wegberg, Yury Zhauniarovich, Michel van EetenS&P 2026 · 被引用 2 次
- Can IOCs Impose Cost? The Effects of Publishing Threat Intelligence on Adversary BehaviorXander Bouwman, Aksel Ethembabaoglu, Bart Hermans, Carlos Gañán 等CCS 2025
- #Twiti: Social Listening for Threat IntelligenceHyejin Shin, WooChul Shim, Saebom Kim, Sol Lee 等WWW 2021 · 被引用 32 次
- Sharing cyber threat intelligence: Does it really help?Beomjin Jin, Eunsoo Kim, Hyunwoo Lee, Elisa Bertino 等NDSS 2024
- Detecting Credential Spearphishing in Enterprise SettingsGrant Ho, Aashish Sharma, Mobin Javed, Vern Paxson 等USENIX Security 2017 · 被引用 94 次
