Can IOCs Impose Cost? The Effects of Publishing Threat Intelligence on Adversary Behavior
Xander Bouwman, Aksel Ethembabaoglu, Bart Hermans, Carlos Gañán, Michel van Eeten
摘要
Exposing intrusion campaigns has become a geopolitical tool, with governments and commercial firms publishing threat intelligence reports about hacking attempts and modus operandi. U.S. government officials have explained this as not just a defensive practice but also as a way to 'impose cost' on attackers by forcing them to develop new infrastructure, tools, and techniques. We empirically examine this claim by analyzing attacker behavior before and after publication of indicators of compromise (IOCs). Using IOC feeds from two leading commercial providers, we matched IOCs against a large dataset of real-world network traffic metadata. This enabled us to generate sightings retroactively, capturing malicious activity up to 150 days before and after publication. Unlike prior work focused on post-publication malicious activity, our method provides a more complete view over time. Our results show that most IOCs point to resources that attackers had already abandoned by publication, limiting their utility for detecting ongoing attacks and undermining the idea of 'imposing costs'. Statistical modeling further reveals that publication status has low explanatory power for sightings, suggesting that confounding variables exist. We also observed a 30-day delay between the peak of threat actor activity and IOC publication for one provider. This study is the first empirical assessment linking threat intelligence publication to attacker behavior, bridging computer science and international relations.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
相关 Paper
- A different cup of TI? The added value of commercial threat intelligenceXander Bouwman, Harm Griffioen, Jelle Egbers, Christian Doerr 等USENIX Security 2020
- Trail: A Knowledge Graph-Based Approach for Attributing Advanced Persistent ThreatsIsaiah J. King, Ramiro Ramirez, Benjamin Bowman, H. Howie HuangICDE 2025 · 被引用 3 次
- APT to Disagree: A Comparative Analysis of Attribution in Commercial TIAksel Ethembabaoglu, Rolf van Wegberg, Yury Zhauniarovich, Michel van EetenS&P 2026 · 被引用 2 次
- Reading the Tea leaves: A Comparative Analysis of Threat IntelligenceVector Guo Li, Matthew Dunn, Paul Pearce, Damon McCoy 等USENIX Security 2019 · 被引用 123 次
- #Twiti: Social Listening for Threat IntelligenceHyejin Shin, WooChul Shim, Saebom Kim, Sol Lee 等WWW 2021 · 被引用 32 次
