Actively Understanding the Dynamics and Risks of the Threat Intelligence Ecosystem
Tillson Galloway, Omar Alrawi, Allen Chang, Athanasios Avgetidis, Manos Antonakakis, Fabian Monrose
摘要
Despite the billions of dollars invested in the threat intelligence (TI) ecosystem-a globally distributed network of security vendors and altruists who drive critical cybersecurity operations-we lack an understanding of how it functions, including its dynamics and vulnerabilities. To fill that void, we propose a novel measurement framework that tracks binaries as they traverse the ecosystem by monitoring for watermarked network Indicators of Compromise (IoCs). By analyzing each stage of the propagation chain of submitted TI (submission, extraction, sharing, and disruption), we uncover an ecosystem where dissemination almost always leads to the disruption of threats, but vendors who selectively share the TI they extract limit the ecosystem's utility. Further, we find that attempts to curtail threats are often slowed by 'bottleneck' vendors delaying the sharing of TI by hours to days. Critically, we identify several threats to the ecosystem's supply chain, some of which are presently exploited in the wild. Unnecessary active probing by vendors, shallow extraction of dropped files, and easy-to-predict sandbox environment fingerprints all threaten the health of the ecosystem. To address these issues, we provide actionable recommendations for vendors and practitioners that improve the safety of the TI supply chain, including detection signatures for known abuse patterns. We collaborated with vendors through a responsible disclosure process, gaining insight into the operational constraints underlying these weaknesses. Finally, we provide a set of ethical best practices for researchers actively measuring the threat intelligence ecosystem. • RQ1 [Propagation]: How do security vendors differ in their ability to analyze malware and share extracted indicators of compromise (IoCs) across the ecosystem? • RQ2 [Disruption]: How do differences in analysis and sharing affect the speed and effectiveness with which vendors block IoCs or take down (or suspend) infrastructure? • RQ3 [Evasion]: How are adversaries exploiting gaps in analysis, sharing, or disruption, and what strategies can improve the ecosystem's resilience against such evasions? Our study reveals a stratified structure in the TI ecosystem that directly impacts IoC sharing and response times. While sandbox analysis occurs rapidly and is widespread (performed
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper1
问问它们各自怎么用它它引用的顶会 Paper21
- Understanding the Mirai BotnetManos Antonakakis, Tim April, Michael D. Bailey, Matt Bernhard 等USENIX Security 2017 · 被引用 2,003 次
- Acing the IOC Game: Toward Automatic Discovery and Analysis of Open-Source Cyber Threat IntelligenceXiaojing Liao, Kan Yuan, XiaoFeng Wang, Zhou Li 等CCS 2016 · 被引用 308 次
- Spotless Sandboxes: Evading Malware Analysis Systems Using Wear-and-Tear ArtifactsNajmeh Miramirkhani, Mahathi Priya Appini, Nick Nikiforakis, Michalis PolychronakisS&P 2017 · 被引用 134 次
- Reading the Tea leaves: A Comparative Analysis of Threat IntelligenceVector Guo Li, Matthew Dunn, Paul Pearce, Damon McCoy 等USENIX Security 2019 · 被引用 123 次
- Domain-Z: 28 Registrations Later Measuring the Exploitation of Residual Trust in DomainsChaz Lever, Robert J. Walls, Yacin Nadji, David Dagon 等S&P 2016 · 被引用 76 次
相关 Paper
- Sharing cyber threat intelligence: Does it really help?Beomjin Jin, Eunsoo Kim, Hyunwoo Lee, Elisa Bertino 等NDSS 2024
- Understanding the Status and Strategies of the Code Signing Abuse EcosystemHanqing Zhao, Yiming Zhang, Lingyun Ying, Mingming Zhang 等NDSS 2026
- FLARE-AI: Flaw Reporting for AIShayne Longpre, Elaine Zhu, Carson Ezell, Avijit Ghosh 等ICML 2026
- "Abuse Risks are Often Inherent to Product Features": Exploring AI Vendors' Bug Bounty and Responsible Disclosure PoliciesYangheran Piao, Jingjie Li, Daniel W. WoodsUSENIX Security 2026 · 被引用 1 次
- No One Drinks From the Firehose: How Organizations Filter and Prioritize Vulnerability InformationStephanie de Smale, Rik van Dijk, Xander Bouwman, Jeroen van der Ham 等S&P 2023
