Indicator Autogeneration of Compromise Oriented to Threat Intelligence

Wen-tao XU,Yi-jun WANG,Zhi XUE
DOI: https://doi.org/10.3969/j.issn.1002-0802.2017.01.020
2017-01-01
Abstract:How to deal with more complex attack and easily share the security information now becomes the key point of detection , response and prevention of specific target. Based on the threat intelligence and OpenIOC framework, real-time access to and analysis on the massive threat intelligence data both at home and abroad are done with the sandbox malware analyzer named cuckoo. Finally by machine learning algorithm, the indicator of compromiseis automatically generated, which can be shared and machine readable. And it is thus possible to make guick response to the latest and most popular attacks.
What problem does this paper attempt to address?