Integration of Cyber Threat Intelligence into Security Onion and Malcolm for the use case of industrial networks

Tim Ackermann,Markus Karch,Jörg Kippe
DOI: https://doi.org/10.1515/auto-2023-0057
2023-09-09
at - Automatisierungstechnik
Abstract:With the increasing frequency of cyberattacks on Industrial Control Systems (ICS), the subject of cybersecurity is becoming increasingly important. Cyber Threat Intelligence (CTI) provides information about cyber adversaries, including their intentions and attack techniques. This paper analyzes the availability of open-source CTI for ICS, with a particular focus on technical indicators that can aid in detecting cyberattacks. Furthermore, this paper examines the automated integration of CTI data into SIEM systems and introduces CTIExchange as a tool that facilitates this integration by connecting Threat Intelligence Platforms with detection tools.
automation & control systems
What problem does this paper attempt to address?