A shared cyber threat intelligence solution for smes

Publication date

2021-12-01

Authors

van Haastrecht, MaxISNI 0000000503887150
Golpur, Guy
Tzismadia, Gilad
Kab, Rolan
Priboi, Cristian
David, Dumitru
Răcătăian, Adrian
Brinkhuis, Matthieu J. S.ORCID 0000-0003-1054-6683ISNI 0000000419480083
Spruit, MarcoISNI 0000000077172004

Editors

Advisors

Supervisors

Document Type

Article
Open Access logo

License

cc_by

Abstract

Small-and medium-sized enterprises (SMEs) frequently experience cyberattacks, but often do not have the means to counter these attacks. Therefore, cybersecurity researchers and practitioners need to aid SMEs in their defence against cyber threats. Research has shown that SMEs require solutions that are automated and adapted to their context. In recent years, we have seen a surge in initiatives to share cyber threat intelligence (CTI) to improve collective cybersecurity resilience. Shared CTI has the potential to answer the SME call for automated and adaptable solutions. Sadly, as we demonstrate in this paper, current shared intelligence approaches scarcely address SME needs. We must investigate how shared CTI can be used to improve SME cybersecurity resilience. In this paper, we tackle this challenge using a systematic review to discover current state-of-the-art approaches to using shared CTI. We find that threat intelligence sharing platforms such as MISP have the potential to address SME needs, provided that the shared intelligence is turned into actionable insights. Based on this observation, we developed a prototype application that processes MISP data automatically, prioritises cybersecurity threats for SMEs, and provides SMEs with actionable recommendations tailored to their context. Subsequent evaluations in operational environments will help to improve our application, such that SMEs are enabled to thwart cyberattacks in future.

Keywords

Cyber threat intelligence, Cybersecurity, Information sharing, MISP, SME, Control and Systems Engineering, Signal Processing, Hardware and Architecture, Computer Networks and Communications, Electrical and Electronic Engineering

Citation

van Haastrecht, M, Golpur, G, Tzismadia, G, Kab, R, Priboi, C, David, D, Răcătăian, A, Brinkhuis, M & Spruit, M 2021, 'A shared cyber threat intelligence solution for smes', Electronics (Switzerland), vol. 10, no. 23, 2913, pp. 1-21. https://doi.org/10.3390/electronics10232913