Motivated by the introduction of CACAO, the first open standard that harmonizes the way we document course of action playbooks in a machine-readable format for interoperability, and the benefits for cybersecurity operations derived from utilizing, and coupling and sharing security playbooks as part of cyber threat intelligence, we introduce a uniform metadata template that supports the management and integration of security playbooks into knowledge representation and knowledge management systems. To demonstrate the applicability of our approach, we provide two use-case implementations where our uniform non-proprietary metadata template is used to introduce security playbooks like CACAO into the MISP threat intelligence platform and the Threat Actor Context ontology.
翻译:在采用CACAO的推动下,我们引入了一个统一的元数据模板,支持将安全游戏手册管理和纳入知识介绍和知识管理系统。为了证明我们的方法的适用性,我们提供了两个使用案例的实施,即我们的统一非专有元数据模板用于将CACAO等安全游戏手册引入军事信息系统威胁情报平台和威胁行为人背景目录。