Developing intelligent, interoperable Cyber Threat Information (CTI) sharing technologies can help build strong defences against modern cyber threats. CTIs allow the community to share information about cybercriminals' threats and vulnerabilities and countermeasures to defend themselves or detect malicious activity. A crucial need for success is that the data connected to cyber risks be understandable, organized, and of good quality. The receiving parties may grasp its content and utilize it effectively. This article describes an innovative cyber threat intelligence management platform (CTIMP) for industrial environments, one of the Cyber-pi project's significant elements. The suggested architecture, in particular, uses cyber knowledge from trusted public sources and integrates it with relevant information from the organization's supervised infrastructure in an entirely interoperable and intelligent way. When combined with an advanced visualization mechanism and user interface, the services mentioned above provide administrators with the situational awareness they require while also allowing for extended cooperation, intelligent selection of advanced coping strategies, and a set of automated self-healing rules for dealing with threats.
翻译:共享智能、可互操作的网络威胁信息(CTIP)技术可以帮助建立抵御现代网络威胁的有力防御。CTIS使社区能够分享有关网络罪犯威胁和脆弱性的信息,以及保护自己或发现恶意活动的对策。成功的关键需要是,与网络风险相关的数据可以理解、有组织和高质量的数据。接收方可以掌握其内容并有效利用其内容。本篇文章描述了工业环境的创新性网络威胁情报管理平台(CTIMP ),这是Cyber-pi项目的重要内容之一。建议的架构特别利用了来自可信赖的公共来源的网络知识,并以完全互操作和智能的方式将其与组织监督基础设施的相关信息相结合。在与先进的可视化机制和用户界面相结合时,上述服务为管理员提供了他们所需要的情景意识,同时也允许扩大合作,明智地选择先进的应对战略,以及一套应对威胁的自动自愈合规则。