Skip to Main Content (Press Enter)

Logo CNR
  • ×
  • Home
  • People
  • Outputs
  • Organizations
  • Expertise & Skills

UNI-FIND
Logo CNR

|

UNI-FIND

cnr.it
  • ×
  • Home
  • People
  • Outputs
  • Organizations
  • Expertise & Skills
  1. Outputs

ORISHA: Improving Threat Detection through Orchestrated Information Sharing

Conference Paper
Publication Date:
2023
abstract:
The exponential growth in the number of cyber threats requires sharing in a timely and efficient manner a wide range of Indicators of Compromise (IoCs), i.e., fragments of forensics data that can be used to recognize malicious network or system activities. To this aim, a suitable architecture is required, especially to distribute and process the various IoCs. Unfortunately, the continuous creation of offensive techniques, along with the diffusion of advanced persistent threats, imposes the ability to update and extend the platform used to manage the multitude of IoCs collected in the wild. In this paper, we present the ORISHA architecture, which takes advantage of a distributed threat detection system to match performance and scalability requirements. The paper also discusses how the platform can be extended to handle the most recent "stealthy" malware as well as campaigns aimed at spreading fake news.
Iris type:
04.01 Contributo in Atti di convegno
Keywords:
threat intelligence; risk mitigation; active learning; collaborative approach
List of contributors:
Zuppelli, Marco; Manco, Giuseppe; Caviglione, Luca; Comito, Carmela; Guarascio, Massimo; Pisani, FRANCESCO SERGIO
Authors of the University:
CAVIGLIONE LUCA
COMITO CARMELA
GUARASCIO MASSIMO
MANCO GIUSEPPE
PISANI FRANCESCO SERGIO
ZUPPELLI MARCO
Handle:
https://iris.cnr.it/handle/20.500.14243/433059
Book title:
Proceedings of the 31st Symposium of Advanced Database Systems
Published in:
CEUR WORKSHOP PROCEEDINGS
Series
  • Overview

Overview

URL

https://sebd2023.dei.unipd.it
  • Use of cookies

Powered by VIVO | Designed by Cineca | 26.5.0.0 | Sorgente dati: PREPROD (Ribaltamento disabilitato)