Skip to Main Content (Press Enter)

Logo CNR
  • ×
  • Home
  • Persone
  • Pubblicazioni
  • Strutture
  • Competenze

UNI-FIND
Logo CNR

|

UNI-FIND

cnr.it
  • ×
  • Home
  • Persone
  • Pubblicazioni
  • Strutture
  • Competenze
  1. Pubblicazioni

ORISHA: Improving Threat Detection through Orchestrated Information Sharing

Contributo in Atti di convegno
Data di Pubblicazione:
2023
Abstract:
The exponential growth in the number of cyber threats requires sharing in a timely and efficient manner a wide range of Indicators of Compromise (IoCs), i.e., fragments of forensics data that can be used to recognize malicious network or system activities. To this aim, a suitable architecture is required, especially to distribute and process the various IoCs. Unfortunately, the continuous creation of offensive techniques, along with the diffusion of advanced persistent threats, imposes the ability to update and extend the platform used to manage the multitude of IoCs collected in the wild. In this paper, we present the ORISHA architecture, which takes advantage of a distributed threat detection system to match performance and scalability requirements. The paper also discusses how the platform can be extended to handle the most recent "stealthy" malware as well as campaigns aimed at spreading fake news.
Tipologia CRIS:
04.01 Contributo in Atti di convegno
Keywords:
threat intelligence; risk mitigation; active learning; collaborative approach
Elenco autori:
Zuppelli, Marco; Manco, Giuseppe; Caviglione, Luca; Comito, Carmela; Guarascio, Massimo; Pisani, FRANCESCO SERGIO
Autori di Ateneo:
CAVIGLIONE LUCA
COMITO CARMELA
GUARASCIO MASSIMO
MANCO GIUSEPPE
PISANI FRANCESCO SERGIO
ZUPPELLI MARCO
Link alla scheda completa:
https://iris.cnr.it/handle/20.500.14243/433059
Titolo del libro:
Proceedings of the 31st Symposium of Advanced Database Systems
Pubblicato in:
CEUR WORKSHOP PROCEEDINGS
Series
  • Dati Generali

Dati Generali

URL

https://sebd2023.dei.unipd.it
  • Utilizzo dei cookie

Realizzato con VIVO | Designed by Cineca | 26.5.0.0 | Sorgente dati: PREPROD (Ribaltamento disabilitato)