Security technologies and methods for advanced cyber threat intelligence, detection and mitigation /

The rapid growth of the Internet interconnectivity and complexity of communication systems has led us to a significant growth of cyberattacks globally often with severe and disastrous consequences. The swift development of more innovative and effective (cyber)security solutions and approaches are vi...

Full description

Bibliographic Details
Corporate Author: Emerald Publishing Group
Other Authors: Sargsyan, Gohar, 1956- (Editor), Kavallieros, Dimitrios (Editor), Kolokotronis, Nicholas (Editor)
Format: eBook
Language:English
Published: Hanover, MA : Now Publishers, [2022]
Subjects:
Online Access:Connect to the full text of this electronic book
Table of Contents:
  • Cover
  • Security Technologies and Methods for Advanced Cyber Threat Intelligence, Detection and Mitigation
  • Copyright Page
  • Contents
  • Dedication
  • Preface
  • Executive Summary
  • 1: How to Design and Set Architecture for Advanced Cyber-Threat Intelligence, Detection, and Mitigation Platforms
  • 1.1 Background and Driving Forces
  • 1.2 Architecture Approach and Methodology
  • 1.2.1 Risk and Cost Driven Architecture Methodology (RCDA)
  • 1.2.2 Architecture Views
  • 1.2.3 Compliance and Security
  • 1.3 Solution, Context and Overviews
  • 1.3.1 Context
  • 1.3.2 Static Solution Overview
  • 1.3.3 Runtime Solution Overview
  • 1.4 Conclusions
  • Acknowledgment
  • References
  • 2: The Cyber-Trust Paradigm of Procedural Aspects for Cybersecurity Research Impact Assessment
  • 2.1 Introduction and Background
  • 2.2 The Rationale Behind an Impact Assessment in a Cyber-security Research Project
  • 2.3 The Rationale Behind an Impact Assessment in Cyber-Trust
  • 2.4 Existing Guidance
  • 2.5 The Seven Steps
  • 2.5.1 First Step: Establishing the Legal and Regulatory Framework at the Start of the Project
  • 2.5.2 Second Step: First Wide Consultation Among Partners to Define Together the Way Forward
  • 2.5.3 Third Step: Carrying Out, Completing and Reporting About the Impact Assessment
  • 2.5.4 Fourth Step: Workshop to Discuss and Validate the Impact Assessment Outcomes
  • 2.5.5 Fifth Step: Continuous Communication During the Development
  • 2.5.6 Sixth Step: Check Before the Pilots
  • 2.5.7 Seventh Step: Review and Second Assessment Report
  • 2.6 Lessons Learnt
  • 2.7 Concluding Remarks
  • Acknowledgment
  • References
  • 3: Cyber-Threat Intelligence
  • 3.1 Introduction
  • 3.2 INTIME Architecture
  • 3.3 Data Acquisition Module
  • 3.3.1 The Crawling Submodule
  • 3.3.2 The Social Media Monitoring Submodule
  • 3.3.3 Submodules for Monitoring Structured Sources
  • 3.4 Data Analysis Modules
  • 3.4.1 The Content Ranking Submodule
  • 3.4.2 The CTI Extraction Submodule
  • 3.5 Data Management and Sharing
  • 3.5.1 Component Overview
  • 3.5.2 MISP
  • 3.5.3 MISP Implementation and Customization
  • 3.5.4 Component Functionality
  • 3.6 Conclusions
  • Acknowledgment
  • References
  • 4: Moving-Target Defense Techniques for Mitigating Sophisticated IoT Threats
  • 4.1 Introduction
  • 4.2 Background and Related Work
  • 4.3 System Modelling
  • 4.3.1 Attack Graphs
  • 4.3.2 Response Generation
  • 4.3.3 Decision-making Process
  • 4.3.4 Further Adjustments
  • 4.4 Attack Strategies
  • 4.4.1 The Mirai Botnet
  • 4.4.2 Zero-Day Attacks
  • 4.5 Experimental Setup
  • 4.5.1 The Mirai Attack Scenario
  • 4.6 IRS Evaluation
  • 4.6.1 Configuration Options
  • 4.6.2 Evaluation Results
  • 4.7 Conclusions
  • Acknowledgment
  • References
  • 5: Cyber-Threat Detection in the IoT
  • 5.1 Introduction: Background and Related Work
  • 5.1.1 Major Cyber Threats to IoT
  • 5.1.2 IoT Threat Detection Methods