Evaluating Cyber Threat Intelligence: Accuracy, Completeness, Relevance, and Freshness
In the realm of cybersecurity, the extraction of Cyber Threat Intelligence (CTI) is vital for acquiring accurate Tactics, Techniques, and Procedures (TTPs) and Indicators of Compromise (IoC) from reputable sources. The extracted CTI must be evaluated to ensure high quality, and different CTI platfor...
| الحاوية / القاعدة: | IEEE Access |
|---|---|
| المؤلفون الرئيسيون: | , , |
| التنسيق: | مقال |
| اللغة: | الإنجليزية |
| منشور في: |
IEEE
2025-01-01
|
| الموضوعات: | |
| الوصول للمادة أونلاين: | https://ieeexplore.ieee.org/document/11151802/ |
| _version_ | 1849264591835496448 |
|---|---|
| author | Asad Ali Ren-Hung Hwang Ying-Dar Lin |
| author_facet | Asad Ali Ren-Hung Hwang Ying-Dar Lin |
| author_sort | Asad Ali |
| collection | DOAJ |
| container_title | IEEE Access |
| description | In the realm of cybersecurity, the extraction of Cyber Threat Intelligence (CTI) is vital for acquiring accurate Tactics, Techniques, and Procedures (TTPs) and Indicators of Compromise (IoC) from reputable sources. The extracted CTI must be evaluated to ensure high quality, and different CTI platforms, such as VirusTotal, AlienVault, and MetaDefender, often yield varying evaluations. A robust method is required that automatically extracts CTI, evaluates it, and provides a verdict on IoCs, determining whether they are malicious, while also evaluating IoC information across multiple platforms. In this work, we propose an automated mechanism that first extracts TTPs and IoCs from reputable threat reports, submits the extracted CTI to multiple platforms, evaluates the platform responses using four key metrics —accuracy, freshness, completeness, and relevance, and provides weighted verdicts for IoCs. We tested 600 IoCs in February 2025, and the weighted verdict matched those of VirusTotal for 79.4%, AlienVault for 87.4%, and MetaDefender for 39.6% of the IoCs. The results also show that VirusTotal provides a consistent evaluation of various types of IoCs in terms of freshness, completeness, and relevance of information, whereas AlienVault shows inconsistencies across all IoC types, and MetaDefender shows inconsistency for some. VirusTotal also outperforms the other two when it comes to providing fresher and more complete intelligence, while AlienVault provides the most relevant information in terms of Structured Threat Information eXpression (STIX) 2.1 objects. |
| format | Article |
| id | doaj-art-a855fe196ee649cbabcff119ead2ca5b |
| institution | Directory of Open Access Journals |
| issn | 2169-3536 |
| language | English |
| publishDate | 2025-01-01 |
| publisher | IEEE |
| record_format | Article |
| spelling | doaj-art-a855fe196ee649cbabcff119ead2ca5b2025-09-15T23:00:29ZengIEEEIEEE Access2169-35362025-01-011315786315787610.1109/ACCESS.2025.360647711151802Evaluating Cyber Threat Intelligence: Accuracy, Completeness, Relevance, and FreshnessAsad Ali0Ren-Hung Hwang1https://orcid.org/0000-0001-7996-4184Ying-Dar Lin2https://orcid.org/0000-0002-5226-4396National Institute of Cyber Security, Taipei, TaiwanInstitute of Computational Intelligence, National Yang Ming Chiao Tung University, Tainan, TaiwanDepartment of Computer Science, National Yang Ming Chiao Tung University, Hsinchu, TaiwanIn the realm of cybersecurity, the extraction of Cyber Threat Intelligence (CTI) is vital for acquiring accurate Tactics, Techniques, and Procedures (TTPs) and Indicators of Compromise (IoC) from reputable sources. The extracted CTI must be evaluated to ensure high quality, and different CTI platforms, such as VirusTotal, AlienVault, and MetaDefender, often yield varying evaluations. A robust method is required that automatically extracts CTI, evaluates it, and provides a verdict on IoCs, determining whether they are malicious, while also evaluating IoC information across multiple platforms. In this work, we propose an automated mechanism that first extracts TTPs and IoCs from reputable threat reports, submits the extracted CTI to multiple platforms, evaluates the platform responses using four key metrics —accuracy, freshness, completeness, and relevance, and provides weighted verdicts for IoCs. We tested 600 IoCs in February 2025, and the weighted verdict matched those of VirusTotal for 79.4%, AlienVault for 87.4%, and MetaDefender for 39.6% of the IoCs. The results also show that VirusTotal provides a consistent evaluation of various types of IoCs in terms of freshness, completeness, and relevance of information, whereas AlienVault shows inconsistencies across all IoC types, and MetaDefender shows inconsistency for some. VirusTotal also outperforms the other two when it comes to providing fresher and more complete intelligence, while AlienVault provides the most relevant information in terms of Structured Threat Information eXpression (STIX) 2.1 objects.https://ieeexplore.ieee.org/document/11151802/Cyber threat intelligence (CTI)indicators of compromise (IoCs)CTI platformsCTI evaluationnatural language processing |
| spellingShingle | Asad Ali Ren-Hung Hwang Ying-Dar Lin Evaluating Cyber Threat Intelligence: Accuracy, Completeness, Relevance, and Freshness Cyber threat intelligence (CTI) indicators of compromise (IoCs) CTI platforms CTI evaluation natural language processing |
| title | Evaluating Cyber Threat Intelligence: Accuracy, Completeness, Relevance, and Freshness |
| title_full | Evaluating Cyber Threat Intelligence: Accuracy, Completeness, Relevance, and Freshness |
| title_fullStr | Evaluating Cyber Threat Intelligence: Accuracy, Completeness, Relevance, and Freshness |
| title_full_unstemmed | Evaluating Cyber Threat Intelligence: Accuracy, Completeness, Relevance, and Freshness |
| title_short | Evaluating Cyber Threat Intelligence: Accuracy, Completeness, Relevance, and Freshness |
| title_sort | evaluating cyber threat intelligence accuracy completeness relevance and freshness |
| topic | Cyber threat intelligence (CTI) indicators of compromise (IoCs) CTI platforms CTI evaluation natural language processing |
| url | https://ieeexplore.ieee.org/document/11151802/ |
| work_keys_str_mv | AT asadali evaluatingcyberthreatintelligenceaccuracycompletenessrelevanceandfreshness AT renhunghwang evaluatingcyberthreatintelligenceaccuracycompletenessrelevanceandfreshness AT yingdarlin evaluatingcyberthreatintelligenceaccuracycompletenessrelevanceandfreshness |
