Evaluating Cyber Threat Intelligence: Accuracy, Completeness, Relevance, and Freshness

In the realm of cybersecurity, the extraction of Cyber Threat Intelligence (CTI) is vital for acquiring accurate Tactics, Techniques, and Procedures (TTPs) and Indicators of Compromise (IoC) from reputable sources. The extracted CTI must be evaluated to ensure high quality, and different CTI platfor...

وصف كامل

التفاصيل البيبلوغرافية
الحاوية / القاعدة:IEEE Access
المؤلفون الرئيسيون: Asad Ali, Ren-Hung Hwang, Ying-Dar Lin
التنسيق: مقال
اللغة:الإنجليزية
منشور في: IEEE 2025-01-01
الموضوعات:
الوصول للمادة أونلاين:https://ieeexplore.ieee.org/document/11151802/
_version_ 1849264591835496448
author Asad Ali
Ren-Hung Hwang
Ying-Dar Lin
author_facet Asad Ali
Ren-Hung Hwang
Ying-Dar Lin
author_sort Asad Ali
collection DOAJ
container_title IEEE Access
description In the realm of cybersecurity, the extraction of Cyber Threat Intelligence (CTI) is vital for acquiring accurate Tactics, Techniques, and Procedures (TTPs) and Indicators of Compromise (IoC) from reputable sources. The extracted CTI must be evaluated to ensure high quality, and different CTI platforms, such as VirusTotal, AlienVault, and MetaDefender, often yield varying evaluations. A robust method is required that automatically extracts CTI, evaluates it, and provides a verdict on IoCs, determining whether they are malicious, while also evaluating IoC information across multiple platforms. In this work, we propose an automated mechanism that first extracts TTPs and IoCs from reputable threat reports, submits the extracted CTI to multiple platforms, evaluates the platform responses using four key metrics —accuracy, freshness, completeness, and relevance, and provides weighted verdicts for IoCs. We tested 600 IoCs in February 2025, and the weighted verdict matched those of VirusTotal for 79.4%, AlienVault for 87.4%, and MetaDefender for 39.6% of the IoCs. The results also show that VirusTotal provides a consistent evaluation of various types of IoCs in terms of freshness, completeness, and relevance of information, whereas AlienVault shows inconsistencies across all IoC types, and MetaDefender shows inconsistency for some. VirusTotal also outperforms the other two when it comes to providing fresher and more complete intelligence, while AlienVault provides the most relevant information in terms of Structured Threat Information eXpression (STIX) 2.1 objects.
format Article
id doaj-art-a855fe196ee649cbabcff119ead2ca5b
institution Directory of Open Access Journals
issn 2169-3536
language English
publishDate 2025-01-01
publisher IEEE
record_format Article
spelling doaj-art-a855fe196ee649cbabcff119ead2ca5b2025-09-15T23:00:29ZengIEEEIEEE Access2169-35362025-01-011315786315787610.1109/ACCESS.2025.360647711151802Evaluating Cyber Threat Intelligence: Accuracy, Completeness, Relevance, and FreshnessAsad Ali0Ren-Hung Hwang1https://orcid.org/0000-0001-7996-4184Ying-Dar Lin2https://orcid.org/0000-0002-5226-4396National Institute of Cyber Security, Taipei, TaiwanInstitute of Computational Intelligence, National Yang Ming Chiao Tung University, Tainan, TaiwanDepartment of Computer Science, National Yang Ming Chiao Tung University, Hsinchu, TaiwanIn the realm of cybersecurity, the extraction of Cyber Threat Intelligence (CTI) is vital for acquiring accurate Tactics, Techniques, and Procedures (TTPs) and Indicators of Compromise (IoC) from reputable sources. The extracted CTI must be evaluated to ensure high quality, and different CTI platforms, such as VirusTotal, AlienVault, and MetaDefender, often yield varying evaluations. A robust method is required that automatically extracts CTI, evaluates it, and provides a verdict on IoCs, determining whether they are malicious, while also evaluating IoC information across multiple platforms. In this work, we propose an automated mechanism that first extracts TTPs and IoCs from reputable threat reports, submits the extracted CTI to multiple platforms, evaluates the platform responses using four key metrics —accuracy, freshness, completeness, and relevance, and provides weighted verdicts for IoCs. We tested 600 IoCs in February 2025, and the weighted verdict matched those of VirusTotal for 79.4%, AlienVault for 87.4%, and MetaDefender for 39.6% of the IoCs. The results also show that VirusTotal provides a consistent evaluation of various types of IoCs in terms of freshness, completeness, and relevance of information, whereas AlienVault shows inconsistencies across all IoC types, and MetaDefender shows inconsistency for some. VirusTotal also outperforms the other two when it comes to providing fresher and more complete intelligence, while AlienVault provides the most relevant information in terms of Structured Threat Information eXpression (STIX) 2.1 objects.https://ieeexplore.ieee.org/document/11151802/Cyber threat intelligence (CTI)indicators of compromise (IoCs)CTI platformsCTI evaluationnatural language processing
spellingShingle Asad Ali
Ren-Hung Hwang
Ying-Dar Lin
Evaluating Cyber Threat Intelligence: Accuracy, Completeness, Relevance, and Freshness
Cyber threat intelligence (CTI)
indicators of compromise (IoCs)
CTI platforms
CTI evaluation
natural language processing
title Evaluating Cyber Threat Intelligence: Accuracy, Completeness, Relevance, and Freshness
title_full Evaluating Cyber Threat Intelligence: Accuracy, Completeness, Relevance, and Freshness
title_fullStr Evaluating Cyber Threat Intelligence: Accuracy, Completeness, Relevance, and Freshness
title_full_unstemmed Evaluating Cyber Threat Intelligence: Accuracy, Completeness, Relevance, and Freshness
title_short Evaluating Cyber Threat Intelligence: Accuracy, Completeness, Relevance, and Freshness
title_sort evaluating cyber threat intelligence accuracy completeness relevance and freshness
topic Cyber threat intelligence (CTI)
indicators of compromise (IoCs)
CTI platforms
CTI evaluation
natural language processing
url https://ieeexplore.ieee.org/document/11151802/
work_keys_str_mv AT asadali evaluatingcyberthreatintelligenceaccuracycompletenessrelevanceandfreshness
AT renhunghwang evaluatingcyberthreatintelligenceaccuracycompletenessrelevanceandfreshness
AT yingdarlin evaluatingcyberthreatintelligenceaccuracycompletenessrelevanceandfreshness