Investigating the Temporal Dynamics of Cyber Threat Intelligence
Angel Kodituwakku, Clark Xu, Daniel Rogers, David K. Ahn, Errin W., Fulp

TL;DR
This study analyzes the timing and patterns of IoC publication related to CVEs, revealing a recurring epidemic-like pattern that impacts cybersecurity defense strategies and emphasizes the need for continuous vigilance.
Contribution
It provides an in-depth analysis of the temporal dynamics of IoC publication for CVEs, filling a gap in understanding how IoCs evolve over time in cyber threat intelligence.
Findings
IoC publication rates follow an epidemic-like pattern over time.
Initial IoC publication is sparse after vulnerability disclosure.
There is a surge in IoC publications followed by a slower, prolonged phase.
Abstract
Indicators of Compromise (IoCs) play a crucial role in the rapid detection and mitigation of cyber threats. However, the existing body of literature lacks in-depth analytical studies on the temporal aspects of IoC publication, especially when considering up-to-date datasets related to Common Vulnerabilities and Exposures (CVEs). This paper addresses this gap by conducting an analysis of the timeliness and comprehensiveness of Cyber Threat Intelligence (CTI) pertaining to several recent CVEs. The insights derived from this study aim to enhance cybersecurity defense strategies, particularly when dealing with dynamic cyber threats that continually adapt their Tactics, Techniques, and Procedures (TTPs). Utilizing IoCs sourced from multiple providers, we scrutinize the IoC publication rate. Our analysis delves into how various factors, including the inherent nature of a threat, its…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
