OSINT와 기업 내 사이버 위협 인텔리전스를 통한 효과적인 위험 대응 기법

Vol. 34, No. 5, pp. 949-959, 10월. 2024
10.13089/JKIISC.2024.34.5.949, Full Text:
Keywords: CTI, OSINT, Threat, Honeypot, risk management
Abstract

Recently, as enterprises utilize the cloud and artificial intelligence, it is becoming increasingly difficult to protect exposed interfaces with existing perimeter security methods. Accordingly, zero trust-based comprehensive risk management is becoming necessary. Most enterprises use vulnerability inspection and bug bounty (security vulnerability reporting system) as basic risk management methods, but it is difficult to effectively respond to unpredictable problems such as zero-day attacks or open source vulnerabilities with these methods alone. Therefore, in this paper, we propose a risk response technique for the entire enterprise that links external OSINT (open source information) and CTI of national government agencies to detect threats through CTI (cyber threat intelligence) and collects the enterprise’s own CTI. As a result of comparing the method of threat detection and blocking that collects the enterprise’s own CTI by configuring a honeypot for effective threat detection and links it to the CTI of an external government agency, the proposed technique showed a 65.8% higher performance improvement in detection accuracy and verified the effect of reducing the number of attackers in the organization through this method

Statistics
Show / Hide Statistics

Statistics (Cumulative Counts from December 1st, 2017)
Multiple requests among the same browser session are counted as one view.
If you mouse over a chart, the values of data points will be shown.


Cite this article
[IEEE Style]
문광석 and 허준범, "Effective Risk Management Technique through OSINT and Cyber Threat Intelligence within the Enterprise," Journal of The Korea Institute of Information Security and Cryptology, vol. 34, no. 5, pp. 949-959, 2024. DOI: 10.13089/JKIISC.2024.34.5.949.

[ACM Style]
문광석 and 허준범. 2024. Effective Risk Management Technique through OSINT and Cyber Threat Intelligence within the Enterprise. Journal of The Korea Institute of Information Security and Cryptology, 34, 5, (2024), 949-959. DOI: 10.13089/JKIISC.2024.34.5.949.