Source-linked AI summary

Cyber Threat Intelligence Model: An Evaluation of Taxonomies, Sharing Standards, and Ontologies within Cyber Threat Intelligence

Vasileios Mavroeidis, Siri Bromander

arXiv:2103.03530v5cs.CR

TL;DR

Cyber threat intelligence needs structured, machine-readable representations that are expressive and unambiguous, yet comprehensive ontology development remains limited. This paper evaluates relevant taxonomies, sharing standards, and ontologies using a cyber threat intelligence model and finds persistent ambiguity, weak interoperability, insufficient relationships, and limited semantic reasoning support.

  • Problem

    Cyber threat intelligence requires expressive, unambiguous, machine-readable representations, but dedicated ontologies supporting diverse intelligence types remain limited.

  • Method

    The study uses a cyber threat intelligence model to evaluate the coverage, expressivity, integration, interoperability, and knowledge-engineering quality of relevant taxonomies, sharing standards, and ontologies.

  • Results

    The analysis confirms that existing efforts are incomplete, ambiguous, non-interoperable, weakly connected, and limited in semantic axioms and reasoning support.

  • Takeaways & Limitations

    A comprehensive cyber threat intelligence ontology should be modular, extensible, contextual, unambiguous, and able to support explainable knowledge graphs and automated reasoning.

  • Takeaways & Limitations

    Existing taxonomy encodings and integrations are limited, including missing interconnections with ontologies needed for standardized and expressive representations.

Abstract

from arXiv · show

Cyber threat intelligence is the provision of evidence-based knowledge about existing or emerging threats. Benefits from threat intelligence include increased situational awareness, efficiency in security operations, and improved prevention, detection, and response capabilities. To process, correlate, and analyze vast amounts of threat information and data and derive intelligence that can be shared and consumed in meaningful times, it is required to utilize structured, machine-readable formats that incorporate the industry-required expressivity while at the same time being unambiguous. To a large extent, this is achieved with technologies like ontologies, schemas, and taxonomies. This research evaluates the coverage and high-level conceptual expressivity of cyber-threat-intelligence-relevant ontologies, sharing standards, and taxonomies pertaining to the who, what, why, where, when, and how elements of threats and attacks in addition to courses of action and technical indicators. The results confirm that little emphasis has been given to developing a comprehensive cyber threat intelligence ontology, with existing efforts being not thoroughly designed, non-interoperable, ambiguous, and lacking proper semantics and axioms for reasoning.

I. INTRODUCTION

Cyber threat intelligence requires structured, machine-readable representations to support large-scale processing and sharing, but current ontology efforts remain limited and ambiguous. The study evaluates existing approaches against the information needed to represent threats, operations, indicators, and courses of action.

  • Traditional defense approaches are insufficient against increasingly capable, persistent, and complex attacks.
  • Cyber threat intelligence provides evidence-based knowledge and actionable context to inform responses, improve situational awareness, and support security operations.
  • Machine-readable knowledge representations are needed to process, correlate, and analyze intelligence at scale.
  • The study identifies limited dedicated ontology design, ambiguity, poor interoperability, weak concept relationships, and minimal semantic axioms as major barriers.
  • The proposed cyber threat intelligence model distinguishes information needed to represent the five W’s and one H, technical indicators, and courses of action.

II. METHODOLOGY

The methodology section introduces two related maturity and representation models. The modified cyber threat intelligence model is used to assess existing intelligence resources.

  • A. The Detection Maturity Level Model - DML: The Detection Maturity Level model describes an organization’s maturity in consuming and acting on cyber threat intelligence.
  • A. The Detection Maturity Level Model - DML: The modified DML model adds an Identity level to support semantic representation of cyber threats.

B. The Cyber Threat Intelligence Model

The cyber threat intelligence model organizes threat information across actor identity, motivation, goals, strategy, TTPs, attack patterns, infrastructure, malware, tools, indicators, targets, and courses of action.

  • Identity can refer to a person, organization, group, nation-state-backed entity, or persona-based threat-actor profile.
  • Motivation describes the driving force behind actions and can help narrow likely targets and defensive priorities.
  • Goals describe desired attack endpoints, but current threat-intelligence approaches often represent them in prose and lack consistent taxonomies.
  • Strategy is a non-technical description of the planned attack approach, while TTPs characterize technically oriented adversary behavior.
  • The model includes malware, infrastructure, tools, indicators of compromise, targets, and courses of action as operational or defensive information elements.
  • Atomic indicators such as email addresses, domain names, and IPs may have limited context and short shelf lives.

C. Evaluation Criteria

The study evaluates taxonomies, sharing standards, and ontologies using coverage, integration, expressivity, interoperability, and knowledge-engineering quality criteria.

  • The cyber threat intelligence model is used to assess which information and concepts each evaluated work covers.
  • The evaluation identifies integrations among ontologies, taxonomies, and sharing schemas that support coverage, expressivity, and interoperability.
  • The study examines semantic relationships, axioms, comprehensiveness, and whether ontological efforts support deductive reasoning or information inference.
  • Incomplete descriptions, unavailable RDF/OWL files, and missing documentation make some ontologies difficult to evaluate.

III. TAXONOMIES AND SHARING STANDARDS

This section categorizes cyber threat intelligence representation resources into enumerations, scoring systems, and sharing standards.

  • Taxonomies and sharing standards are further categorized into enumerations, scoring systems, and sharing standards.

A. Enumerations

The enumerations cover threat agents, motivations, vulnerabilities, platforms, weaknesses, attack patterns, and adversary behaviors.

  • TAL standardizes definitions and descriptions of significant threat agents for risk management, without representing individual actors.
  • Casey’s taxonomy identifies drivers motivating threat actors to commit illegal acts and potentially indicates expected harmful actions.
  • CVE records publicly known information-security vulnerabilities in software packages.
  • NVD provides standards-based vulnerability-management data and analyzes CVEs to derive severity metrics, weakness associations, and platform applicability statements.
  • CPE standardizes machine-readable names for IT product classes, while CWE catalogs software and hardware security weaknesses.
  • CAPEC describes adversarial techniques and attributes used to exploit known weaknesses, whereas ATT&CK details adversary lifecycle phases and TTPs.

B. Scoring Systems

The scoring systems assign severity or priority to vulnerabilities and weaknesses to support remediation and risk decisions.

  • CVSS scores software vulnerabilities according to severity and can help prioritize remediation when combined with timely threat intelligence.
  • CWSS scores and prioritizes software weaknesses using 18 factors, with CWRAF supporting business-specific CWE prioritization.

C. Sharing Standards

The sharing standards differ in scope, from broad threat-information exchange to high-fidelity malware communication and low-level compromise indicators.

  • STIX is the most-used threat-information-sharing standard and represents observables, indicators, incidents, adversary activity, campaigns, actors, targets, and courses of action.
  • MAEC encodes high-fidelity malware information based on behaviors, artifacts, and attack patterns, either standalone or integrated with STIX.
  • OpenIOC is an extensible XML schema for describing technical characteristics of threats, attacker methodologies, and evidence of compromise.

IV. ONTOLOGIES

The surveyed ontologies address varied cybersecurity domains and use cases, but few directly support comprehensive cyber threat intelligence representation. Evaluation is hindered by high-level descriptions, missing ontology files, disconnected efforts, and inconsistent terminology.

  • Interoperability: The literature lacks a shared conceptual basis: similar concepts use different terms, and the Cyber Intelligence Ontology is not connected or unified with its included standards and taxonomies.These conditions complicate ontology combination, integration, and adoption.
  • Scope and coverage: Few identified ontologies directly address threat information and intelligence representation, while many broader cybersecurity ontologies map poorly to the CTI model.Several efforts were described only at a high level and lacked RDF/OWL files, making evaluation and abstraction-layer mapping difficult.
  • Scope and coverage: Existing efforts cover specialized areas including vulnerability management, intrusion detection, malware behavior, attack surfaces, security metrics, and cyber operations.Examples include OVM, MBO, Attack Surface Reasoning, the Security Metric Ontology, and CRATELO.
  • Representative approaches: CRATELO combines top-, middle-, and low-level ontologies to represent threats, vulnerabilities, attacks, countermeasures, assets, and cyber operations.Its layered design extends DOLCE-SPRAY through SECCO and OSCO.
  • Representative approaches: Malware-focused ontologies use behavioral hierarchies and SWRL-based inference to identify suspicious executions and complex malware involving multiple exploit methods.The modeled behaviors include attack launching, evasion, remote control, self-defense, stealing, and subversion.

V. DISCUSSION

The discussion argues that cyber threat intelligence needs unambiguous, expressive, and explainable representations. It presents the model as a blueprint for modular ontology development and links interoperability and reasoning to standardized taxonomies and formal ontology expressions.

  • Requirements: Cyber threat intelligence requires unambiguous representations with sufficient expressivity and explainable relationships across concepts.These properties are needed to leverage ontologies and description logics in CTI.
  • Reference architecture: The cyber threat intelligence model provides a high-level reference architecture for developing a comprehensive ontology that is modular, extensible, and adaptive.The model is positioned as a conceptual blueprint rather than a complete ontology.
  • Reference architecture: Modularity and extensibility allow domain-focused ontologies to be replaced or integrated into more holistic representations tailored to organizational use cases.This supports expanding representation across a domain of interest.
  • Reasoning: OWL expressions encode domain expertise, make implicit knowledge explicit, and allow reasoners to infer new information from asserted information at machine speed.The evaluated ontologies commonly lacked these expressions.
  • Interoperability: Limited taxonomy encoding and weak connections between taxonomies and ontologies constrain standardized, interoperable, expressive, and unambiguous representations.The discussion identifies threat-actor motivations, goals, and types as examples of taxonomies needing integration.
  • Reasoning: A suitable CTI ontology should form a knowledge graph containing historical, present, and inferred information that analysts can use for assessment and knowledge-gap work.The representation is intended to support analytical tasks assisted by automated reasoning.

VI. CONCLUSION

The study concludes that a contextual and unambiguous cyber threat intelligence ontology remains incomplete. It identifies barriers spanning coverage, terminology, queryability, explainability, and formal reasoning.

  • Conclusion: The study concludes that much work remains before achieving a contextual and unambiguous cyber threat intelligence ontology.This is the paper’s overall conclusion about the state of the field.
  • Conclusion: Key barriers include limited dedicated CTI ontology efforts covering strategic, operational, and tactical intelligence levels.The conclusion treats multi-level coverage as an unresolved development need.
  • Conclusion: Ambiguous concepts hinder ontology integration and adoption, while extensive prose and limited taxonomy use undermine knowledge-graph queryability and reasoning.These barriers affect both interoperability and analytical use.
  • Conclusion: Missing relationships between concepts weaken interpretation and explainability, and minimal axioms and expressions limit consistency checking and inference.The conclusion identifies formal semantics as a central unresolved requirement.
Loading 2103.03530v5…