Journal of Civil Aviation University of China ›› 2024, Vol. 42 ›› Issue (4): 29-36.

• Safety and airworthiness of civil aircraft • Previous Articles     Next Articles

Quality evaluation method of cyber threat intelligence based on multi-source heterogeneous data

ZHOU Jingxian   LI Qiwei  CHENG Zhipeng#br#   

  1. (1a. Information Security Evaluation Center; 1b. College of Computer Science and Technology, CAUC, Tianjin 300300, China;
    2. Communication Network Center of North China Air Traffic Management Bureau, CAAC, Beijing 100621, China)
  • Received:2023-08-21 Revised:2024-01-17 Online:2024-12-19 Published:2024-12-21

Abstract: With the diversification of cyber attacks forms and the complexity of attack methods, cyber threat intelligence (CTI)
has become an important means of dealing with unknown cyber threats. To effectively solve the problem of difficulty
to evaluate CTI quality due to the wide source and high repeatability, this paper proposes ISU-Measure (intelligent-source-user measure), a quality evaluation method of CTI based on multi-source heterogeneous data. Firstly,
timeliness, activity, relevance and completeness are designed as quantitative indicators to characterize the quality
of micro threat intelligence. Secondly, it is proposed to use scale, periodicity and originality as quantitative indicators to evaluate the overall quality of threat intelligence sources. Then, based on the differences in user needs, user
indicator preferences are designed and combing with the Critic weighting method, composite weight is generated.
At the same time, seven quantitative indicators are weighted to construct a quantitative evaluation model. The quality evaluation results of 12 mainstream threat intelligence sources show that the composite weighting method designed by the ISU-Measure method is superior to the Critic weighting method and the mean method, and has significant advantages in indicator coverage, acquisition difficulty and discrimination, compared with other research
methods.

Key words: cyber security, threat intelligence, multi-source intelligence, quantitative evaluation, Critic weighting method

CLC Number: