바로가기메뉴

본문 바로가기 주메뉴 바로가기

Indicators of Compromise Data Generation Method for Malware on Cyber Incident Occurrence in IoT Environments

Journal of The Korea Internet of Things Society / Journal of The Korea Internet of Things Society, (P)2799-4791;
2023, v.9 no.4, pp.1-8
https://doi.org/https://doi.org/10.20465/kiots.2023.9.4.001

  • Downloaded
  • Viewed

Abstract

As cyber attacks become more intelligent and advanced, cyber attacks targeting heterogeneous systems such as Internet of Things (IoT) devices are increasing. There is a need for a technique to share detailed threat information about the incident attack. In the event of an infringement incident, a technique that can express digital forensic artifacts collected from heterogeneous IoT devices as indicators of compromise (IoC) and share them must be established. In particular, when malicious code is executed targeting various IoT devices, an efficient IoC generation method to express cyber threat information and share it among CTI systems must be presented. Therefore, in this study, the existing IoC creation method and expression method were analyzed. A classification system for generating IoC for malware and an efficient and standardized expression method were presented. Based on the proposed IoC expression and standardization method, it is expected that it will be able to actively respond to intelligent attacks when establishing an accident management framework

keywords
IoT, Malware, Cyber Incident, Indicators of Compromise, Cyber Threat Intelligence, 사물인터넷, 멀웨어, 침해사고, 침해지표, 사이버 공격 인텔리전트

Journal of The Korea Internet of Things Society