Daniel Fischer 0003

dblp:16/1569-3 · DBLP profile ↗
← Back
4ranked-venue papers
2as first author
3since 2021 · last 2024
0009-0001-0617-1826ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 3 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2024 The Role of Threat Intelligence Sharing Platforms in Companies, Public Authorities, and Universities: Insights from an Exploratory Global Survey
abstract
Threat intelligence sharing offers a promising discipline to bolster knowledge and situational awareness amidst the rapid emergence of new cyber threats. Numerous platforms in the security solutions market enable effective and targeted sharing of threat intelligence among organizations. However, there is limited knowledge of the diffusion and use of threat intelligence platforms within companies, public authorities, and universities worldwide. To meet this challenge, we conducted an exploratory global survey of 118 security experts from companies, public authorities, and universities. Our findings show that threat intelligence sharing platforms are becoming more mature, evidenced by an increase in their prevalence and the utilization of their functionalities within the threat intelligence life cycle.
Daniel Fischer 0003, Clemens Sauerwein, Marie Liz Sayin, Dirk Stelzer, Ruth Breu
IEEE Big Data1
2023 An Exploratory Study on the Use of Threat Intelligence Sharing Platforms in Germany, Austria and Switzerland
abstract
Threat intelligence sharing is a promising solution to enhance knowledge and situational awareness of the rapidly growing number of emerging cyber threats. Accordingly, there are a variety of platforms on the security solutions market that enable the efficient and targeted exchange of threat intelligence across organisations. Unfortunately, very little is known so far about the dissemination and use of these platforms from the end-user perspective. To address this issue, we conducted an exploratory study on the use of threat intelligence sharing platforms in Germany, Austria and Switzerland. For this purpose, we surveyed 69 security and IT experts from large companies, federal authorities and public universities in autumn 2022. Our findings show, among other things, a growing interest in threat intelligence sharing platforms and their value to information security processes.
Daniel Fischer 0003, Clemens Sauerwein, Martin Werchan, Dirk Stelzer
ARES1
2021 From Threat Data to Actionable Intelligence: An Exploratory Analysis of the Intelligence Cycle Implementation in Cyber Threat Intelligence Sharing Platforms
abstract
In the last couple of years, organizations have demonstrated an increasing willingness to share data, information and intelligence regarding emerging threats to collectively protect against today’s sophisticated cyber attacks. Accordingly, several vendors started to implement software solutions that facilitate this exchange and appear under the name cyber threat intelligence sharing platforms. However, recent investigations have shown that these platforms differ significantly in their functional scope and often only provide threat data instead of the promised actionable intelligence. Moreover, it is unclear to what extent the platforms implement the expected intelligence cycle processes. In order to close this gap, we investigate the state-of-the-art in scientific literature and analyze the functional scope of nine threat intelligence sharing platforms with respect to the intelligence cycle. Our study provides a comprehensive list of software functions that should be implemented by cyber threat intelligence sharing platforms in order to support the intelligence cycle to generate actionable threat intelligence.
Clemens Sauerwein, Daniel Fischer 0003, Milena Rubsamen, Guido Rosenberger, Dirk Stelzer, Ruth Breu
ARES2
2019 Automated Cyber Threat Sensing and Responding: Integrating Threat Intelligence into Security-Policy-Controlled Systems
abstract
Cyber security management requires fast and cost efficient responses to threat alerts. Automation of cyber threat sensing and responding is one way to achieve immediate reactions to imminent threats. There are already tools for an extensive automation of threat sensing, e.g. threat intelligence sharing platforms. Methods, techniques and tools for reacting to menacing states and events, e.g. security-policy-controlled systems, have also been explored and published for some time. What is still missing, however, is the integration of these two approaches. This paper describes first steps towards an integration of threat intelligence sharing platforms and security-policy-controlled systems. We present a conceptual design for threat reaction strategies, security architectures and mechanisms and information representation requirements. We use two exemplary threat scenarios to demonstrate our proposals.
Peter Amthor 0001, Daniel Fischer 0003, Winfried E. Kühnhauser, Dirk Stelzer
ARES2