Por favor, use este identificador para citar o enlazar este ítem:
http://hdl.handle.net/10201/149584


Registro completo de metadatos
Campo DC | Valor | Lengua/Idioma |
---|---|---|
dc.contributor.advisor | Pastor Galindo, Javier | - |
dc.contributor.advisor | Ruipérez Valiente, José Antonio | - |
dc.contributor.author | Sánchez González, Felipe | - |
dc.contributor.other | Facultad de Informática | es |
dc.date.accessioned | 2025-01-29T07:44:38Z | - |
dc.date.available | 2025-01-29T07:44:38Z | - |
dc.date.created | 2025-01-20 | - |
dc.date.issued | 2025-01-29 | - |
dc.identifier.uri | http://hdl.handle.net/10201/149584 | - |
dc.description.abstract | Cyber Threat Intelligence (CTI) has empowered cybersecurity teams worldwide by improving the quality and speed of their analysis for cybersecurity incidents through the establishment standards and specialized tools. These tools and frameworks facilitate correlation and collaboration across global communities, helping organizations stay informed about the evolving cyber threat landscape. Despite its success in cybersecurity, CTI has yet to be leveraged for the systematic exchange and management of knowledge about disinformation threats, which are often described in unstructured natural language. This thesis introduces DISINFOX, an open-source threat intelligence sharing platform designed to enable the interoperable exchange of disinformation incidents. DISINFOX adapts disinformation-related information to a CTI-compliant format by incorporating several key elements. First, it utilizes the DISARM framework, which provides a matrix similar to MITRE ATT&CK to characterize the tactics, techniques, and procedures (TTPs) of disinformation incidents. Second, a custom mapping codifies these TTPs along with other relevant information, such as actors and targeted countries, into the STIX2 standard. Finally, the platform integrates with OpenCTI to validate its interoperability, alongside a user-friendly, web-based frontend for visualizing, managing, and analyzing incidents. DISINFOX employs a modular, containerized architecture comprising four main components: a backend providing a RESTful API independent of other modules, a frontend serving as the ingestion entry point for disinformation incidents, a public API enabling other CTI solutions to extract incidents from the platform, and the DISINFOX OpenCTI connector that validates the interoperability of incidents within a mature CTI tool. The platform’s capabilities were validated through the modeling, storage, sharing, and consumption of over 100 disinformation incidents, demonstrating its technical feasibility. This work highlights the potential of using CTI concepts and tools to systematically combat disinformation threats. | es |
dc.format | application/pdf | es |
dc.format.extent | 47 | es |
dc.language | eng | es |
dc.publisher | Universidad de Murcia, Facultad de Informática | es |
dc.relation | Sin financiación externa a la Universidad | es |
dc.rights | info:eu-repo/semantics/openAccess | es |
dc.rights | Attribution-NonCommercial-NoDerivatives 4.0 Internacional | * |
dc.rights.uri | http://creativecommons.org/licenses/by-nc-nd/4.0/ | * |
dc.subject | ciberseguridad redes | es |
dc.subject.other | 004.4 | es |
dc.title | DISINFOX: A Threat Intelligence sharing platform for disinformation incidents | es |
dc.type | info:eu-repo/semantics/masterThesis | es |
dc.type | info:eu-repo/semantics/masterThesis | es |
Aparece en las colecciones: | Trabajos académicos del alumnado |
Ficheros en este ítem:
Fichero | Descripción | Tamaño | Formato | |
---|---|---|---|---|
trabajoFinmaster-Felipez Schez Gonzalez.pdf | 1,66 MB | Adobe PDF | ![]() Visualizar/Abrir |
Este ítem está sujeto a una licencia Creative Commons Licencia Creative Commons