Por favor, use este identificador para citar o enlazar este ítem: http://hdl.handle.net/10201/149584

Registro completo de metadatos
Campo DCValorLengua/Idioma
dc.contributor.advisorPastor Galindo, Javier-
dc.contributor.advisorRuipérez Valiente, José Antonio-
dc.contributor.authorSánchez González, Felipe-
dc.contributor.otherFacultad de Informáticaes
dc.date.accessioned2025-01-29T07:44:38Z-
dc.date.available2025-01-29T07:44:38Z-
dc.date.created2025-01-20-
dc.date.issued2025-01-29-
dc.identifier.urihttp://hdl.handle.net/10201/149584-
dc.description.abstractCyber Threat Intelligence (CTI) has empowered cybersecurity teams worldwide by improving the quality and speed of their analysis for cybersecurity incidents through the establishment standards and specialized tools. These tools and frameworks facilitate correlation and collaboration across global communities, helping organizations stay informed about the evolving cyber threat landscape. Despite its success in cybersecurity, CTI has yet to be leveraged for the systematic exchange and management of knowledge about disinformation threats, which are often described in unstructured natural language. This thesis introduces DISINFOX, an open-source threat intelligence sharing platform designed to enable the interoperable exchange of disinformation incidents. DISINFOX adapts disinformation-related information to a CTI-compliant format by incorporating several key elements. First, it utilizes the DISARM framework, which provides a matrix similar to MITRE ATT&CK to characterize the tactics, techniques, and procedures (TTPs) of disinformation incidents. Second, a custom mapping codifies these TTPs along with other relevant information, such as actors and targeted countries, into the STIX2 standard. Finally, the platform integrates with OpenCTI to validate its interoperability, alongside a user-friendly, web-based frontend for visualizing, managing, and analyzing incidents. DISINFOX employs a modular, containerized architecture comprising four main components: a backend providing a RESTful API independent of other modules, a frontend serving as the ingestion entry point for disinformation incidents, a public API enabling other CTI solutions to extract incidents from the platform, and the DISINFOX OpenCTI connector that validates the interoperability of incidents within a mature CTI tool. The platform’s capabilities were validated through the modeling, storage, sharing, and consumption of over 100 disinformation incidents, demonstrating its technical feasibility. This work highlights the potential of using CTI concepts and tools to systematically combat disinformation threats.es
dc.formatapplication/pdfes
dc.format.extent47es
dc.languageenges
dc.publisherUniversidad de Murcia, Facultad de Informáticaes
dc.relationSin financiación externa a la Universidades
dc.rightsinfo:eu-repo/semantics/openAccesses
dc.rightsAttribution-NonCommercial-NoDerivatives 4.0 Internacional*
dc.rights.urihttp://creativecommons.org/licenses/by-nc-nd/4.0/*
dc.subjectciberseguridad redeses
dc.subject.other004.4es
dc.titleDISINFOX: A Threat Intelligence sharing platform for disinformation incidentses
dc.typeinfo:eu-repo/semantics/masterThesises
dc.typeinfo:eu-repo/semantics/masterThesises
Aparece en las colecciones:Trabajos académicos del alumnado

Ficheros en este ítem:
Fichero Descripción TamañoFormato 
trabajoFinmaster-Felipez Schez Gonzalez.pdf1,66 MBAdobe PDFVista previa
Visualizar/Abrir


Este ítem está sujeto a una licencia Creative Commons Licencia Creative Commons Creative Commons