Additive manufacturing (AM) offers numerous benefits, such as manufacturing complex and customised designs quickly and cost-effectively, reducing material waste, and enabling on-demand production. However, several security challenges are associated with AM, making it increasingly attractive to attackers ranging from individual hackers to organised criminal gangs and nation-state actors. This paper addresses the cyber risk in AM to attackers by proposing a novel semantic-based threat prioritisation system for identifying, extracting and ranking indicators of compromise (IOC). The system leverages the heterogeneous information networks (HINs) that automatically extract high-level IOCs from multi-source threat text and identifies semantic relations among the IOCs. It models IOCs with a HIN comprising different meta-paths and meta-graphs to depict semantic relations among diverse IOCs. We introduce a domain-specific recogniser that identifies IOCs in three domains: organisation-specific, regional source-specific, and regional target-specific. A threat assessment uses similarity measures based on meta-paths and meta-graphs to assess semantic relations among IOCs. It prioritises IOCs by measuring their severity based on the frequency of attacks, IOC lifetime, and exploited vulnerabilities in each domain.
翻译:增材制造(AM)具有诸多优势,例如能够快速且经济地制造复杂和定制化设计、减少材料浪费以及实现按需生产。然而,AM 也伴随着若干安全挑战,这使得其越来越受到从个人黑客到有组织犯罪团伙乃至国家级行为者等各种攻击者的青睐。本文针对AM中攻击者面临的风险,提出了一种新颖的基于语义的威胁优先级排序系统,用于识别、提取和排序入侵指标(IOC)。该系统利用异构信息网络(HIN)从多源威胁文本中自动提取高级IOC,并识别IOC之间的语义关系。它通过包含不同元路径和元图的HIN对IOC进行建模,以描述不同IOC之间的语义关系。我们引入了一种领域特定的识别器,可在三个领域识别IOC:组织特定领域、区域来源特定领域和区域目标特定领域。威胁评估利用基于元路径和元图的相似性度量来评估IOC之间的语义关系。它通过基于攻击频率、IOC生命周期以及每个领域中利用的漏洞来衡量IOC的严重程度,从而对其进行优先级排序。