HEИндивидуална стипендия2022–2025

OPTIMA · Organization sPecific Threat Intelligence Mining and sharing

„Хоризонт Европа“ — Действия „Мария Склодовска-Кюри“

Период
2022-12-01 → 2025-03-31
Финансиране от ЕС
188 590 €
Участници
4
Схема
HORIZON-TMA-MSCA-PF-EF

Линиите свързват координатора с партньорите.

Накратко на български

Методи за автоматично откриване на киберзаплахи чрез анализ на данни от отворени източници, например за болници или банки. Това помага на организациите да разпознават нови атаки и да споделят информация за тях анонимно и сигурно.

Този кратък обзор е генериран от изкуствен интелект

Кратко обяснение, генерирано от езиков модел по текста на CORDIS. Оригиналът е по-долу.

Резултати накратко

Organization sPecific Threat Intelligence Mining and sharing

Digitalisation is creating new opportunities in finance, healthcare, industrial control systems, network security, and AI-driven cybersecurity, but it also introduces critical risks. These include cyber threats, adversarial AI attacks, privacy concerns, and regulatory challenges. To maximize the benefits while mitigating risks, organisations must adopt explainable AI, privacy-preserving federated learning, secure blockchain integration, and proactive cyber threat intelligence mechanisms. Strengthening cybersecurity frameworks with robust attack detection, secure data-sharing, and adversarial resilience is essential to ensure a secure digital future. Thus, the OPTIMA project (Organization sPecific Threat Intelligence Mining and sharing) aimed to design techniques and tools for the extraction of Threat Intelligence targeted to organizations using ML algorithms, and effectively share attack records using privacy-preserving methods. The Research & Innovation Objectives (RIO) of the project are as follows: 1. RIO1-To develop techniques for automatic extraction of threat intelligence using OSINT data for multiple institutions (eg., health care, finance, IoT, education) using deep learning approaches. 2. RIO2-To create a novel automated system to derive Indicator of Compromise (IOC) based on word embedding and syntactic dependencies of words to identify unseen IOCs. Utilizing the extracted IOCs a threat index will be estimated to define the impact of threat and attack trends across individual organizations; 3. RIO3-To build a system by integrating cryptographic tools and Federated learning which will enable an organization to anonymously share threat logs with different parties in a privacy-preserving manner. The OPTIMA project (Organization-sPecific Threat Intelligence Mining and shAring) developed advanced AI-driven tools and frameworks to generate, analyze, and securely share cyber threat intelligence (CTI) tailored to organizational needs. The core outcome, OSTIS, enables organization-specific CTI generation through a dedicated crawler and NLP pipeline that extracts threat data from reliable sources, classifies it by domain (e.g., healthcare, finance), and visualizes attack patterns via knowledge graphs. Explainable AI tools like SHAP were integrated to interpret threat predictions and support trust in automation. Complementing OSTIS, we proposed SeCTIS, a privacy-preserving CTI sharing framework using Blockchain and Swarm Learning. SeCTIS ensures secure collaboration and verifiable trust among participants through Zero-Knowledge Proofs. The MoRSE and IntellBot systems advanced AI-based CTI delivery by deploying Retrieval-Augmented Generation (RAG) models to provide accurate, real-time cybersecurity insights. Additionally, our efforts in darknet traffic analysis, malware visualization, and multi-modal threat detection delivered interpretable models using SHAP, GradCAM, and LIME. In parallel, we addressed security in federated learning (FL) with tools like DLShield, SecDefender, and LFGuard, which detect low-quality or poisoned models and improve global accuracy while preserving privacy. Through these contributions, OPTIMA has enhanced both the granularity and trustworthiness of CTI across diverse domains, enabling proactive, explainable, and collaborative cybersecurity defense.

Текст от CORDIS, на английски · Данни: CORDIS, © Европейски съюз

Цел на проекта

The OPTIMA project (Organization sPecific Threat Intelligence Mining and sharing) aims to design techniques and tools for the extraction of Threat Intelligence targeted to organizations using ML algorithms, and effectively share attack records using privacy-preserving methods. The project will use technologies to protect societies from cyber-attacks and sophisticated threats prioritized in the European Council’s New Strategic Agenda. The key beneficiaries of the project are (a) security operation center-to support real time monitoring (b) incident response, threat hunting, fraud detection team-to prioritize risk (c), operational leaders- to prioritize activities of IT staff and (d) Strategic leaders such as Chief Information Security Officers - to make well-informed business decisions. This project will be executed at the University of Padua, under the supervision of Prof. Mauro Conti. The project will investigate solutions for the core questions: RQ1: How effectively can ML algorithms extract organization-specific threat artefacts to be utilized for preparing actionable Threat Intelligence? RQ2: How can organizations share threat intelligence without disclosing their private information to others?The objectives (SO) of the project are as follows: 1.SO1-To develop techniques for automatic extraction of threat intelligence using OSINT data for diverse IT industries (health care, finance, IoT, education, etc.) using deep learning approaches.2.SO2-To create a novel automated system to derive Indicator of Compromise (IOC) based on word embedding and syntactic dependencies of words to identify unseen IOCs. Utilizing the extracted IOCs a threat index will be estimated to define the impact of threat and attack trends across individual organizations;3.SO3-To build a system by integrating cryptographic tools and Federated learning which will enable an organization to anonymously share threat logs with different parties in a privacy-preserving manner

Оригинален текст от CORDIS (на английски).

Участници

Връзки

Данни: CORDIS, © Европейски съюз