Skip to main content
QUICK REVIEW

[Paper Review] Research Directions in Cyber Threat Intelligence

Stjepan Groš|arXiv (Cornell University)|Jan 18, 2020
Advanced Malware Detection Techniques11 references4 citations
TL;DR

This paper proposes accelerating cyber threat intelligence (CTI) research by leveraging established methodologies from mature fields such as intelligence fusion, situational awareness, and knowledge management. By mapping CTI processes to these time-tested domains, the study identifies actionable research directions that enable faster, more effective threat intelligence development through cross-disciplinary reuse of knowledge and frameworks.

ABSTRACT

Cyber threat intelligence is a relatively new field that has grown from two distinct fields, cyber security and intelligence. As such, it draws knowledge from and mixes the two fields. Yet, looking into current scientific research on cyber threat intelligence research, it is relatively scarce, which opens up a lot of opportunities. In this paper we define what cyber threat intelligence is, briefly review some aspects for cyber threat intelligence. Then, we analyze existing research fields that are much older that cyber threat intelligence but related to it. This opens up an opportunity to draw knowledge and methods from those older field, and in that way advance cyber threat intelligence much faster than it would by following its own path. With such an approach we effectively give a research directions for CTI.

Motivation & Objective

  • To address the nascent state of cyber threat intelligence (CTI) research by identifying underutilized, mature research fields with transferable methodologies.
  • To reduce the time-to-advancement in CTI by reusing proven frameworks from related disciplines instead of developing new ones from scratch.
  • To provide a structured research roadmap for CTI by aligning it with long-established domains such as intelligence fusion, knowledge management, and cognitive computing.
  • To enhance CTI's decision-making capabilities by integrating principles from situational awareness and uncertainty reasoning.
  • To stimulate interdisciplinary innovation by mapping CTI processes to existing, well-researched domains with shared conceptual foundations.

Proposed method

  • Identifies core components of CTI—data collection, information fusion, knowledge generation, and decision support—and maps them to analogous processes in mature research fields.
  • Analyzes intelligence fusion (DIF) as a foundational framework for integrating heterogeneous cyber threat data into actionable insights.
  • Applies situational awareness (SAW) theory to model perception, comprehension, and projection of cyber threats in real time.
  • Integrates knowledge management (KM) principles to structure, store, and share CTI knowledge across organizational boundaries and over time.
  • Draws on cognitive computing and decision theory to model reasoning under uncertainty and improve threat prediction accuracy.
  • Uses comparative analysis to align CTI processes with established models such as the OODA loop, Waterfall, and Omnibus models from intelligence and systems engineering.

Experimental results

Research questions

  • RQ1How can established research fields like intelligence fusion and knowledge management be leveraged to accelerate the development of cyber threat intelligence?
  • RQ2What commonalities exist between cyber threat intelligence and traditional intelligence domains such as business intelligence and competitive intelligence?
  • RQ3In what ways can situational awareness frameworks improve the perception and prediction of cyber threats in dynamic environments?
  • RQ4How can uncertainty management and decision theory enhance the reliability and actionability of CTI outputs?
  • RQ5What specific methodologies from mature fields can be adapted to address current limitations in CTI data integration, knowledge representation, and operational use?

Key findings

  • Cyber threat intelligence is currently in an early developmental stage, with limited foundational research, creating a strong opportunity for cross-disciplinary knowledge transfer.
  • Intelligence fusion (DIF) provides a mature framework for integrating multi-source cyber threat data into coherent, actionable intelligence, directly applicable to CTI pipelines.
  • Situational awareness models offer a proven structure for perceiving, comprehending, and projecting cyber threats, aligning closely with CTI’s goal of threat anticipation.
  • Knowledge management practices significantly enhance CTI by enabling systematic capture, sharing, and retention of expert threat knowledge across organizations.
  • Cognitive computing and uncertainty reasoning techniques can improve CTI’s ability to handle ambiguous or incomplete threat data, increasing decision support quality.
  • The integration of mature fields such as decision theory, ontology engineering, and big data analytics offers a viable pathway to advance CTI beyond its current tactical, technical focus.

Better researchstarts right now

From reading papers to final review, dramatically reduce your research time.

No credit card · Free plan available

This review was created by AI and reviewed by human editors.