{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,23]],"date-time":"2026-07-23T15:40:54Z","timestamp":1784821254050,"version":"3.55.0"},"reference-count":32,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2020,3,2]],"date-time":"2020-03-02T00:00:00Z","timestamp":1583107200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2020,3,2]],"date-time":"2020-03-02T00:00:00Z","timestamp":1583107200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/501100007601","name":"Horizon 2020","doi-asserted-by":"publisher","award":["830927"],"award-info":[{"award-number":["830927"]}],"id":[{"id":"10.13039\/501100007601","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Int. J. Inf. Secur."],"published-print":{"date-parts":[[2021,2]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>The very raison d\u2019\u00eatre of cyber threat intelligence (CTI) is to provide meaningful knowledge about cyber security threats. The exchange and collaborative generation of CTI by the means of sharing platforms has proven to be an important aspect of practical application. It is evident to infer that inaccurate, incomplete, or outdated threat intelligence is a major problem as only high-quality CTI can be helpful to detect and defend against cyber attacks. Additionally, while the amount of available CTI is increasing it is not warranted that quality remains unaffected. In conjunction with the increasing number of available CTI, it is thus in the best interest of every stakeholder to be aware of the quality of a CTI artifact. This allows for informed decisions and permits detailed analyses. Our work makes a twofold contribution to the challenge of assessing threat intelligence quality. We first propose a series of relevant quality dimensions and configure metrics to assess the respective dimensions in the context of CTI. In a second step, we showcase the extension of an existing CTI analysis tool to make the quality assessment transparent to security analysts. Furthermore, analysts\u2019 subjective perceptions are, where necessary, included in the quality assessment concept.<\/jats:p>","DOI":"10.1007\/s10207-020-00490-y","type":"journal-article","created":{"date-parts":[[2020,3,2]],"date-time":"2020-03-02T18:03:41Z","timestamp":1583172221000},"page":"21-38","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":70,"title":["Measuring and visualizing cyber threat intelligence quality"],"prefix":"10.1007","volume":"20","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-4847-522X","authenticated-orcid":false,"given":"Daniel","family":"Schlette","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0023-6051","authenticated-orcid":false,"given":"Fabian","family":"B\u00f6hm","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Marco","family":"Caselli","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"G\u00fcnther","family":"Pernul","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2020,3,2]]},"reference":[{"key":"490_CR1","unstructured":"Symantec Corporation.: Internet security threat report 2019 (2019). https:\/\/www.symantec.com\/content\/dam\/ symantec\/docs\/reports\/istr-24-2019-en.pdf"},{"key":"490_CR2","doi-asserted-by":"publisher","first-page":"715","DOI":"10.1007\/s10207-019-00433-2","volume":"18","author":"R Riesco","year":"2019","unstructured":"Riesco, R., Villagr\u00e1, V.A.: Leveraging cyber threat intelligence fora dynamic risk framework. Int. J. Inf. Secur. 18, 715\u2013739 (2019)","journal-title":"Int. J. Inf. Secur."},{"key":"490_CR3","unstructured":"Ponemon Institute LLC.: Live threat intelligence impact report 2013 (2013). https:\/\/www.ponemon.org\/blog\/ live-threat-intelligence-impact-report-2013-1"},{"issue":"3","key":"490_CR4","doi-asserted-by":"publisher","first-page":"5","DOI":"10.1016\/S1361-3723(14)70469-5","volume":"2014","author":"T Ring","year":"2014","unstructured":"Ring, T.: Threat intelligence: Why people don\u2019t share. Comput. Fraud Secur. 2014(3), 5 (2014)","journal-title":"Comput. Fraud Secur."},{"key":"490_CR5","doi-asserted-by":"crossref","unstructured":"Sillaber, C., Sauerwein, C., Mussmann, A., Breu, R.: Data quality challenges and future research directions in threat intelligence sharing practice. In: Proceedings of the 2016 ACM on Workshop on Information Sharing and Collaborative Security - WISCS\u201916, pp. 65\u201370. ACM, New York (2016)","DOI":"10.1145\/2994539.2994546"},{"key":"490_CR6","unstructured":"Sillaber, C., Sauerwein, C., Mussmann, A., Breu, R.: Towards a maturity model for inter-organizational cyber threat intelligence sharing: A case study of stakeholder\u2019s expectations and willingness to share. In: Proceedings of Multikonferenz Wirtschaftsinformatik (MKWI 2018), pp. 6\u20139. Springer, Heidelberg (2018)"},{"key":"490_CR7","doi-asserted-by":"publisher","first-page":"212","DOI":"10.1016\/j.cose.2017.09.001","volume":"72","author":"W Tounsi","year":"2018","unstructured":"Tounsi, W., Rais, H.: A survey on technical threat intelligence in the age of sophisticated cyber attacks. Comput. Secur. 72, 212\u2013233 (2018)","journal-title":"Comput. Secur."},{"key":"490_CR8","volume-title":"Juran\u2019s Quality Control Handbook","author":"JM Juran","year":"1988","unstructured":"Juran, J.M., Gryna, F.M.: Juran\u2019s Quality Control Handbook, 4th edn. McGraw-Hill, New York (1988)","edition":"4"},{"issue":"2","key":"490_CR9","doi-asserted-by":"publisher","first-page":"618","DOI":"10.1016\/j.dss.2005.05.019","volume":"43","author":"A J\u00f8sang","year":"2007","unstructured":"J\u00f8sang, A., Ismail, R., Boyd, C.: A survey of trust and reputation systems for online service provision. Decis. Support Syst. 43(2), 618 (2007)","journal-title":"Decis. Support Syst."},{"key":"490_CR10","unstructured":"Dandurand, L., Serrano, O.S.: Towards improved cyber security information sharing. In: 2013 5th International Conference on Cyber Conflict (CYCON 2013). IEEE Computer Society Press, Los Alamitos (2013)"},{"key":"490_CR11","doi-asserted-by":"crossref","unstructured":"Serrano, O., Dandurand, L., Brown, S.: On the design of a cyber security data sharing system. In: Proceedings of the 2014 ACM Workshop on Information Sharing & Collaborative Security - WISCS \u201914, pp. 61\u201369. ACM, New York (2014)","DOI":"10.1145\/2663876.2663882"},{"key":"490_CR12","doi-asserted-by":"publisher","unstructured":"Kokulu, F.B. Soneji, A. Bao, T., Shoshitaishvili, Y., Zhao, Z., Doup\u00e9, A., Ahn G.J.: Matched and mismatched socs: a qualitative study on security operations center issues. In: Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security (Association for Computing Machinery, New York, NY, USA, 2019), CCS \u201919, pp. 1955\u20131970. https:\/\/doi.org\/10.1145\/3319535.3354239","DOI":"10.1145\/3319535.3354239"},{"key":"490_CR13","unstructured":"Sauerwein, C., Sillaber, C., Mussmann, A., Breu, R.: Threat intelligence sharing platforms: an exploratory study of software vendors and research perspectives. In: Proceedings of the 13th International Conference on Wirtschaftsinformatik, pp. 837\u2013851. Springer, Heidelberg (2017)"},{"key":"490_CR14","doi-asserted-by":"publisher","first-page":"87","DOI":"10.1016\/j.cose.2017.10.009","volume":"73","author":"F Menges","year":"2018","unstructured":"Menges, F., Pernul, G.: A comparative analysis of incident reporting formats. Comput. Secur. 73, 87\u2013101 (2018)","journal-title":"Comput. Secur."},{"key":"490_CR15","unstructured":"Piazza, R., Wunder, J., Jordan, B.: StixTM version 2.0. part 2: Stix objects (2017). https:\/\/docs.oasis-open.org\/cti\/ stix\/v2.0\/stix-v2.0-part2-stix-objects.html"},{"issue":"3","key":"490_CR16","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/1541880.1541883","volume":"41","author":"C Batini","year":"2009","unstructured":"Batini, C., Cappiello, C., Francalanci, C., Maurino, A.: Methodologies for data quality assessment and improvement. ACM Comput. Surv. 41(3), 1 (2009)","journal-title":"ACM Comput. Surv."},{"key":"490_CR17","doi-asserted-by":"publisher","first-page":"154","DOI":"10.1016\/j.cose.2016.04.003","volume":"60","author":"F Skopik","year":"2016","unstructured":"Skopik, F., Settanni, G., Fiedler, R.: A problem shared is a problem halved: a survey on the dimensions of collective cyber defense through security information sharing. Computers & Security 60, 154\u2013176 (2016)","journal-title":"Computers & Security"},{"key":"490_CR18","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-24106-7","volume-title":"Data and Information Quality: Dimensions, Principles and Techniques","author":"C Batini","year":"2016","unstructured":"Batini, C., Scannapieco, M.: Data and Information Quality: Dimensions, Principles and Techniques. Springer, Cham (2016)"},{"issue":"11","key":"490_CR19","doi-asserted-by":"publisher","first-page":"86","DOI":"10.1145\/240455.240479","volume":"39","author":"Y Wand","year":"1996","unstructured":"Wand, Y., Wang, R.Y.: Anchoring data quality dimensions in ontological foundations. Commun. ACM 39(11), 86 (1996)","journal-title":"Commun. ACM"},{"issue":"4","key":"490_CR20","doi-asserted-by":"publisher","first-page":"5","DOI":"10.1080\/07421222.1996.11518099","volume":"12","author":"RY Wang","year":"1996","unstructured":"Wang, R.Y., Strong, D.M.: Beyond accuracy: What data quality means to data consumers. J. Manag. Inf. Syst. 12(4), 5 (1996)","journal-title":"J. Manag. Inf. Syst."},{"key":"490_CR21","volume-title":"Data Quality for the Information Age","author":"TC Redman","year":"1996","unstructured":"Redman, T.C.: Data Quality for the Information Age. Artech House Publishers, Norwood (1996)"},{"key":"490_CR22","doi-asserted-by":"crossref","unstructured":"Umbrich, J., Neumaier, S., Polleres, A.: Quality assessment and evolution of open data portals. In: 2015 3rd International Conference on Future Internet of Things and Cloud (FiCloud), pp. 404\u2013411. IEEE Computer Society Press, Los Alamitos (2015)","DOI":"10.1109\/FiCloud.2015.82"},{"issue":"4","key":"490_CR23","doi-asserted-by":"publisher","first-page":"623","DOI":"10.1109\/69.404034","volume":"7","author":"RY Wang","year":"1995","unstructured":"Wang, R.Y., Storey, V.C., Firth, C.P.: A framework for analysis of data quality research. IEEE Trans. Knowl. Data Eng. 7(4), 623 (1995)","journal-title":"IEEE Trans. Knowl. Data Eng."},{"issue":"4","key":"490_CR24","doi-asserted-by":"publisher","first-page":"211","DOI":"10.1145\/505248.506010","volume":"45","author":"LL Pipino","year":"2002","unstructured":"Pipino, L.L., Lee, Y.W., Wang, R.Y.: Data quality assessment. Commun. ACM 45(4), 211 (2002)","journal-title":"Commun. ACM"},{"key":"490_CR25","unstructured":"Batini, C., Palmonari, M., Viscusi, G.: The many faces of information and their impact on information quality. In: Proceedings of the 17th International Conference in Information Quality (ICIQ 2012), pp. 212\u2013228. MIT, Cambridge (2012)"},{"issue":"5","key":"490_CR26","first-page":"1","volume":"2","author":"J S\u00e4nger","year":"2015","unstructured":"S\u00e4nger, J., Richthammer, C., Pernul, G.: Reusable components for online reputation systems. J. Trust Manag. 2(5), 1 (2015)","journal-title":"J. Trust Manag."},{"key":"490_CR27","doi-asserted-by":"crossref","unstructured":"Gascon, H., Grobauer, B., Schreck, T., Rist, L., Arp, D., Rieck, K.: Mining attributed graphs for threat intelligence. In: Proceedings of the 7th ACM on Conference on Data and Application Security and Privacy, pp. 15\u201322. ACM, New York (2017)","DOI":"10.1145\/3029806.3029811"},{"key":"490_CR28","doi-asserted-by":"publisher","first-page":"65","DOI":"10.1016\/j.inffus.2017.12.006","volume":"44","author":"I Chaturvedi","year":"2018","unstructured":"Chaturvedi, I., Cambria, E., Welsch, R.E., Herrera, F.: Distinguishing between facts and opinions for sentiment analysis: survey and challenges. Inf. Fus. 44, 65 (2018)","journal-title":"Inf. Fus."},{"key":"490_CR29","doi-asserted-by":"crossref","unstructured":"B\u00f6hm, F., Menges, F., Pernul, G.: Graph-based visual analytics for cyber threat intelligence. Cybersecurity (Cybersecurity) 1, 1 (2018)","DOI":"10.1186\/s42400-018-0017-4"},{"key":"490_CR30","unstructured":"Heinrich, B. Kaiser, M. Klier, M.: How to measure data quality? A metric-based approach. In: ICIS 2007 Proceedings pp. 108\u2013122 (2007)"},{"key":"490_CR31","unstructured":"Piazza, R., Wunder, J., Jordan, B.: StixTM version 2.0. part 1: Stix core concepts (2017). https:\/\/docs.oasis-open.org\/ cti\/stix\/v2.0\/stix-v2.0-part1-stix-core.html"},{"key":"490_CR32","volume-title":"Research Methods in Human\u2013Computer Interaction","author":"J Lazar","year":"2010","unstructured":"Lazar, J., Feng, J.H., Hochheiser, H.: Research Methods in Human\u2013Computer Interaction. Morgan Kaufmann, Burlington (2010)"}],"container-title":["International Journal of Information Security"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s10207-020-00490-y.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s10207-020-00490-y\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s10207-020-00490-y.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,3,2]],"date-time":"2021-03-02T01:14:50Z","timestamp":1614647690000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s10207-020-00490-y"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,3,2]]},"references-count":32,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2021,2]]}},"alternative-id":["490"],"URL":"https:\/\/doi.org\/10.1007\/s10207-020-00490-y","relation":{},"ISSN":["1615-5262","1615-5270"],"issn-type":[{"value":"1615-5262","type":"print"},{"value":"1615-5270","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020,3,2]]},"assertion":[{"value":"2 March 2020","order":1,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Compliance with ethical standards"}},{"value":"All authors declare that they have no conflict of interest.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}},{"value":"This article does not contain any studies with human participants or animals performed by any of the authors.","order":3,"name":"Ethics","group":{"name":"EthicsHeading","label":"Ethical approval"}}]}}