Research Article

An Automatic Assessment Method of Cyber Threat Intelligence Combined with ATT&CK Matrix

Table 4

Assessment features and corresponding scores.

Assessment featureDescriptionAttributesScore

AlertThe possible harm through the IOCsMarked high-risk in the database3
Marked medium-risk in the database2
Marked low-risk in the database1
Created timeTimestamp related to IOCLast day5
Last week4
Last month3
Last year2
Other1
External referenceOther threat activities related to this indicatorMulti known reference4
Single known reference3
Unknown reference2
No reference1
CVECheck if the CVE is found in the extracted IOCs, and if so, check the CVSSCVE with critical CVSS5
CVE with high CVSS4
CVE with medium CVSS3
CVE with low CVSS2
No CVE or CVE with no CVSS1