<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>ORISHA: Improving Threat Detection through Orchestrated Information Sharing (Discussion Paper)</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Luca Caviglione</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Carmela Comito</string-name>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Massimo Guarascio</string-name>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Giuseppe Manco</string-name>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Francesco Sergio Pisani</string-name>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Marco Zuppelli</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Institute for Applied Mathematics and Information Technologies</institution>
          ,
          <addr-line>Via de Marini 6, Genova, 16149</addr-line>
          ,
          <country country="IT">Italy</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Institute for High Performance Computing and Networking</institution>
          ,
          <addr-line>Via P. Bucci 8-9/C, Rende, 87036</addr-line>
          ,
          <country country="IT">Italy</country>
        </aff>
      </contrib-group>
      <abstract>
        <p>The exponential growth in the number of cyber threats requires sharing in a timely and eficient manner a wide range of Indicators of Compromise (IoCs), i.e., fragments of forensics data that can be used to recognize malicious network or system activities. To this aim, a suitable architecture is required, especially to distribute and process the various IoCs. Unfortunately, the continuous creation of ofensive techniques, along with the difusion of advanced persistent threats, imposes the ability to update and extend the platform used to manage the multitude of IoCs collected in the wild. In this paper, we present the ORISHA architecture, which takes advantage of a distributed threat detection system to match performance and scalability requirements. The paper also discusses how the platform can be extended to handle the most recent “stealthy” malware as well as campaigns aimed at spreading fake news.</p>
      </abstract>
      <kwd-group>
        <kwd>eol&gt;Threat Intelligence</kwd>
        <kwd>Risk Mitigation</kwd>
        <kwd>Active Learning</kwd>
        <kwd>Collaborative Approach</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>
        In recent years, we observed exponential growth in the number of attacks targeting organizations
and users. Successful attacks performed by Blackhats were able to provoke a wide variety of
damages and proved the weakness (in terms of security) of both government computer systems
as well as user devices. As reported in [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ], DDoS, information leakage, phishing, identity theft,
and botnet were among the most frequent attacks performed in 2020, and the outbreak of
the pandemic emergency has done nothing but further exacerbate this complex scenario. The
vulnerabilities of popular platforms, applications, and systems discovered during this critical
period have fed the interest in employing information-sharing technologies to increase attack
detection and risk mitigation capabilities of enterprises and organizations [
        <xref ref-type="bibr" rid="ref2 ref3">2, 3</xref>
        ].
      </p>
      <p>Quick decisions and adequate countermeasures can be set up if information concerning
threat events and Indicators of Compromise (IoCs) is shared promptly. Specifically, proactive
threat information sharing and defensive mitigation strategies can be exploited to boost the
resilience of the entities belonging to trusted communities generating herd immunity against
new (possibly unknown) threats. Therefore, an emerging research line focuses on devising new
platforms, approaches, and methodologies to deliver and share threat events to prevent further
damage by quickly arranging countermeasures.</p>
      <p>
        Recently, Cyber Threat Intelligence (CTI) platforms have proved their efectiveness in
managing threat information [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ]. These tools are currently adopted to gather, preprocess, enrich,
correlate, analyze, and share threat events [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ]. As highlighted in [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ], Threat Intelligence
Platforms (TIP) have to satisfy some main requirements, i.e., providing (i) services for information
sharing, (ii) facilities for automatizing the process, and (iii) functionalities for collaborative
threat data analysis. Alas, devising a complete solution for handling information from diferent
sources is a challenging objective [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ]. Indeed, diferent open issues (e.g., standardization, privacy,
and reliability of the shared information, just to cite a few) have to be addressed to realize a fully
operational platform. Although some recent works propose advanced solutions for easing threat
data sharing, many only focused on some of the issues mentioned above [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ]. A comprehensive
review of the current state of the art and open challenges can be found in [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ].
      </p>
      <p>
        In this work, we provide an overview of ORISHA [
        <xref ref-type="bibr" rid="ref10">10</xref>
        ], a platform for ORchestrated
Information SHaring and Awareness that combines TIPs with AI-based Threat Intelligence solutions
in a single comprehensive framework. ORISHA allows for improving the accuracy of Threat
Detection Systems (TDS) in recognizing incoming attacks and also enables the sharing of
reliable and relevant threat information among organizations and threat detection algorithms.
The main idea is that TDSs can benefit each other mutually by sharing knowledge since a
threat feed produced by a TDS can be exploited to improve the threat modeling strategies of
another one. The platform allows for publishing threat information on a distributed TIP and
making them accessible to other actors. Although the current implementation is fully general,
ORISHA has been mainly used for Network Intrusion Detection Systems. In this work, we
discuss how ORISHA can also be employed to mitigate the risk of new emerging threats, such
as information-hiding-based attacks and spreading fake news.
      </p>
      <p>The rest of the paper is structured as follows. Section 2 surveys state-of-the-art solutions for
threat information sharing and awareness. Section 3 describes ORISHA, our platform for threat
event sharing. Section 4 introduces the new threats to be managed and discusses how ORISHA
can be extended. Finally, Section 5 concludes the paper and outlines future research directions.</p>
    </sec>
    <sec id="sec-2">
      <title>2. Background</title>
      <p>
        Threat Intelligence refers to the task of gathering data concerning attacks or breaches (e.g.,
context, methods, indicators, or devices) with the aim to help organizations to set up efective
countermeasures by leveraging a wide range of information [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ]. Specifically, organizations
can cooperate to improve the detection and prevention of new threats by sharing information
about recently identified attacks. In this respect, Indicators of Compromise (IoCs) are the mean
typically used to share this information. An IoC is a piece of forensic data identifying potentially
malicious activities on a system or network. The IP address of a DoS attack, a hash of a malicious
executable file or the URL of a phishing website are examples of IoCs.
      </p>
      <p>
        Threat Intelligence is a relatively new research line in the field of cybersecurity and, as
reported in [
        <xref ref-type="bibr" rid="ref12">12</xref>
        ], both academic and industrial entities have shown a growing interest in this
topic. Cooperation and data sharing can boost the security of computer networks and mitigate
the risk of compromising. However, the research in this field mainly aimed at developing
tools for threat information sharing; hence in recent years, there has been a proliferation of
threat intelligence platforms [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ]. The lack of standards and solid approaches yielded several
combinations of solutions and methods incorrectly tagged as threat intelligence.
      </p>
      <p>
        Tentative guidelines have been proposed in [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ], where the authors define information-sharing
goals for organizations by also specifying threat information sources and rules for handling the
publication and distribution of the data. Nevertheless, there is no consensus among researchers
and practitioners on adopting a methodology or technology, as no complete solution exists for
handling the standardization, privacy, and reliability issues related to the sharing process.
      </p>
      <p>
        Although channels such as mail messages, phone calls, ticket systems, or face-to-face
meetings have been widely used as a primary way to share threat information quickly, the growing
number of cyberattacks made these tools inadequate to handle the volume of data produced,
hence the necessity to replace them with semi-automatic tools. Recently, several standards,
such as Structured Threat Information CybereXpression (STIX) [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ], Cyber Observable
eXpression (CybOX) [
        <xref ref-type="bibr" rid="ref15">15</xref>
        ], Incident Object Description Exchange Format (IODEF) [
        <xref ref-type="bibr" rid="ref16">16</xref>
        ] and Trusted
Automated eXchange of Indicator Information (TAXII) [
        <xref ref-type="bibr" rid="ref17">17</xref>
        ], have been proposed to facilitate
the sharing of IoCs.
      </p>
      <p>
        In more detail, in [
        <xref ref-type="bibr" rid="ref18">18</xref>
        ], the authors describe the main platforms for threat information sharing
based on the standards introduced above [
        <xref ref-type="bibr" rid="ref12 ref5">12, 5</xref>
        ]. One of the most adopted solutions is MISP
(Malware Information Sharing Platform), an open-source software solution for collecting,
storing, distributing, and sharing cyber security indicators and threat information [
        <xref ref-type="bibr" rid="ref19">19</xref>
        ].
      </p>
      <p>
        MITRE CRITs (Collaborative Research Threats) is another widely used open-source malware
and threat repository that leverages diferent open-source software to create a unified tool
for analysts and security experts engaged in threat defense [
        <xref ref-type="bibr" rid="ref20">20</xref>
        ]. CIF (Collective Intelligence
Framework) is an open-source cyber threat intelligence platform that allows for gathering data
from diferent sources and exploiting them for threat identification, detection, and mitigation.
Finally, EclecticIQ Platform is a commercial platform based on STIX and TAXII standards that
gathers and interprets intelligence data from open sources.
      </p>
    </sec>
    <sec id="sec-3">
      <title>3. The ORISHA Platform</title>
      <p>
        In this section, we illustrate the main components composing ORISHA. Figure 1 depicts the
core actors cooperating within the system: Distributed TIP, TDS Layer, and Honeynet. The TIP
is devoted to orchestrate the interactions among the components and represents the core of
ORISHA. Basically, it performs two main tasks: (i) it allows for storing and encrypting the
information (gathered from heterogeneous sources) in a distributed fashion, and (ii) it permits to
share the collected data to the other components. The distributed TIP is realized by connecting
several MISP instances. Among the tools introduced in Section 2, the MISP exhibits diferent
benefits as highlighted in [
        <xref ref-type="bibr" rid="ref21">21</xref>
        ]: (i) integration with SIEMs and Intrusion Detection Systems
Honeynet
sharing data concerning
new attacks
TIP information is used to
deploy new honeypots
      </p>
      <p>Organization 1</p>
      <p>Share:MISPEvents
containingThreatData
TDS
Threat
Detection
System</p>
      <p>TDS input:Network Traffic
TDS output:Alarms</p>
      <p>TDS
Threat
Detection
System</p>
      <p>Organization 2</p>
      <p>MISPEvent</p>
      <p>Security Service</p>
      <p>Providers/Consumers
EnrichedIoCs,privatizeddata,</p>
      <p>Risk Indicators,etc.</p>
      <p>TDS
Threat
Detection
System</p>
      <p>Organization N
(IDSs) functionalities, (ii) extensible and flexible architecture, ( iii) support for diferent standards
(e.g., STIX, TAXI), (iv) detailed documentation, and (v) several active communities. Basically,
the diferent MISP instances cooperate by sharing data about upcoming threat events gathered
by the other actors.</p>
      <p>
        To this aim, ORISHA mainly leverages two elements: the data exchange format defined in
[
        <xref ref-type="bibr" rid="ref10">10</xref>
        ] and the layers handling the communication between TDSs and TIP. As an example, in the
following, we consider the case in which ORISHA is used to share data about anomalous flow
connections discovered by ML-Based IDSs. Specifically, we focused on describing how ORISHA
can be used to realize an Active Learning scheme [
        <xref ref-type="bibr" rid="ref22">22</xref>
        ]. It is important to note that the platform
can be extended to integrate other TDSs by customizing the data exchange format.
      </p>
      <sec id="sec-3-1">
        <title>3.1. Leveraging ORISHA for Active Learning</title>
        <p>In this section, we show how the cooperation among diferent TDSs is realized using ORISHA
and how the decision-making process is improved. Figure 2 depicts the overall information
lfow. The process begins by monitoring the system. The computer network periodically yields
trafic flow that the underlying TDS layer will analyze. In this scenario, a specific anomaly
detector (TDS1 in the figure) processes the .pcap files containing the trafic traces and detects
an anomaly. A MISP security event is generated and shared with the TIP, which plays the role
of “security event hub”. Then, a diferent IDS ( TDS2 in the figure) reads the event, analyzes the
embedded .pcap files, and labels the event with additional information. The updated MISP
object, now with two consensus labels, is examined by an expert who can accept or reject the
threat classification. Once validated, the event can be used by other IDSs (e.g., TDS in the
ifgure) for the training stage in order to improve their predictive performances.</p>
        <p>Now let us consider a diferent case where the event produced by TDS1 is classified diferently
(non-anomalous) by TDS2. Again, the domain expert examines the event with dissimilar scores
and realizes that the event is a false alarm. The event is then returned to TDS1, which can
include the validated event in its training set and refine the underlying model for better accuracy
...</p>
        <p>MISP</p>
        <p>Instance k
MISPNetwork
and improve its false positive rate.</p>
        <p>
          The solution described above corresponds to the well-known Query-By-Committee
strategy [
          <xref ref-type="bibr" rid="ref23">23</xref>
          ], with the diference that, here, we foresee that the expert validates both the agreement
(in the first situation) and the disagreement (in the second one). More sophisticated validation
criteria can be adopted to implement diferent optimization objectives. For example, to reduce
human intervention, automatic validation can be used to confirm the agreements based on
confidence values and reduce human analysis to the most uncertain cases based, e.g., on label
entropy.
        </p>
      </sec>
    </sec>
    <sec id="sec-4">
      <title>4. Extending ORISHA for Emerging Threats</title>
      <p>In this section, we present two classes of emerging threats, i.e., multi-vector attacks leveraging
information hiding and fake news. We then discuss how to extend the ORISHA platform with
IoCs able to capture the challenging and fast-paced modern security scenario.</p>
      <sec id="sec-4-1">
        <title>4.1. Multi-Vector and Information Hiding Attack Campaigns</title>
        <p>
          In recent years, threat actors are increasingly taking advantage of complex attack chains,
especially to elude detection or target large-scale organizations and critical infrastructures.
For instance, many modern malware deploy multi-stage loading architectures, e.g., ofensive
routines are retrieved only when needed to reduce the footprint of the malicious software
[
          <xref ref-type="bibr" rid="ref24">24</xref>
          ]. Moreover, advanced persistent threats are now able to exploit diferent portions of the
attack surface, making them intrinsically multi-vector (see, e.g., [
          <xref ref-type="bibr" rid="ref25">25</xref>
          ], for the case of smart
manufacturing systems). Notable recent examples of sophisticated ofensive campaigns are
the ransomware attack against the Italian vaccination booking system in August 2021 and
against the US Colonial Pipeline facility in May 2021. In both cases, threat actors used
socialengineering-like techniques, e.g., malicious mail attachments dropped in the home computer
of a remote worker, jointly with multi-vector approaches, e.g., flawed password policies or
known exploits in commercial software suites. Besides societal and economic losses, such
attack campaigns highlighted several limits of CTI and TIP frameworks. First, the sharing of
data needs to overcome resistance to disclosing information that can reveal insights on how
the security of a complex organization is enforced. Second, collaborative analysis demands a
precise methodology for collecting data about a security incident and making it compliant with
several (often incompatible) regulations. Third, critical infrastructures are often characterized
by sensitive information, which could be actively exploited by state-level threat actors to infer
details, such as work shifts or energy requirements.
        </p>
        <p>
          Unfortunately, the surge of ofensive techniques leveraging information hiding is expected to
challenge the process of creating IoCs to be shared across various organizations. For the sake of
clarity, we present two recent use cases observed in real attacks [
          <xref ref-type="bibr" rid="ref26">26</xref>
          ].
        </p>
        <p>Steganographic Malware and Covert Channels
To prevent detection, many recent threats deploy information-hiding mechanisms. For instance,
malicious payloads are hidden in digital images by means of steganography. The most used
technique encodes bits of secret data by altering the least significant bits of the red, green,
and blue color components of pixels belonging to the target image. Altered files can then
be sent via mail attachments, embedded within Word/PDF documents, or bundled within an
application. Despite the chosen vector, the typical use of steganography is to conceal additional
information, such as remote URLs, configuration files, or IP addresses, without leading to a
visible signature. From the perspective of developing IoCs or supporting collaborative threat
analysis, steganographic malware represents a challenging scenario. In fact, images can be sent
or embedded in diferent manners, thus requiring specialized procedures for the creation of the
IoC. Moreover, the steganographic process could introduce overheads in the TIP. As an example,
a URL used to retrieve a remote payload hidden within an image could not be a complete IoC.
Specifically, also the “carrier” concealing the secret data and the used steganographic mechanism
(e.g., the Invoke-PSImage techniques observed in Ursnif) should be part of the IoC itself. In
other words, steganographic malware may “inflate” the IoC space to explicitly consider both
the malicious hidden content and the container.</p>
        <p>
          Another challenge deals with the abused carriers, which could be very mixed or hard to
collect (in principle, any digital content could be used to conceal information). In more detail,
attackers could hide malicious information by manipulating icons or images bundled with
applications [
          <xref ref-type="bibr" rid="ref27">27</xref>
          ] as well as in concurrent code or HTML files [
          <xref ref-type="bibr" rid="ref28">28</xref>
          ]. The creation of IoCs should
then consider a multitude of heterogeneous assets (e.g., HTML pages, icons, and additional files),
which could not be retrieved in a simple manner. Specifically, the original IoC could require to
interact with an application store/repository or to crawl/scrape contents through the Web.
        </p>
        <p>
          Advancements in IDSs, firewalls, and trafic analyzers partially ignited the difusion among
threat actors of covert channels hidden within network trafic. In essence, network covert
channels are parasitic communications cloaked within legitimate trafic flows [
          <xref ref-type="bibr" rid="ref29">29</xref>
          ], which are
created with the ultimate goal of bypassing security tools or blockages. As an example, the
attacker could hide sensitive data in unused protocol fields or botnet commands in HTTP
headers. Similarly to the case of steganographic malware, network covert channels require
the preparation of multiple IoCs. Even if one may consider to share .pcap traces containing
covert communications, this could lead to several hazards. First, recognizing in which part of
the protocol (or flow) the data has been hidden may require to store a non-negligible volume
of trafic. Second, an attacker targeting the payload could be identified only via complete
trafic traces, which usually conflicts with standard anonymization procedures. Third, covert
communications are usually long-lasting, thus collecting data for preparing the IoC could need
to gather a huge amount of information at a wire speed, thus lacking of proper scalability [
          <xref ref-type="bibr" rid="ref30">30</xref>
          ].
        </p>
        <p>
          Lastly, a possible realistic example considering the mitigation of the aforementioned threats
by using the ORISHA platform could be as follows. A TDS ( 1) detects the presence of an
image containing malicious content concealed via steganography, e.g., it deploys well-known
heuristics or an AI-based countermeasure. For instance, a Web server has been instrumented to
spot the presence of skimmers or additional payloads hidden in favicons [
          <xref ref-type="bibr" rid="ref31">31</xref>
          ]. The tampered
favicon is then “quarantined” and the hidden content is retrieved if possible, e.g., the script or
URL is stored in a textual form. A suitable IoC composed of the original favicon, the script,
and companion metadata is then prepared and sent via the MISP interface. The IoC could also
be enriched with information such as the name of the threat (e.g., Magecart/Magento), the
size of the favicon, and the type of the cloaked data (e.g., JavaScript or PowerShell). If needed,
additional details on the obfuscation technique used by the attacker (e.g., zipx or Base64) can
be put in metadata as well. In a similar manner, a detector ( 2) in charge of revealing the
presence of network covert channels could bundle fragments of trafic in one or more .pcap
ifles, along with information on which part of the protocol has been exploited (e.g., the TTL or
the Flow Label). The IoC could also contain data on the detection accuracy to avoid propagating
false positives/negatives or help in setting up suitable labels to train an AI-based framework.
        </p>
      </sec>
      <sec id="sec-4-2">
        <title>4.2. Fake News</title>
        <p>Recent years have also seen an increased concern for the threats that fake news and online
misinformation present to the democratic debate. Online Web sources and social media are the
main means of news information dissemination and spreading. In particular, an exponential
increase in the use of social media has accelerated information difusion. The speed at which
misinformation spreads, alongside social media’s open access content production and
dissemination, increases the potential damage, making online platforms primary targets for fake news
propagation.</p>
        <p>
          Therefore, it is necessary to mitigate the impact of misinformation as well as develop specific
tools and services to allow citizens and the professional community to access reliable and
trustworthy information on the Web and social media. The automatic detection of fake news is a
relevant problem attracting great interest from the research community. Most previous research
studied the problem of fake news detection, by typically using feature extraction from news
content. Text content-based approaches mainly explore lexical and syntactic features like word
usage and linguistic styles to identify fake news or to detect the diferences in the writing style
of real and fake news, such as deception [
          <xref ref-type="bibr" rid="ref32 ref33 ref34 ref35 ref36 ref37 ref38">32, 33, 34, 35, 36, 37, 38</xref>
          ]. Other methods, such as the
one reported in [
          <xref ref-type="bibr" rid="ref39">39</xref>
          ], capture and exploit sensational emotions for learning emotion-enhanced
representations. Moreover, some works analyze the images in the news along with the text
content for fake news detection [
          <xref ref-type="bibr" rid="ref36 ref40">36, 40</xref>
          ]. Exploiting user-based features as auxiliary information
for improving the identification of fake news was explored in [
          <xref ref-type="bibr" rid="ref32 ref41">32, 41</xref>
          ].
        </p>
        <p>With the advent of social media, the nature of misinformation has evolved from text-to-visual
based modalities, such as images, audio, and video. Therefore, the identification of media-rich
fake news requires an approach that exploits and efectively combines the information acquired
from diferent multi-modal data.</p>
        <p>Multi-modality is a key approach to improve fake news detection, but successful solutions
supporting diferent data modalities, with their diferent structure and dimension, is still poorly
explored. Multi-Modal Deep Learning based approaches demonstrated to be efective in
providing accurate predictions but require feeding with diferent types of labeled data. In this respect,
the integration with ORISHA could represent an efective solution to obtain suficient data for
their learning. In particular, the multi-modality can be implemented through the cooperation of
the diferent TDS within the ORISHA architecture, which can exhibit peculiar classification
abilities according to the specific data modality. We can envisage a deep learning based cooperative
model that uses the feedbacks of the diferent organizations within the ORISHA frameworks to
estimate news trust levels and ranks the news accordingly.</p>
        <p>Let us consider the following scenario. A fake news detector ( 1) identifies a fake news
by analyzing the textual content of a social media post. At this point, the TDS creates a proper
IoC that specifies the news text, the url of an image posted together with the textual content,
and a set of metadata reporting the source of the news and its social context (e.g., engaged
users, retweets, replies). Further metadata include information such as the probability with
which the news has been detected as fake (e.g., the accuracy of the fake news classifier) and
that the news has not been validated yet as fake. A MISP security event is then produced and
delivered. The event is distributed in the TIP, where a diferent TDS (  2) analyzes the IoC
and classifies the news as real, diferently than  1. The updated MISP object, now with two
opposite labels, is delivered in the TIP. At this point a third TDS ( 3) handles the IoC and
analyzes the image (e.g., exploiting a CNN network), classifying it as malicious. Again the MISP
security event is updated and delivered. The domain expert inspects the event with dissimilar
scores and realizes that the event represents a fake news. The event is then returned to  2,
which will adapt its training set with the validated news, improving the classification accuracy
of the model by adapting its false negative rate.</p>
      </sec>
    </sec>
    <sec id="sec-5">
      <title>5. Conclusions and Future Works</title>
      <p>
        In this paper, we provided an overview of the ORISHA platform, which allows for sharing
diferent pieces of forensics information as well as specific IoCs. As shown, our approach can
be used to both improve the accuracy of the detection or foster cooperative threat mitigation
campaigns among diferent organizations. However, the recent surge of advanced attack schemes
using information hiding and the difusion of fake news requires extending the platform and
addressing specific challenges. For instance, the heterogeneity of IoCs, privacy constraints, and
scalability properties should be considered to efectively deploy ORISHA in realistic deployments.
Moreover, we want also to investigate new emerging types of threats aiming at compromising
ML models through specific attacks against the learning or deployment stages [
        <xref ref-type="bibr" rid="ref42">42</xref>
        ].
      </p>
    </sec>
    <sec id="sec-6">
      <title>Acknowledgments</title>
      <p>This work was partially supported by project SERICS (PE00000014) under the NRRP MUR
program funded by the EU - NGEU.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>ENISA</given-names>
            ,
            <surname>Enisa</surname>
          </string-name>
          <string-name>
            <surname>threat</surname>
          </string-name>
          <source>landscape 2020 - list of top 15 threats</source>
          ,
          <year>2020</year>
          . https://www.enisa.europa. eu/publications/enisa-threat-landscape
          <article-title>-2020-list-of-top-15-threats</article-title>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <surname>Interpol</surname>
          </string-name>
          , Covid-19
          <source>cybercrime analysis report.</source>
          ,
          <year>2020</year>
          . https://tinyurl.com/6wek2rk.
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3] Microsoft 365
          <string-name>
            <given-names>Defender</given-names>
            <surname>Threat Intelligence Team</surname>
          </string-name>
          ,
          <article-title>Exploiting a crisis: How cybercriminals behaved during the outbreak</article-title>
          ,
          <year>2020</year>
          . https://tinyurl.com/cybercrime-during-outbreak.
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>C. S.</given-names>
            <surname>Johnson</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M. L.</given-names>
            <surname>Badger</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Waltermire</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Snyder</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.</given-names>
            <surname>Skorupka</surname>
          </string-name>
          ,
          <article-title>Guide to cyber threat information sharing</article-title>
          ,
          <source>NIST Special Publication</source>
          <volume>800</volume>
          -
          <fpage>150</fpage>
          (
          <year>2016</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>S.</given-names>
            <surname>Brown</surname>
          </string-name>
          , J.
          <string-name>
            <surname>Gommers</surname>
            ,
            <given-names>O.</given-names>
          </string-name>
          <string-name>
            <surname>Serrano</surname>
          </string-name>
          ,
          <article-title>From cyber security information sharing to threat management</article-title>
          ,
          <source>in: Proceedings of the 2nd ACM Workshop on Information Sharing and Collaborative Security</source>
          ,
          <year>2015</year>
          , pp.
          <fpage>43</fpage>
          -
          <lpage>49</lpage>
          . doi:
          <volume>10</volume>
          .1145/2808128.2808133.
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>L.</given-names>
            <surname>Dandurand</surname>
          </string-name>
          ,
          <string-name>
            <given-names>O. S.</given-names>
            <surname>Serrano</surname>
          </string-name>
          ,
          <article-title>Towards improved cyber security information sharing</article-title>
          ,
          <source>in: 2013 5th International Conference on Cyber Conflict (CYCON</source>
          <year>2013</year>
          ),
          <year>2013</year>
          , pp.
          <fpage>1</fpage>
          -
          <lpage>16</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>A.</given-names>
            <surname>Zibak</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Simpson</surname>
          </string-name>
          ,
          <article-title>Cyber threat information sharing: Perceived benefits and barriers</article-title>
          ,
          <source>in: Proceedings of the 14th International Conference on Availability, Reliability and Security</source>
          , ARES '19,
          <string-name>
            <surname>Association</surname>
          </string-name>
          for Computing Machinery,
          <year>2019</year>
          , pp.
          <fpage>1</fpage>
          -
          <lpage>9</lpage>
          . doi:
          <volume>10</volume>
          .1145/3339252. 3340528.
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>S.</given-names>
            <surname>Qamar</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Z.</given-names>
            <surname>Anwar</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M. A.</given-names>
            <surname>Rahman</surname>
          </string-name>
          ,
          <string-name>
            <given-names>E.</given-names>
            <surname>Al-Shaer</surname>
          </string-name>
          ,
          <string-name>
            <given-names>B.-T.</given-names>
            <surname>Chu</surname>
          </string-name>
          ,
          <article-title>Data-driven analytics for cyber-threat intelligence and information sharing</article-title>
          ,
          <source>Computers &amp; Security</source>
          <volume>67</volume>
          (
          <year>2017</year>
          )
          <fpage>35</fpage>
          -
          <lpage>58</lpage>
          . doi:https://doi.org/10.1016/j.cose.
          <year>2017</year>
          .
          <volume>02</volume>
          .005.
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>T. D.</given-names>
            <surname>Wagner</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.</given-names>
            <surname>Mahbub</surname>
          </string-name>
          ,
          <string-name>
            <given-names>E.</given-names>
            <surname>Palomar</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A. E.</given-names>
            <surname>Abdallah</surname>
          </string-name>
          ,
          <article-title>Cyber threat intelligence sharing: Survey and research directions</article-title>
          ,
          <source>Computers &amp; Security</source>
          <volume>87</volume>
          (
          <year>2019</year>
          )
          <article-title>101589</article-title>
          . doi:https: //doi.org/10.1016/j.cose.
          <year>2019</year>
          .
          <volume>101589</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <given-names>M.</given-names>
            <surname>Guarascio</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Cassavia</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F. S.</given-names>
            <surname>Pisani</surname>
          </string-name>
          , G. Manco,
          <article-title>Boosting cyber-threat intelligence via collaborative intrusion detection</article-title>
          ,
          <source>Future Generation Computer Systems</source>
          <volume>135</volume>
          (
          <year>2022</year>
          )
          <fpage>30</fpage>
          -
          <lpage>43</lpage>
          . URL: https://www.sciencedirect.com/science/article/pii/S0167739X22001571. doi:https: //doi.org/10.1016/j.future.
          <year>2022</year>
          .
          <volume>04</volume>
          .028.
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <given-names>V.</given-names>
            <surname>Mavroeidis</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Bromander</surname>
          </string-name>
          ,
          <article-title>Cyber threat intelligence model: An evaluation of taxonomies, sharing standards, and ontologies within cyber threat intelligence</article-title>
          ,
          <source>in: 2017 European Intelligence and Security Informatics Conference (EISIC)</source>
          ,
          <year>2017</year>
          , pp.
          <fpage>91</fpage>
          -
          <lpage>98</lpage>
          . doi:
          <volume>10</volume>
          .1109/ EISIC.
          <year>2017</year>
          .
          <volume>20</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <given-names>C.</given-names>
            <surname>Sauerwein</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.</given-names>
            <surname>Sillaber</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Mussmann</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Breu</surname>
          </string-name>
          ,
          <article-title>Threat intelligence sharing platforms: An exploratory study of software vendors and research perspectives, Wirtschaftsinformatik und Angewandte Informatik (</article-title>
          <year>2017</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <surname>M. C. Libicki</surname>
          </string-name>
          ,
          <article-title>Sharing information about threats is not a cybersecurity panacea</article-title>
          , Santa Monica, CA: RAND Corporation,
          <year>2015</year>
          , pp.
          <fpage>1</fpage>
          -
          <lpage>9</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <given-names>B.</given-names>
            <surname>Jordan</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Piazza</surname>
          </string-name>
          , T. Darley,
          <source>Stix™ version 2.1 committee specification 01</source>
          (
          <year>2020</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [15]
          <string-name>
            <given-names>T.</given-names>
            <surname>Darley</surname>
          </string-name>
          ,
          <string-name>
            <surname>I. Kirillov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Piazza</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Beck</surname>
          </string-name>
          ,
          <source>Cybox™ version 2.1</source>
          .1. part 01: Overview - committee
          <source>specification draft 01 / public review draft 01</source>
          (
          <year>2016</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [16]
          <string-name>
            <given-names>R.</given-names>
            <surname>Danyliw</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Meijer</surname>
          </string-name>
          ,
          <string-name>
            <surname>Y. Demchenko,</surname>
          </string-name>
          <article-title>The incident object description exchange format</article-title>
          ,
          <source>in: RFC 5070 (Proposed Standard)</source>
          ,
          <year>2007</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          [17]
          <string-name>
            <given-names>T.</given-names>
            <surname>Darley</surname>
          </string-name>
          ,
          <string-name>
            <surname>I. Kirillov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Piazza</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Beck</surname>
          </string-name>
          ,
          <source>Taxii™ version 2.1 committee specification 01</source>
          (
          <year>2020</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          [18]
          <article-title>ENISA, Exploring the opportunities and limitations of current threat intelligence platforms</article-title>
          ,
          <year>December 2017</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          [19]
          <string-name>
            <given-names>C.</given-names>
            <surname>Wagner</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Dulaunoy</surname>
          </string-name>
          ,
          <string-name>
            <given-names>G.</given-names>
            <surname>Wagener</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Iklody</surname>
          </string-name>
          ,
          <article-title>Misp: The design and implementation of a collaborative threat intelligence sharing platform</article-title>
          ,
          <source>in: Proceedings of the 2016 ACM on Workshop on Information Sharing and Collaborative Security</source>
          , WISCS '16,
          <string-name>
            <surname>Association</surname>
          </string-name>
          for Computing Machinery,
          <year>2016</year>
          , p.
          <fpage>49</fpage>
          -
          <lpage>56</lpage>
          . doi:
          <volume>10</volume>
          .1145/2994539.2994542.
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          [20]
          <string-name>
            <given-names>M.</given-names>
            <surname>Gofin</surname>
          </string-name>
          , Crits: Collaborative research into threats, https://crits.github.io/,
          <year>2014</year>
          . [Online].
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          [21]
          <string-name>
            <given-names>G.</given-names>
            <surname>González-Granadillo</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Faiella</surname>
          </string-name>
          ,
          <string-name>
            <surname>I. Medeiros</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Azevedo</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>González-Zarzosa</surname>
          </string-name>
          ,
          <article-title>Etip: An enriched threat intelligence platform for improving osint correlation, analysis, visualization and sharing capabilities</article-title>
          ,
          <source>Journal of Information Security and Applications</source>
          <volume>58</volume>
          (
          <year>2021</year>
          )
          <article-title>102715</article-title>
          . doi:https://doi.org/10.1016/j.jisa.
          <year>2020</year>
          .
          <volume>102715</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref22">
        <mixed-citation>
          [22]
          <string-name>
            <given-names>P.</given-names>
            <surname>Ren</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Y.</given-names>
            <surname>Xiao</surname>
          </string-name>
          ,
          <string-name>
            <given-names>X.</given-names>
            <surname>Chang</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Huang</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Z.</given-names>
            <surname>Li</surname>
          </string-name>
          ,
          <string-name>
            <given-names>B.</given-names>
            <surname>Gupta</surname>
          </string-name>
          ,
          <string-name>
            <given-names>X.</given-names>
            <surname>Chen</surname>
          </string-name>
          ,
          <string-name>
            <given-names>X.</given-names>
            <surname>Wang</surname>
          </string-name>
          ,
          <article-title>A survey of deep active learning</article-title>
          ,
          <source>ACM Comput. Surv</source>
          .
          <volume>54</volume>
          (
          <year>2021</year>
          ). doi:
          <volume>10</volume>
          .1145/3472291.
        </mixed-citation>
      </ref>
      <ref id="ref23">
        <mixed-citation>
          [23]
          <string-name>
            <given-names>D. A.</given-names>
            <surname>Cohn</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L. E.</given-names>
            <surname>Atlas</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R. E.</given-names>
            <surname>Ladner</surname>
          </string-name>
          ,
          <article-title>Improving generalization with active learning</article-title>
          ,
          <source>Machine Learning</source>
          <volume>15</volume>
          (
          <year>1994</year>
          )
          <fpage>201</fpage>
          -
          <lpage>221</lpage>
          . doi:
          <volume>10</volume>
          .1007/BF00993277.
        </mixed-citation>
      </ref>
      <ref id="ref24">
        <mixed-citation>
          [24]
          <string-name>
            <given-names>A.</given-names>
            <surname>Afianian</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Niksefat</surname>
          </string-name>
          ,
          <string-name>
            <given-names>B.</given-names>
            <surname>Sadeghiyan</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Baptiste</surname>
          </string-name>
          ,
          <article-title>Malware dynamic analysis evasion techniques: A survey, ACM Computing Surveys (CSUR) 52 (</article-title>
          <year>2019</year>
          )
          <fpage>1</fpage>
          -
          <lpage>28</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref25">
        <mixed-citation>
          [25]
          <string-name>
            <given-names>F.</given-names>
            <surname>Zahid</surname>
          </string-name>
          ,
          <string-name>
            <given-names>G.</given-names>
            <surname>Funchal</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Melo</surname>
          </string-name>
          ,
          <string-name>
            <surname>M. M. Kuo</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          <string-name>
            <surname>Leitao</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          <string-name>
            <surname>Sinha</surname>
          </string-name>
          ,
          <article-title>Ddos attacks on smart manufacturing systems: A cross-domain taxonomy and attack vectors</article-title>
          ,
          <source>in: 2022 IEEE 20th International Conference on Industrial Informatics (INDIN)</source>
          , IEEE,
          <year>2022</year>
          , pp.
          <fpage>214</fpage>
          -
          <lpage>219</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref26">
        <mixed-citation>
          [26]
          <string-name>
            <given-names>L.</given-names>
            <surname>Caviglione</surname>
          </string-name>
          , W. Mazurczyk,
          <article-title>Never mind the malware, here's the stegomalware</article-title>
          ,
          <source>IEEE Security &amp; Privacy</source>
          <volume>20</volume>
          (
          <year>2022</year>
          )
          <fpage>101</fpage>
          -
          <lpage>106</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref27">
        <mixed-citation>
          [27]
          <string-name>
            <given-names>N.</given-names>
            <surname>Cassavia</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Caviglione</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Guarascio</surname>
          </string-name>
          , G. Manco,
          <string-name>
            <given-names>M.</given-names>
            <surname>Zuppelli</surname>
          </string-name>
          ,
          <article-title>Detection of steganographic threats targeting digital images in heterogeneous ecosystems through machine learning</article-title>
          ,
          <source>Journal of Wireless Mobile Networks, Ubiquitous Computing, and Dependable Applications</source>
          <volume>13</volume>
          (
          <year>2022</year>
          )
          <fpage>50</fpage>
          -
          <lpage>67</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref28">
        <mixed-citation>
          [28]
          <string-name>
            <given-names>Y.</given-names>
            <surname>Liu</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Z.</given-names>
            <surname>Xu</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Fan</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Y.</given-names>
            <surname>Hao</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.</given-names>
            <surname>Chen</surname>
          </string-name>
          ,
          <string-name>
            <given-names>H.</given-names>
            <surname>Chen</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Y.</given-names>
            <surname>Cai</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Z.</given-names>
            <surname>Yang</surname>
          </string-name>
          , T. Liu, Concspectre:
          <article-title>Be aware of forthcoming malware hidden in concurrent programs</article-title>
          ,
          <source>IEEE Transactions on Reliability</source>
          <volume>71</volume>
          (
          <year>2022</year>
          )
          <fpage>1174</fpage>
          -
          <lpage>1188</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref29">
        <mixed-citation>
          [29]
          <string-name>
            <given-names>S.</given-names>
            <surname>Zander</surname>
          </string-name>
          , G. Armitage,
          <string-name>
            <given-names>P.</given-names>
            <surname>Branch</surname>
          </string-name>
          ,
          <article-title>A survey of covert channels and countermeasures in computer network protocols</article-title>
          ,
          <source>IEEE Communications Surveys &amp; Tutorials</source>
          <volume>9</volume>
          (
          <year>2007</year>
          )
          <fpage>44</fpage>
          -
          <lpage>57</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref30">
        <mixed-citation>
          [30]
          <string-name>
            <given-names>W.</given-names>
            <surname>Mazurczyk</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.</given-names>
            <surname>Powójski</surname>
          </string-name>
          , L. Caviglione,
          <article-title>IPv6 covert channels in the wild</article-title>
          ,
          <source>in: Proceedings of the third central european cybersecurity conference</source>
          ,
          <year>2019</year>
          , pp.
          <fpage>1</fpage>
          -
          <lpage>6</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref31">
        <mixed-citation>
          [31]
          <string-name>
            <given-names>M.</given-names>
            <surname>Guarascio</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Zuppelli</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Cassavia</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Caviglione</surname>
          </string-name>
          , G. Manco,
          <article-title>Revealing MageCart-like threats in favicons via artificial intelligence</article-title>
          ,
          <source>in: Proceedings of the 17th International Conference on Availability, Reliability and Security</source>
          ,
          <year>2022</year>
          , pp.
          <fpage>1</fpage>
          -
          <lpage>7</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref32">
        <mixed-citation>
          [32]
          <string-name>
            <given-names>K.</given-names>
            <surname>Shu</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Cui</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Wang</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Lee</surname>
          </string-name>
          , H. Liu, Defend:
          <article-title>Explainable fake news detection</article-title>
          ,
          <source>in: Proceedings of the 25th ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, KDD '19</source>
          ,
          <year>2019</year>
          , p.
          <fpage>395</fpage>
          -
          <lpage>405</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref33">
        <mixed-citation>
          [33]
          <string-name>
            <given-names>C.</given-names>
            <surname>Raj</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Meel</surname>
          </string-name>
          ,
          <article-title>Arcnn framework for multimodal infodemic detection</article-title>
          ,
          <source>Neural Networks</source>
          <volume>146</volume>
          (
          <year>2022</year>
          )
          <fpage>36</fpage>
          -
          <lpage>68</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref34">
        <mixed-citation>
          [34]
          <string-name>
            <given-names>T.</given-names>
            <surname>Sachan</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Pinnaparaju</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Gupta</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Varma</surname>
          </string-name>
          , Scate:
          <article-title>Shared cross attention transformer encoders for multimodal fake news detection</article-title>
          ,
          <source>in: Proceedings of the 2021 IEEE/ACM International Conference on Advances in Social Networks Analysis and Mining, ASONAM '21</source>
          ,
          <year>2021</year>
          , p.
          <fpage>399</fpage>
          -
          <lpage>406</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref35">
        <mixed-citation>
          [35]
          <string-name>
            <given-names>R.</given-names>
            <surname>Kumari</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Ekbal</surname>
          </string-name>
          ,
          <article-title>Amfb: Attention based multimodal factorized bilinear pooling for multimodal fake news detection</article-title>
          ,
          <source>Expert Systems with Applications</source>
          <volume>184</volume>
          (
          <year>2021</year>
          )
          <fpage>115412</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref36">
        <mixed-citation>
          [36]
          <string-name>
            <given-names>Z.</given-names>
            <surname>Jin</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Cao</surname>
          </string-name>
          ,
          <string-name>
            <given-names>H.</given-names>
            <surname>Guo</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Y.</given-names>
            <surname>Zhang</surname>
          </string-name>
          , J. Luo,
          <article-title>Multimodal fusion with recurrent neural networks for rumor detection on microblogs</article-title>
          ,
          <source>in: Proceedings of the 25th ACM International Conference on Multimedia, Association for Computing Machinery</source>
          , New York, NY, USA,
          <year>2017</year>
          , p.
          <source>MM '17.</source>
        </mixed-citation>
      </ref>
      <ref id="ref37">
        <mixed-citation>
          [37]
          <string-name>
            <given-names>Q.</given-names>
            <surname>Jing</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Yao</surname>
          </string-name>
          ,
          <string-name>
            <given-names>X.</given-names>
            <surname>Fan</surname>
          </string-name>
          ,
          <string-name>
            <given-names>B.</given-names>
            <surname>Wang</surname>
          </string-name>
          ,
          <string-name>
            <given-names>H.</given-names>
            <surname>Tan</surname>
          </string-name>
          ,
          <string-name>
            <given-names>X.</given-names>
            <surname>Bu</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Bi</surname>
          </string-name>
          ,
          <article-title>Transfake: Multi-task transformer for multimodal enhanced fake news detection</article-title>
          ,
          <source>in: IJCNN</source>
          ,
          <year>2021</year>
          , pp.
          <fpage>1</fpage>
          -
          <lpage>8</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref38">
        <mixed-citation>
          [38]
          <string-name>
            <given-names>J.</given-names>
            <surname>Wang</surname>
          </string-name>
          ,
          <string-name>
            <given-names>H.</given-names>
            <surname>Mao</surname>
          </string-name>
          ,
          <string-name>
            <given-names>H.</given-names>
            <surname>Li</surname>
          </string-name>
          ,
          <article-title>Fmfn: Fine-grained multimodal fusion networks for fake news detection</article-title>
          ,
          <source>Applied Sciences</source>
          <volume>12</volume>
          (
          <year>2022</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref39">
        <mixed-citation>
          [39]
          <string-name>
            <given-names>X.</given-names>
            <surname>Zhang</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Cao</surname>
          </string-name>
          ,
          <string-name>
            <given-names>X.</given-names>
            <surname>Li</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Q.</given-names>
            <surname>Sheng</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Zhong</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.</given-names>
            <surname>Shu</surname>
          </string-name>
          ,
          <article-title>Mining dual emotion for fake news detection</article-title>
          ,
          <source>in: Proceedings of the Web Conference</source>
          <year>2021</year>
          , WWW '21,
          <string-name>
            <surname>Association</surname>
          </string-name>
          for Computing Machinery,
          <year>2021</year>
          , p.
          <fpage>3465</fpage>
          -
          <lpage>3476</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref40">
        <mixed-citation>
          [40]
          <string-name>
            <given-names>Y.</given-names>
            <surname>Wang</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F.</given-names>
            <surname>Ma</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Z.</given-names>
            <surname>Jin</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Y.</given-names>
            <surname>Yuan</surname>
          </string-name>
          , G. Xun,
          <string-name>
            <given-names>K.</given-names>
            <surname>Jha</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Su</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Gao</surname>
          </string-name>
          , Eann:
          <article-title>Event adversarial neural networks for multi-modal fake news detection</article-title>
          ,
          <source>in: Proceedings of the 24th ACM SIGKDD International Conference on Knowledge Discovery &amp; Data Mining, KDD '18</source>
          ,
          <string-name>
            <surname>Association</surname>
          </string-name>
          for Computing Machinery,
          <year>2018</year>
          , p.
          <fpage>849</fpage>
          -
          <lpage>857</lpage>
          . URL: https://doi.org/10.1145/3219819.3219903. doi:
          <volume>10</volume>
          .1145/3219819.3219903.
        </mixed-citation>
      </ref>
      <ref id="ref41">
        <mixed-citation>
          [41]
          <string-name>
            <given-names>K.</given-names>
            <surname>Shu</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Mahudeswaran</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Wang</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Lee</surname>
          </string-name>
          , H. Liu,
          <article-title>Fakenewsnet: A data repository with news content, social context and dynamic information for studying fake news on social media</article-title>
          , arXiv preprint arXiv:
          <year>1809</year>
          .
          <volume>01286</volume>
          (
          <year>2018</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref42">
        <mixed-citation>
          [42]
          <string-name>
            <given-names>L.</given-names>
            <surname>Caviglione</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.</given-names>
            <surname>Comito</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Guarascio</surname>
          </string-name>
          , G. Manco,
          <article-title>Emerging challenges and perspectives in deep learning model security: A brief survey</article-title>
          ,
          <source>Systems and Soft Computing</source>
          <volume>5</volume>
          (
          <year>2023</year>
          )
          <article-title>200050</article-title>
          . doi:https://doi.org/10.1016/j.sasc.
          <year>2023</year>
          .
          <volume>200050</volume>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>