<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta>
      <journal-title-group>
        <journal-title>A. Skurativskyi)</journal-title>
      </journal-title-group>
    </journal-meta>
    <article-meta>
      <title-group>
        <article-title>A comparative analysis of cyber threat intelligence models</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Roman Odarchenko</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Alla Pinchuk</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Oleh Polihenko</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Anatolii Skurativskyi</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>National Aviation University</institution>
          ,
          <addr-line>Liubomyra Huzara Ave. 1, Kyiv, 03058</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
      </contrib-group>
      <pub-date>
        <year>2025</year>
      </pub-date>
      <volume>000</volume>
      <fpage>0</fpage>
      <lpage>0002</lpage>
      <abstract>
        <p>Cyber Threat Intelligence (CTI) plays a crucial role in modern cybersecurity by providing actionable insights into attacker behavior, motives, and tactics. As the threat landscape evolves, so too do CTI models, each with its own strengths and weaknesses. This article presents a comparative analysis of various CTI models, such as Diamond Model, Extended Diamond Model, Cyber Kill Chain, Unified Cyber Kill Chain and MITRE ATT&amp;CK Model, exploring their core functionalities, underlying methodologies, and suitability for different use cases. By understanding the nuances of each model, security professionals can make informed decisions about which CTI approach best suits their organizational needs.</p>
      </abstract>
      <kwd-group>
        <kwd>eol&gt;cyber threat intelligence</kwd>
        <kwd>CTI models</kwd>
        <kwd>models analysis1</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>•
•
•
•</p>
      <p>Strategic: it provides a high-level perspective on threat intelligence, considering financial
impact, attack trends, and global implications. It focuses on long-term usability of gathered
intelligence. In this context, analysts examine attack patterns across industries, changes in
TTPs over time, malware usage, and data breaches. Strategic CTI informs executive decisions
and guides long-term security planning. On the other hand, subtype CTI delves beyond
technical risks, considering the motivations behind attacks. It takes into account who or
which organization is behind the attacks, their objectives, and why they target specific
entities. Subtype CTI serves as an early warning system for anticipated threats, aiding
organizations in proactively establishing defences based on current attack trends, without
necessarily revealing specific methods or codes.</p>
      <p>Tactical: focuses on understanding threat actors’ methods of operation. It equips responders
and defenders with knowledge to prepare alarms, defences, and investigations against the
latest threats. Sources for tactical CTI include white papers, technical press, and interactions
with other organizations and peers. Specifically, tactical CTI provides detailed information
about attackers. This encompasses mapping out threat actor TTPs, defining their goals, and
understanding their technical capabilities. Armed with this intelligence, organizations can
proactively fine-tune their mitigation tactics and even simulate attacks to identify
vulnerabilities in their security infrastructure.</p>
      <p>Technical: it focuses on specific threat indicators, such as Indicators of Compromise (IoCs),
relevant to SOC Staff. Aligned with operational intelligence, technical CTI helps identify
signs of ongoing attacks. By leveraging threat intelligence platforms with AI, organizations
can automatically scan for known indicators, including phishing email content, malicious IP
addresses, and specific malware implementations. SOC and incident response teams can
swiftly respond to this information, preventing potential damage to the organization.
Analysts gather information about the attacker’s command and control (C2) infrastructure,
tools, malware, and other technical resources used against the organization.</p>
      <p>
        Operational: it focuses on specific threats against an organization, considering threat actor
motivations, vulnerability exploitation, past and current malicious activity, and the impact
of cyberattacks on confidentiality, integrity, and availability. It helps assess an organization’s
resilience against cyber threats. Operational CTI provides specialized information about
attacker identities, motivations, and methods. Automation through a cyber threat intelligence
platform enhances data collection efficiency [
        <xref ref-type="bibr" rid="ref2 ref3 ref4 ref5">2–5</xref>
        ].
      </p>
      <p>High-level
information on
changing risk
The board
Details of a specific
incoming attack</p>
      <p>Defenders</p>
      <p>For every subtype, there are also different methods for gathering information, such as OSINT
(Open-Source Intelligence), CSINT (Closed Source Intelligence), HUMINT (Human Intelligence) and
TECHINT (Technical Intelligence).</p>
      <p>CTI models enable organizations to effectively organize and analyze CTI data, gaining a
comprehensive understanding of the evolving threat landscape. To achieve all CTI goals, different
Cyber Threat Intelligence models are used. Each CTI model offers unique perspectives and
methodologies to analyze, understand, and mitigate these threats. At the same time, each model has
advantages and disadvantages that cyber security specialists in organizations need to take into
account.</p>
      <p>
        There are a lot of CTI models available, and research was conducted regarding their use in CTI
systems. In [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ], the usage, pros and cons of such models as the F2T2EA model, the Cyber Kill Chain
model, the Diamond model of intrusion analysis, and the Q model were discussed. According to [
        <xref ref-type="bibr" rid="ref7 ref8">7,
8</xref>
        ], there are three models that stand above all other existence models: Cyber Kill Chain, MITRE
ATT&amp;CK, and Diamond; they use different approaches, but all of them are very useful in CTI. In [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ],
the most effective models of cybersecurity organizations were discussed.
      </p>
      <p>Thus, the aim of this article is to analyze the most common Cyber Threat Intelligence models and
provide full comparison regarding their usage in CTI systems.</p>
    </sec>
    <sec id="sec-2">
      <title>2. The Diamond Model and the Extended Diamond Model</title>
      <sec id="sec-2-1">
        <title>2.1. The Diamond Model</title>
        <p>
          The Diamond model represents a new concept for analyzing intrusions developed by cybersecurity
analysts. This model establishes the basic "atomic element" of any intrusion activity or cyber incident
consists of four main functions: adversary, infrastructure, capability, and victim that are shown on
Figure 2. Because of the shape formed by the relationships between all these elements, this model is
named as a Diamond [
          <xref ref-type="bibr" rid="ref10">10</xref>
          ].
        </p>
        <p>When an event is detected, the vertices of the model are filled in automatically or with the help
of analysts.</p>
        <p>
          The vertices are connected by edges and highlight the natural connections between functions,
such as adversary-victim, adversary-infrastructure, victim-infrastructure and victim-capability [
          <xref ref-type="bibr" rid="ref11">11</xref>
          ].
As analysts follow the edges and vertices, they discover more information about the attacker's
operations and identify new capabilities, infrastructure, and victims.
        </p>
        <p>
          Infrastructure
(Physical and/or
logical resources
used by adversary)
The Diamond model includes the next meta-features [
          <xref ref-type="bibr" rid="ref10">10</xref>
          ]:
•
•
•
•
•
•
timestamp: date and time intrusion event occurred;
phase: which event, in the chain of events, is represented by this particular model;
result: outcome of intrusion (e.g., success, failure, or unknown; or confidentiality
compromised, integrity compromised, and/or availability compromised);
direction: how event moved through network or host (e.g., Victim-to-Infrastructure,
Adversary-to-Infrastructure, Bidirectional);
methodology: category of event (e.g., spear phishing, port scan);
resources: elements required for intrusion (e.g., particular software, hardware, knowledge,
funds, facilities, access).
        </p>
        <p>
          According to [
          <xref ref-type="bibr" rid="ref12">12</xref>
          ], this model establishes scientific principles and applies formal methods to
intrusion analysis, including measurement, testing, and comparison, providing a comprehensive
methodology for documenting, synthesizing, and correlating processes during the intrusion
investigator's activities.
        </p>
        <p>This scientific approach and simplicity results in improved analytical efficiency, productivity, and
accuracy. After all, the Diamond Model provides the ability to integrate real-time vulnerability
intelligence to protect networks, automate and correlate events, classify them by confidence level in
adversarial campaigns, predict adversarial operations in planning, and develop cost reduction
strategies.</p>
      </sec>
      <sec id="sec-2-2">
        <title>2.2. The Extended Diamond Model</title>
        <p>
          The Extended Diamond Model has some additional features that complement the original model and
make it more informative for analysts. New features for Extended Diamond Model are socio-political
meta-features to determine the relationship between the adversary and victim as well as technology
meta-features for infrastructure and capabilities [
          <xref ref-type="bibr" rid="ref13">13</xref>
          ]. The scheme of model is shown on Figure 3.
        </p>
        <p>Considering both versions of this model, it is worth adding a few key aspects. First of all, it makes
it simple for analysts to switch between different intelligence pieces, which either helps to reveal
intelligence blind spots or complete the picture while acquiring intelligence. Tracking enemies,
capabilities, infrastructure, and victims over time is the model's primary goal. An activity thread that
links trends in attackers, TPPs, and infrastructure across assaults against several victims is used to
display this activity. By outlining possible future directions that threat actors might go, the activity
thread helps defenders and responders approach security pro-actively rather than reactively.</p>
        <p>
          The diamond model's capacity to create activity groups and activity-attack graphs is another
essential feature. Activity groups are collections of shared identifying behaviors, such as a specific
APT activity or a typical attack path that threat actors use to indicate a particular kind of attack.
Activity-attack graphs are visual depictions of real attacks that take place at various points along the
cyber death chain in the threat landscape. In order to create scenarios that a company would
encounter, this enables CTI analysts to monitor ongoing activity in the threat landscape and correlate
the MITRE ATT&amp;CK TPPs to the cyber death chain. Security teams may create targeted threat hunt
scenarios and make sure their security stack defends against assaults encountered in the field by
using these attack graphs [
          <xref ref-type="bibr" rid="ref14">14</xref>
          ]. An example of such a graph is discussed in [
          <xref ref-type="bibr" rid="ref10 ref15">10, 15</xref>
          ].
        </p>
      </sec>
    </sec>
    <sec id="sec-3">
      <title>3. The Cyber Kill Chain and the Unified Cyber Kill Chain</title>
      <sec id="sec-3-1">
        <title>3.1. The Cyber Kill Chain Model</title>
        <p>
          The Cyber Kill Chain (CKC) Model was developed in 2011 by the US company Lockheed Martin and
mainly focused on Advanced Persistent Threat (APT) attacks [
          <xref ref-type="bibr" rid="ref16">16</xref>
          ]. Focusing on APT attacks, create
a strong impact on the CTI field. Generally, this model represents a series of steps that an attacker
must execute to reach his or her final objective based on the F2T2EA (Find, Fix, Track, Target,
Engage, Assess) concept [
          <xref ref-type="bibr" rid="ref17">17</xref>
          ]. The scheme of this model is shown on Figure 4. Explanation of each
step is in [
          <xref ref-type="bibr" rid="ref18 ref19">18, 19</xref>
          ]. The variants of this model are shown in [
          <xref ref-type="bibr" rid="ref20">20</xref>
          ].
        </p>
        <p>From the other side, here we cannot see the defender's part. If we present time scale correctly and
name some steps according to defender side, the whole attack can be divided in the next phases:
•
•
•</p>
        <p>Preparation (Phase 1 Reconnaissance, Phase 2 Arming);
Incident (Phase 3 Delivery, Phase 4 Intrusion, Phase 5 Installation);</p>
        <p>Active Intrusion (Phase 6 C2, Phase 7 Action).</p>
        <p>
          This model also has some problems. Firstly, it should be noticed that the flaw in this model lies
in its oversimplified portrayal of cyber-attacks as tidy and linear processes, which diverges from the
messier reality. Moreover, Cyber Kill Chain tends to focus solely on the immediate actor behind a
cyber-attack, disregarding the underlying motives or any potential insider collaboration. To enhance
the model’s effectiveness, it’s crucial to supplement it with knowledge about the attack’s sponsor,
drawing insights from real-world espionage cases [
          <xref ref-type="bibr" rid="ref6">6</xref>
          ].
        </p>
        <p>Despite its limitations, this model remains valuable for organizations seeking to fortify their
defenses by addressing vulnerabilities at each link in the chain, provided they have access to
highquality intelligence on the adversary’s actions throughout the process.</p>
      </sec>
      <sec id="sec-3-2">
        <title>3.2. The Unified Kill Chain Model</title>
        <p>
          The Cyber Kill Chain Model has been improved, the new approach was created and named Unified
Kill Chain (UKC) Model. The main idea of this model is to combine two existing models: the Lockheed
Martin' Cyber Kill Chain and the MITRE ATT&amp;CK for Enterprise [
          <xref ref-type="bibr" rid="ref21">21</xref>
          ].
        </p>
        <p>The MITRE ATT&amp;CK Framework offers a comprehensive inventory of adversary tactics and
techniques, while the Lockheed Martin Kill Chain offers a methodical view of an attacker's intrusion
stages. By merging these frameworks, the Unified Kill Chain allows enterprises to evaluate their
defenses from two different perspectives [22]:
•
•
strategically, taking into account the stages of an attack;
tactically, emphasizing particular attacker actions.</p>
        <p>This combination enables organizations to assess their security posture holistically and adjust
their defensive strategies as necessary.</p>
        <p>The Unified Kill Chain consists of eighteen phases, or strategies, that a cyberattack could go
through. Phases may be skipped, repeated, or executed out of order by any given attack. The scheme
of this model is shown on Figure 5.</p>
        <p>It is possible to combine several tactical phases of an attack to accomplish intermediate goals, like
getting a first foothold in a targeted network, breaking into it to increase your level of access, and
taking action against important assets.</p>
        <p>All typical cyberattack activities, from the initial reconnaissance conducted by external attackers
to the successful accomplishment of the attack's ultimate goals beyond the organizational perimeter,
can be modeled using the Unified Kill Chain. The Unified Kill Chain relies on the expertise of industry
leaders such as Lockheed Martin' Cyber Kill Chain and MITRE's ATT&amp;CK for Enterprise model in
order to cover such a wide range.</p>
      </sec>
    </sec>
    <sec id="sec-4">
      <title>4. The MITRE ATT&amp;CK model</title>
      <p>
        The MITRE Corporation developed the framework, data matrices, and assessment model known as
MITRE ATT&amp;CK (Adversarial Tactics, Techniques and Common Knowledge) to assist organizations
in assessing their security readiness and identifying weak points in their defenses [23]. Most of all,
it is a hub for exchanging knowledge and information about cyberattacks with an emphasis on the
development and execution of TTPs, where tactics stand for the reasons behind the actions an
attacker takes to accomplish their goal, techniques for how the attacker carries out the actions, and
procedures for the specific steps involved in putting the techniques into practice [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ].
      </p>
      <p>The adversary's "technical objectives" are divided into 14 tactics categories within the framework:
Reconnaissance, Resource Development, Initial Access, Execution, Persistence, Privilege Escalation,
Defence Evasion, Credential Access, Discovery, Lateral Movement, Collection, Command and
Control, Exfiltration and Impact [24]. Each category includes techniques and sub-techniques
(Figure 6).</p>
      <p>It can be said that the matrix is basically a historical reference of what techniques and methods
were popular among cybercriminals in the past, as well as a fresh look at the cyberthreat model
through the prism of techniques that hackers are actively using now [25, 26]. But it is worth adding
that in MITRE ATT&amp;CK, one technique can be repeated in several columns of the matrix [27]. This
is because attackers may have different goals, but may use the same means to achieve them.</p>
      <p>The MITRE ATT&amp;CK Matrix is looked at by security researchers from around the world. For
analysts, it's a good source to help structure information about current attack techniques. Knowing
how real APT groups operate allows you to formulate hypotheses for proactive threat hunting.</p>
      <p>Despite of advantages of this model, it also has some disadvantages:
•
•
•</p>
      <p>It's huge and complicated.</p>
      <p>There is a lot of data to be processed, and many organizations have not automated much of
that data in terms of mapping it to their security infrastructure or to other data they have in
their system.</p>
      <p>There are various attack patterns that are constantly evolving, making it impractical to detect
and map them against your security infrastructure.</p>
    </sec>
    <sec id="sec-5">
      <title>5. Comparison amongst different models</title>
      <p>The Diamond Model and the Extended Diamond Model have different approaches than other models.
In this case, we can compare these models regarding their focuses, granularities, and applications.
These characteristics provide a full understanding of each model and their use in CTI (Table 1).</p>
      <p>Despite the fact that CKC, UKC, and MITRE ATT&amp;CK are providing a lot of useful information
for incident response, attribution of a cyberattack to a threat actor is a complicated procedure that
the Diamond Model and the Extended Diamond Model excel at through all their features (both
nonmeta and meta). In fact, attribution should not be solely based on the analysis of an adversary’s use
of TTPs alone.</p>
      <p>By combining models that have different approaches, security teams will be able to get a complete
picture of cyber threats, how to protect their organization, and how to respond to incidents more
effectively [28–31].</p>
      <sec id="sec-5-1">
        <title>Diamond/</title>
        <p>Extended Diamond
Model emphasizes
attacker motivations
and capabilities
Model offers a broader
perspective
Model is useful for
threat intelligence and
threat hunting</p>
      </sec>
      <sec id="sec-5-2">
        <title>Cyber Kill Chain / Unified Kill Chain Model emphasizes attack stages</title>
      </sec>
      <sec id="sec-5-3">
        <title>Model is more specific</title>
      </sec>
      <sec id="sec-5-4">
        <title>Model is focused on incident response</title>
      </sec>
      <sec id="sec-5-5">
        <title>Users of the Diamond Model will need to feed it themselves</title>
      </sec>
      <sec id="sec-5-6">
        <title>In case of UKC, model uses MITRE ATT&amp;CK matrix</title>
      </sec>
    </sec>
    <sec id="sec-6">
      <title>6. Conclusions</title>
      <p>The cyber threat landscape is complex and constantly changing. Each CTI model offers unique
perspectives and methodologies for analyzing, understanding, and mitigating these threats.</p>
      <p>The Diamond Model/Extended Diamond Model is used only to analyze cyberattacks (intrusions),
to formalize them in order to answer the questions "who", "why" and "how" implemented the
cyberattack, provides IoCs of cyberattacks for further examination, but this model does not reflect
the stages of attacks.</p>
      <p>Models such as CKC, UKC, and MITRE ATT&amp;CK take into account the stages of cyber attacks,
with UKC covering more stages than the other two models. At the same time, MITRE ATT&amp;CK
serves as a broad knowledge base of intruder’s TTPs and provides a full understanding of threat actor
behavior. However, these models do not answer the question of what to do when an attack is
successful, nor do they pay attention to intrusion prevention.</p>
      <p>Combining multiple models or frameworks often results in a more holistic and effective approach
to cybersecurity, enabling organizations to proactively defend against a variety of cyber threats.
Continuously evolving and adapting these models is essential to staying ahead in the ongoing battle
against cyber adversaries.</p>
    </sec>
    <sec id="sec-7">
      <title>Declaration on Generative AI</title>
      <sec id="sec-7-1">
        <title>The author(s) have not employed any Generative AI tools.</title>
        <p>[22] J. Garrett, The Unified Kill Chain: Your Tool for Actively Evaluating Your Cyber Defenses, 2022.</p>
        <p>URL:
https://www.opkalla.com/articles/the-unified-kill-chain-your-tool-for-activelyevaluating-your-cyber-defenses.
[23] Understanding Cyber Kill Chain, MITRE ATT&amp;CK Framework and Unified Kill Chain, 2023.</p>
        <p>URL:
https://medium.com/@wintersoldiers/understanding-cyber-kill-chain-mitre-att-ckframework-and-unified-kill-chain-f306ceca19be.
[24] MITRE ATT&amp;CK, 2023. URL: https://attack.mitre.org.
[25] Y. Averyanova, et al., UAS cyber security hazards analysis and approach to qualitative
assessment, In: S. Shukla, A. Unal, J. Varghese Kureethara, D.K. Mishra, D.S. Han (Eds.), Data
science and security, volume 290 of Lecture Notes in Networks and Systems, Springer,
Singapore, 2021, pp. 258–265. doi: 10.1007/978-981-16-4486-3_28.
[26] M. Zaliskyi, et al., Heteroskedasticity analysis during operational data processing of radio
electronic systems, in: S. Shukla, A. Unal, J. Varghese Kureethara, D.K. Mishra, D.S. Han (Eds.),
Data science and security, volume 290 of Lecture Notes in Networks and Systems, Springer,
Singapore, 2021, pp. 168–175. doi: 10.1007/978-981-16-4486-3_18.
[27] R. S. Odarchenko, S. O. Gnatyuk, T. O. Zhmurko, O. P. Tkalich, Improved method of routing in
UAV network, in: Proceedings of International Conference Actual Problems of Unmanned
Aerial Vehicles Developments (APUAVD), IEEE, Kyiv, Ukraine, 2015, pp. 294–297. doi:
10.1109/APUAVD.2015.7346624.
[28] M. Zaliskyi, R. Odarchenko, S. Gnatyuk, Y. Petrova, A. Chaplits, Method of traffic monitoring
for DDoS attacks detection in e-health systems and networks, CEUR Workshop Proceedings
2255 (2018) 193–204. URL: https://ceur-ws.org/Vol-2255/paper18.pdf.
[29] V. Kharchenko, I. Chyrka, Detection of airplanes on the ground using YOLO neural network,
in: Proceedings of 17th International Conference on Mathematical Methods in Electromagnetic
Theory (MMET), IEEE, Kyiv, Ukraine, 2018, pp. 294–297. doi: 10.1109/MMET.2018.8460392.
[30] O. Sushchenko, et al., Airborne sensor for measuring components of terrestrial magnetic field,
in: Proceedings of IEEE 41st International Conference on Electronics and Nanotechnology
(ELNANO), IEEE, Kyiv, Ukraine, 2022, pp. 687–691. doi: 10.1109/ELNANO54667.2022.9926760.
[31] O. Solomentsev, M. Zaliskyi, O. Kozhokhina and T. Herasymenko, Efficiency of data processing
for UAV operation system, in: Proceedings of 4th International Conference Actual Problems of
Unmanned Aerial Vehicles Developments (APUAVD), IEEEб Kiev, Ukraine, 2017, pp. 27–31. doi:
10.1109/APUAVD.2017.8308769.</p>
      </sec>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <surname>Cyber</surname>
            <given-names>threat intelligence</given-names>
          </string-name>
          ,
          <year>2018</year>
          . URL: https://iitd.com.ua/en/rozvidka-kiberzagroz-cti/.
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>T.</given-names>
            <surname>Punz</surname>
          </string-name>
          , Cyber threat intelligence,
          <year>2018</year>
          . URL: https://www.securnite.com/index.php/onepress_service/cyber-threat-intelligence/.
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>L.</given-names>
            <surname>Taggart</surname>
          </string-name>
          ,
          <source>Why does strategic threat intelligence matter?</source>
          ,
          <year>2023</year>
          . URL: https://www.pwc.com/gx/en/issues/cybersecurity/cyber-threat
          <article-title>-intelligence/why-doesstrategic-threat-intelligence-matter</article-title>
          .html.
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>A.</given-names>
            <surname>Funkhouser</surname>
          </string-name>
          ,
          <source>Understanding cyber threat intelligence</source>
          ,
          <year>2022</year>
          . URL: https://www.netskope.com/blog/understanding
          <article-title>-cyber-threat-intelligence.</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          <source>[5] What is cyber threat intelligence?</source>
          ,
          <year>2022</year>
          . URL: https://www.microsoft.com/enus/security/business/security-101/what-is
          <article-title>-cyber-threat-intelligence.</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>M.</given-names>
            <surname>Sahrom</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S. R.</given-names>
            <surname>Selamat</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Ariffin</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Y.</given-names>
            <surname>Robiah</surname>
          </string-name>
          ,
          <article-title>An enhancement of cyber threat intelligence framework</article-title>
          ,
          <source>Journal of Advanced Research in Dynamical and Control Systems</source>
          <volume>10</volume>
          (
          <year>2018</year>
          )
          <fpage>96</fpage>
          -
          <lpage>104</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>A.</given-names>
            <surname>Sánchez del Monte</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Hernández-Álvarez</surname>
          </string-name>
          ,
          <article-title>Analysis of cyber-intelligence frameworks for AI data processing</article-title>
          ,
          <source>Appl. Sci. 13</source>
          .16 (
          <year>2023</year>
          )
          <article-title>9328</article-title>
          . doi:
          <volume>10</volume>
          .3390/app13169328.
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>N.</given-names>
            <surname>Naik</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Jenkins</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Grace</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Song</surname>
          </string-name>
          ,
          <article-title>Comparing attack models for IT systems: Lockheed Martin's Cyber Kill Chain</article-title>
          ,
          <string-name>
            <surname>MITRE ATT</surname>
          </string-name>
          &amp;
          <article-title>CK framework and diamond model</article-title>
          ,
          <source>in: Proceedings of International Symposium on Systems Engineering (ISSE)</source>
          , IEEE, Vienna, Austria,
          <year>2022</year>
          , pp.
          <fpage>1</fpage>
          -
          <lpage>7</lpage>
          . doi:
          <volume>10</volume>
          .1109/isse54508.
          <year>2022</year>
          .
          <volume>10005490</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>O.</given-names>
            <surname>Volot</surname>
          </string-name>
          ,
          <article-title>Information and cybernetic security of modern enterprise: Provision and modeling</article-title>
          ,
          <source>Central Ukr. Sci. Bull. Econ. Sci</source>
          .
          <volume>3</volume>
          (
          <issue>36</issue>
          ) (
          <year>2019</year>
          )
          <fpage>238</fpage>
          -
          <lpage>247</lpage>
          . doi:
          <volume>10</volume>
          .32515/
          <fpage>2663</fpage>
          -
          <lpage>1636</lpage>
          .
          <year>2018</year>
          .
          <volume>3</volume>
          (
          <issue>36</issue>
          ).
          <fpage>238</fpage>
          -
          <lpage>247</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <given-names>C.</given-names>
            <surname>Warner</surname>
          </string-name>
          , Diamond model in
          <source>cyber threat intelligence</source>
          ,
          <year>2021</year>
          . URL: https://warnerchad.medium.
          <article-title>com/diamond-model-for-cti-5aba5ba5585.</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <given-names>D.</given-names>
            <surname>Tidmarsh</surname>
          </string-name>
          ,
          <article-title>What is the Diamond Model of Intrusion Analysis in cybersecurity, 2023</article-title>
          . URL: https://www.eccouncil.org/cybersecurity-exchange/
          <article-title>ethical-hacking/diamond-model-intrusionanalysis.</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <given-names>A.</given-names>
            <surname>Zhylin</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Hudyncev</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Litvinov</surname>
          </string-name>
          ,
          <article-title>Functional model of cybersecurity situation center</article-title>
          ,
          <source>Collect. Inf. Technol. Secur. 6</source>
          .
          <issue>2</issue>
          (
          <year>2018</year>
          )
          <fpage>51</fpage>
          -
          <lpage>67</lpage>
          . doi:
          <volume>10</volume>
          .20535/
          <fpage>2411</fpage>
          -
          <lpage>1031</lpage>
          .
          <year>2018</year>
          .
          <volume>6</volume>
          .2.153490.
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <given-names>A.</given-names>
            <surname>Hearts</surname>
          </string-name>
          ,
          <source>Diamond Model of Intrusion Analysis</source>
          ,
          <year>2024</year>
          . URL: https://medium.com/@agapehearts/diamond
          <article-title>-model-of-intrusion-analysis-81af3ee1baeb.</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <article-title>Strategies for Gathering and Contextualizing Cyber Threat Intelligence</article-title>
          . URL: https://www.netskope.com/blog/strategies
          <article-title>-for-gathering-and-contextualizing-cyber-threatintelligence.</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [15]
          <string-name>
            <given-names>S.</given-names>
            <surname>Caltagirone</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Pendergast</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.</given-names>
            <surname>Betz</surname>
          </string-name>
          ,
          <article-title>The diamond model of intrusion analysis</article-title>
          ,
          <source>Threat Connect</source>
          <volume>298</volume>
          (
          <issue>0704</issue>
          ) (
          <year>2013</year>
          )
          <fpage>1</fpage>
          -
          <lpage>61</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [16]
          <string-name>
            <given-names>E. M.</given-names>
            <surname>Hutchins</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M. J.</given-names>
            <surname>Cloppert</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R. M.</given-names>
            <surname>Amin</surname>
          </string-name>
          ,
          <article-title>Intelligence-driven computer network defense informed by analysis of adversary campaigns and intrusion kill chains</article-title>
          ,
          <source>Leading Issues in Information Warfare &amp; Security Research</source>
          <volume>1</volume>
          (
          <issue>1</issue>
          ) (
          <year>2011</year>
          )
          <fpage>80</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          [17]
          <string-name>
            <surname>C. D. Means</surname>
            ,
            <given-names>E.</given-names>
          </string-name>
          <string-name>
            <surname>Darling</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          <string-name>
            <surname>Perron</surname>
          </string-name>
          ,
          <article-title>Applying Cognitive Work Analysis to Time Critical Targeting Functionality, Center For Air Force C2 Systems</article-title>
          , Bedford, MA (
          <year>2004</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          [18]
          <string-name>
            <surname>I. Tarnowski</surname>
          </string-name>
          ,
          <article-title>How to use cyber kill chain model to build cybersecurity?</article-title>
          ,
          <source>European Journal of Higher Education IT</source>
          (
          <year>2017</year>
          ). URL: https://www.eunis.org/download/TNC2017/TNC17- IreneuszTarnowski-cybersecurity.pdf.
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          [19]
          <string-name>
            <given-names>T.</given-names>
            <surname>Yadav</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.M.</given-names>
            <surname>Rao</surname>
          </string-name>
          ,
          <article-title>Technical aspects of cyber kill chain</article-title>
          . In: J.
          <string-name>
            <surname>Abawajy</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          <string-name>
            <surname>Mukherjea</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          <string-name>
            <surname>Thampi</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          <string-name>
            <surname>Ruiz-Martínez</surname>
          </string-name>
          (Eds.),
          <source>Security in Computing and Communications. SSCC</source>
          <year>2015</year>
          , volume
          <volume>536</volume>
          of Communications in Computer and Information Science, Springer, Cham,
          <year>2015</year>
          , pp.
          <fpage>438</fpage>
          -
          <lpage>452</lpage>
          . doi:
          <volume>10</volume>
          .1007/978-3-
          <fpage>319</fpage>
          -22915-7_
          <fpage>40</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          [20]
          <string-name>
            <surname>J. van den Berg</surname>
          </string-name>
          ,
          <source>The unified kill chain</source>
          ,
          <year>2017</year>
          . URL: https://www.unifiedkillchain.com/assets/TheUnified-Kill-Chain-Thesis.pdf.
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          [21]
          <string-name>
            <given-names>P.</given-names>
            <surname>Pols</surname>
          </string-name>
          ,
          <string-name>
            <surname>J. van den Berg</surname>
          </string-name>
          ,
          <article-title>The unified kill chain</article-title>
          ,
          <source>CSA Thesis</source>
          , Hague,
          <fpage>1</fpage>
          -
          <lpage>104</lpage>
          (
          <year>2017</year>
          ).
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>