In the modern cybersecurity landscape, Cyber Threat Intelligence (CTI) has become essential for proactive defense strategies. However, its effectiveness is limited by massive data volumes and scattered information sources. Security analysts are increasingly challenged by the lack of a unified, timely, and granular view of the threat landscape, necessitating the manual correlation of heterogeneous data from Surface Web reports, ephemeral social media channels, and restricted communities within the Deep and Dark Web. This thesis addresses these challenges through the design and implementation of Argus, a distributed, microservices-based platform engineered to automate the entire lifecycle of intelligence data collection and processing. The proposed solution leverages a scalable ETL (Extract, Transform, Load) pipeline that orchestrates advanced web spiders to harvest data from disparate sources, overcoming technical barriers such as anti-bot protections and anonymous network routing (Tor). An AI pipeline enriches the raw data, transforming it into actionable intelligence, including Named Entity Recognition (NER) and automated classification (to filter noise from relevant, high-quality data), before being normalized into a structured Data Warehouse optimized for analytical queries. Furthermore, this work utilizes the deployed platform to conduct a comprehensive comparative analysis of the monitored sources. By defining and applying rigorous metrics, specifically timeliness, information density, and exclusivity to real-world case studies, the research highlights the distinct contribution of non-conventional sources to the early warning process. The empirical results confirm that official advisories are the most reliable baseline for validated disclosure and remediation, while underground sources provide a measurable Time-to-Insight advantage: Telegram is increasingly becoming a key reference point for early detection and forums can anticipate disclosure by weeks to months, while still providing strategic signals.
Nel panorama odierno della sicurezza informatica, la Cyber Threat Intelligence (CTI) è diventata fondamentale per abilitare strategie di difesa proattive. Tuttavia, la sua efficacia è limitata da volumi di dati massivi e da fonti informative frammentate. Gli analisti di sicurezza sono sempre più penalizzati dall'assenza di una visione unificata, tempestiva e granulare del threat landscape, che rende necessaria la correlazione manuale di dati eterogenei provenienti da report del Surface Web, canali effimeri dei social media e comunità a accesso ristretto nel Deep e Dark Web. Questa tesi affronta tali sfide attraverso la progettazione e l'implementazione di Argus, una piattaforma distribuita basata su microservizi, ingegnerizzata per automatizzare l'intero ciclo di vita della raccolta e dell'elaborazione dei dati di intelligence. La soluzione proposta sfrutta una pipeline ETL (Extract, Transform, Load) scalabile che orchestra web spider avanzati per acquisire dati da sorgenti eterogenee, superando barriere tecniche quali protezioni anti-bot e il routing su reti anonime (Tor). Una pipeline di AI arricchisce i dati grezzi, trasformandoli in intelligence azionabile, questa include un modulo di Named Entity Recognition (NER) e uno di classificazione (per filtrare il rumore dai dati CTI rilevanti), prima della normalizzazione in un Data Warehouse strutturato e ottimizzato per query analitiche. Questo lavoro utilizza inoltre la piattaforma implementata per condurre un'analisi comparativa completa delle sorgenti monitorate. Valutando metriche come tempestività, densità informativa ed esclusività, a casi di studio reali, la ricerca mette in evidenza il contributo distintivo delle sorgenti non convenzionali nel processo di early warning. I risultati empirici confermano che gli advisory ufficiali rappresentano la baseline più affidabile per disclosure e remediation validate, mentre le sorgenti underground forniscono un vantaggio misurabile in termini di Time-to-Insight: Telegram sta diventando un punto di riferimento chiave per l'identificazione precoce e i forum possono anticipare la disclosure da settimane a mesi, preservando comunque segnali strategici.
Argus: a platform for multi-source cyber threat intelligence collection and analysis
MARRA, BIAGIO;POLITO, ATTILIO
2025/2026
Abstract
In the modern cybersecurity landscape, Cyber Threat Intelligence (CTI) has become essential for proactive defense strategies. However, its effectiveness is limited by massive data volumes and scattered information sources. Security analysts are increasingly challenged by the lack of a unified, timely, and granular view of the threat landscape, necessitating the manual correlation of heterogeneous data from Surface Web reports, ephemeral social media channels, and restricted communities within the Deep and Dark Web. This thesis addresses these challenges through the design and implementation of Argus, a distributed, microservices-based platform engineered to automate the entire lifecycle of intelligence data collection and processing. The proposed solution leverages a scalable ETL (Extract, Transform, Load) pipeline that orchestrates advanced web spiders to harvest data from disparate sources, overcoming technical barriers such as anti-bot protections and anonymous network routing (Tor). An AI pipeline enriches the raw data, transforming it into actionable intelligence, including Named Entity Recognition (NER) and automated classification (to filter noise from relevant, high-quality data), before being normalized into a structured Data Warehouse optimized for analytical queries. Furthermore, this work utilizes the deployed platform to conduct a comprehensive comparative analysis of the monitored sources. By defining and applying rigorous metrics, specifically timeliness, information density, and exclusivity to real-world case studies, the research highlights the distinct contribution of non-conventional sources to the early warning process. The empirical results confirm that official advisories are the most reliable baseline for validated disclosure and remediation, while underground sources provide a measurable Time-to-Insight advantage: Telegram is increasingly becoming a key reference point for early detection and forums can anticipate disclosure by weeks to months, while still providing strategic signals.| File | Dimensione | Formato | |
|---|---|---|---|
|
2026_03_Marra_Polito_Executive Summary.pdf
accessibile in internet per tutti
Descrizione: Testo dell'Executive Summary
Dimensione
544.6 kB
Formato
Adobe PDF
|
544.6 kB | Adobe PDF | Visualizza/Apri |
|
2026_03_Marra_Polito_Tesi.pdf
accessibile in internet per tutti
Descrizione: Testo della Tesi
Dimensione
64.67 MB
Formato
Adobe PDF
|
64.67 MB | Adobe PDF | Visualizza/Apri |
I documenti in POLITesi sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.
https://hdl.handle.net/10589/251549