A Case-Control Measurement Study of OSINT Source Effectiveness for Critical Infrastructure Defense

📅 2026-08-20
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
研究通过审计十类公开OSINT源对54起关键基础设施网络攻击的覆盖率、误报率和预警时间,解决了缺乏实证基础选择有效情报源的问题。
📝 Abstract
Defenders of critical infrastructure (CI) subscribe to many public open-source intelligence (OSINT) feeds without an empirical basis for which feeds actually precede attacks. We provide one. Across 54 confirmed CI cyberattacks from 2010 through 2024 spanning twelve named CI sectors plus a cross-sector category (consolidation rules in Section IV), paired with 12 null-control vulnerability cases drawn from the same source space, we audit per-source attack coverage, null-case contamination, and signal lead time for ten public OSINT source classes that meet a minimum-volume threshold. Sources separate cleanly into three operationally distinct mission profiles (pooled Fisher exact p = 3.4x10^-8): precursor (six classes with zero observed null firings at coverage at or above 5%), disclosure-exposure (three classes whose null contamination meets or exceeds attack coverage), and one large broad-coverage class that mixes the two profiles but retains 91.3% within-corpus precision. The precision-side classification is stable across a 2019 temporal partition and across a US-versus-non-US geographic partition. Two sources, one broad-coverage and one precursor, cover 92.6% of corpus attacks; three cover 96.3%. The greedy portfolio at k = 3 outperforms the mean random three-source subset by 39.8 percentage points. Several source classes widely treated as canonical for industrial control system defense fall into the disclosure-exposure profile by operational mission, not by quality. Per-sector, per-actor, and per-jurisdiction portfolios diverge in rank order despite a shared rank-one source. The corpus, linkage protocol, and classification rules are released.
Problem

Research questions and friction points this paper is trying to address.

OSINT
Critical Infrastructure
Cyberattacks
Source Effectiveness
Empirical Basis
Innovation

Methods, ideas, or system contributions that make the work stand out.

OSINT Source Effectiveness
Critical Infrastructure Defense
Cyberattack Prediction
Source Classification
Empirical Basis
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
E
Ekrem E. Emeksiz
The University of Baltimore, Baltimore, MD, USA
J
Jeel Piyushkumar Khatiwala
The University of Baltimore, Baltimore, MD, USA
D
Divyangkumar Patel
Cox Automotive Inc, USA
Weifeng Xu
Weifeng Xu
Professor, University of Baltimore
Digital ForensicsSoftware SecurityApplied AI/ML