TEMPORAL DECAY DYNAMIC SCORING MODEL FOR INDICATORS OF COMPROMISE VIA STIX 2.1 EXTENSION

Authors

DOI:

https://doi.org/10.28925/2663-4023.2026.34.1273

Keywords:

STIX 2.1, CTI, SIEM, dynamic scoring, temporal decay, source reputation, OSINT enrichment, CTI lifecycle

Abstract

This article proposes a temporal decay dynamic scoring model (TDDS) for indicators of compromise (IoC), formalized as an extension of the STIX 2.1 standard using the Extension Definition mechanism. The model is based on a composite mathematical formula that combines four components: an initial relevance score, determined by the indicator type according to the Pyramid of Pain (PoP) hierarchy, source reputation, and the degree of corroboration; an adaptive decay coefficient, which depends on the characteristic half-life for the respective indicator type, a scaling factor derived from the source reputation, and the campaign context; a sighting-based decay-slowing function; and an enrichment adjustment term derived from Open-Source Intelligence (OSINT) data. Using the STIX 2.1 extension mechanism, the paper formalizes a data structure that enables the transfer of TDDS model parameters between cyber threat intelligence (CTI) systems. Unlike existing implementations such as MISP and OpenCTI, where decay-related parameters remain part of the platform's internal logic and are not preserved during export, the proposed approach encapsulates computed model parameters and intermediate calculation results directly within the STIX 2.1 object structure. This enables autonomous IoC relevance evaluation by receiving systems without dependence on the infrastructure of the originating platform.

Downloads

Download data is not yet available.

References

IBM Security. (2025). Cost of a data breach report 2025. IBM. https://www.ibm.com/reports/data-breach

Crowley, C. (2025). SANS 2025 SOC survey. SANS Institute. https://www.sans.org/white-papers/sans-2025-soc-survey

OASIS Cyber Threat Intelligence Technical Committee. (2021). STIX™ Version 2.1. OASIS Open. https://www.oasis-open.org/standard/stix-version-2-1/

Blakely, B., & Karcz, D. (2025). Grid-STIX: A STIX 2.1-compliant cyber-physical security ontology for power grid (arXiv:2511.11366). arXiv. https://doi.org/10.48550/arXiv.2511.11366

Mavroeidis, V., & Zych, M. (2022). Cybersecurity playbook sharing with STIX 2.1 (arXiv:2203.04136). arXiv. https://doi.org/10.48550/arXiv.2203.04136

Iklody, A., Wagener, G., Dulaunoy, A., Mokaddem, S., & Wagner, C. (2018). Decaying indicators of compromise (arXiv:1803.11052). arXiv. https://doi.org/10.48550/arXiv.1803.11052

Jard, A., & Hadjiat, S. (2024). Introducing decay rules implementation for indicators in OpenCTI. Filigran Blog. https://filigran.io/blog/introducing-decay-rules-implementation-for-indicators-in-opencti/

Tostes, B., Ventura, L., Lovat, E., Martins, M., & Menasché, D. S. (2023). Learning when to say goodbye: What should be the shelf life of an indicator of compromise? (arXiv:2307.16852). arXiv. https://doi.org/10.48550/arXiv.2307.16852

Kodituwakku, A., Xu, C., Rogers, D., Ahn, D. K., & Fulp, E. W. (2024). Investigating the temporal dynamics of cyber threat intelligence (arXiv:2412.19086). arXiv. https://doi.org/10.48550/arXiv.2412.19086

Chen, S.-S., Hwang, R.-H., Ali, A., Lin, Y.-D., Wei, Y.-C., & Pai, T.-W. (2024). Improving quality of indicators of compromise using STIX graphs. Computers & Security, Article 103972. https://doi.org/10.1016/j.cose.2024.103972

Bianco, D. J. (2013). The Pyramid of Pain. Enterprise Detection & Response. https://detect-respond.blogspot.com/2013/03/the-pyramid-of-pain.html

Yang, L., Wang, M., & Lou, W. (2024). An automated dynamic quality assessment method for cyber threat intelligence. Computers & Security, Article 104079. https://doi.org/10.1016/j.cose.2024.104079

MISP Project. (2019). Best practices in threat intelligence. https://www.misp-project.org/best-practices-in-threat-intelligence.html

Siam, A. A., Hassan, M. M., Masum, A. K. M., & Bhuiyan, T. (2025). Automating malware detection and response via real-time threat feed integration with Wazuh SIEM. In Proceedings of the IEEE Conference (IEEE Xplore). https://ieeexplore.ieee.org/document/11381876/

Elastic. (2024). Elastic’s new custom threat intelligence integration. Elastic Blog. https://www.elastic.co/blog/custom-threat-intelligence-integration

Downloads


Abstract views: 16

Published

2026-09-24

How to Cite

Hordiienko, M. (2026). TEMPORAL DECAY DYNAMIC SCORING MODEL FOR INDICATORS OF COMPROMISE VIA STIX 2.1 EXTENSION. Electronic Professional Scientific Journal «Cybersecurity: Education, Science, Technique», 2(34), 158–168. https://doi.org/10.28925/2663-4023.2026.34.1273