TEMPORAL DECAY DYNAMIC SCORING MODEL FOR INDICATORS OF COMPROMISE VIA STIX 2.1 EXTENSION
DOI:
https://doi.org/10.28925/2663-4023.2026.34.1273Keywords:
STIX 2.1, CTI, SIEM, dynamic scoring, temporal decay, source reputation, OSINT enrichment, CTI lifecycleAbstract
This article proposes a temporal decay dynamic scoring model (TDDS) for indicators of compromise (IoC), formalized as an extension of the STIX 2.1 standard using the Extension Definition mechanism. The model is based on a composite mathematical formula that combines four components: an initial relevance score, determined by the indicator type according to the Pyramid of Pain (PoP) hierarchy, source reputation, and the degree of corroboration; an adaptive decay coefficient, which depends on the characteristic half-life for the respective indicator type, a scaling factor derived from the source reputation, and the campaign context; a sighting-based decay-slowing function; and an enrichment adjustment term derived from Open-Source Intelligence (OSINT) data. Using the STIX 2.1 extension mechanism, the paper formalizes a data structure that enables the transfer of TDDS model parameters between cyber threat intelligence (CTI) systems. Unlike existing implementations such as MISP and OpenCTI, where decay-related parameters remain part of the platform's internal logic and are not preserved during export, the proposed approach encapsulates computed model parameters and intermediate calculation results directly within the STIX 2.1 object structure. This enables autonomous IoC relevance evaluation by receiving systems without dependence on the infrastructure of the originating platform.
Downloads
References
IBM Security. (2025). Cost of a data breach report 2025. IBM. https://www.ibm.com/reports/data-breach
Crowley, C. (2025). SANS 2025 SOC survey. SANS Institute. https://www.sans.org/white-papers/sans-2025-soc-survey
OASIS Cyber Threat Intelligence Technical Committee. (2021). STIX™ Version 2.1. OASIS Open. https://www.oasis-open.org/standard/stix-version-2-1/
Blakely, B., & Karcz, D. (2025). Grid-STIX: A STIX 2.1-compliant cyber-physical security ontology for power grid (arXiv:2511.11366). arXiv. https://doi.org/10.48550/arXiv.2511.11366
Mavroeidis, V., & Zych, M. (2022). Cybersecurity playbook sharing with STIX 2.1 (arXiv:2203.04136). arXiv. https://doi.org/10.48550/arXiv.2203.04136
Iklody, A., Wagener, G., Dulaunoy, A., Mokaddem, S., & Wagner, C. (2018). Decaying indicators of compromise (arXiv:1803.11052). arXiv. https://doi.org/10.48550/arXiv.1803.11052
Jard, A., & Hadjiat, S. (2024). Introducing decay rules implementation for indicators in OpenCTI. Filigran Blog. https://filigran.io/blog/introducing-decay-rules-implementation-for-indicators-in-opencti/
Tostes, B., Ventura, L., Lovat, E., Martins, M., & Menasché, D. S. (2023). Learning when to say goodbye: What should be the shelf life of an indicator of compromise? (arXiv:2307.16852). arXiv. https://doi.org/10.48550/arXiv.2307.16852
Kodituwakku, A., Xu, C., Rogers, D., Ahn, D. K., & Fulp, E. W. (2024). Investigating the temporal dynamics of cyber threat intelligence (arXiv:2412.19086). arXiv. https://doi.org/10.48550/arXiv.2412.19086
Chen, S.-S., Hwang, R.-H., Ali, A., Lin, Y.-D., Wei, Y.-C., & Pai, T.-W. (2024). Improving quality of indicators of compromise using STIX graphs. Computers & Security, Article 103972. https://doi.org/10.1016/j.cose.2024.103972
Bianco, D. J. (2013). The Pyramid of Pain. Enterprise Detection & Response. https://detect-respond.blogspot.com/2013/03/the-pyramid-of-pain.html
Yang, L., Wang, M., & Lou, W. (2024). An automated dynamic quality assessment method for cyber threat intelligence. Computers & Security, Article 104079. https://doi.org/10.1016/j.cose.2024.104079
MISP Project. (2019). Best practices in threat intelligence. https://www.misp-project.org/best-practices-in-threat-intelligence.html
Siam, A. A., Hassan, M. M., Masum, A. K. M., & Bhuiyan, T. (2025). Automating malware detection and response via real-time threat feed integration with Wazuh SIEM. In Proceedings of the IEEE Conference (IEEE Xplore). https://ieeexplore.ieee.org/document/11381876/
Elastic. (2024). Elastic’s new custom threat intelligence integration. Elastic Blog. https://www.elastic.co/blog/custom-threat-intelligence-integration
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Мілан Гордієнко

This work is licensed under a Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.