This paper presents MATRIX (Malware Analysis and Threat Research with STIX), a graph database for the comprehensive analysis and research of malware and threats. To provide a unified view of the threat landscape, MATRIX integrates data from major cybersecurity frameworks, including MITRE ATT&CK, DEF3ND, CAPEC, Malware Behavior Catalog (MBC), Metasploit, Common Vulnerabilities and Exposures (CVE) and Common Weakness Enumeration (CWE). Developed in Neo4j using the Structured Threat Information Expression (STIX™) standard, MATRIX includes more than 22,910 nodes and combines 14 STIX Domain Objects (SDOs) and 6 STIX Relationship Objects (SROs) to provide a detailed analysis of malware behavior, detection rules and defense strategies, making it a valuable tool for cybersecurity research. The system also integrates real-world malware reports and is automatically updated with data from sources such as VirusTotal, MalwareBazaar and VirusShare, supporting continuous and up-to-date threat analysis. We demonstrate its versatility through case studies comparing malware objectives and analyzing the impact of detection and mitigation.

MATRIX: A Comprehensive Graph-Based Framework for Malware Analysis and Threat Research / Simoni, M., Saracino, A.. - 1:(2025), pp. 495-502. (International Conference on Security and Cryptography (SECRYPT 2025) Bilbao; Spain ) [10.5220/0013629300003979].

MATRIX: A Comprehensive Graph-Based Framework for Malware Analysis and Threat Research

Simoni, Marco
Primo
;
2025

Abstract

This paper presents MATRIX (Malware Analysis and Threat Research with STIX), a graph database for the comprehensive analysis and research of malware and threats. To provide a unified view of the threat landscape, MATRIX integrates data from major cybersecurity frameworks, including MITRE ATT&CK, DEF3ND, CAPEC, Malware Behavior Catalog (MBC), Metasploit, Common Vulnerabilities and Exposures (CVE) and Common Weakness Enumeration (CWE). Developed in Neo4j using the Structured Threat Information Expression (STIX™) standard, MATRIX includes more than 22,910 nodes and combines 14 STIX Domain Objects (SDOs) and 6 STIX Relationship Objects (SROs) to provide a detailed analysis of malware behavior, detection rules and defense strategies, making it a valuable tool for cybersecurity research. The system also integrates real-world malware reports and is automatically updated with data from sources such as VirusTotal, MalwareBazaar and VirusShare, supporting continuous and up-to-date threat analysis. We demonstrate its versatility through case studies comparing malware objectives and analyzing the impact of detection and mitigation.
2025
International Conference on Security and Cryptography (SECRYPT 2025)
Cyber Threat Intelligence; Knowledge Graph; Malware Analysis; Structured Threat Information Expression
04 Pubblicazione in atti di convegno::04b Atto di convegno in volume
MATRIX: A Comprehensive Graph-Based Framework for Malware Analysis and Threat Research / Simoni, M., Saracino, A.. - 1:(2025), pp. 495-502. (International Conference on Security and Cryptography (SECRYPT 2025) Bilbao; Spain ) [10.5220/0013629300003979].
File allegati a questo prodotto
File Dimensione Formato  
Simoni_MATRIX_2025.pdf

accesso aperto

Note: DOI: 10.5220/0013629300003979
Tipologia: Versione editoriale (versione pubblicata con il layout dell'editore)
Licenza: Creative commons
Dimensione 296.95 kB
Formato Adobe PDF
296.95 kB Adobe PDF

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11573/1752441
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 1
  • ???jsp.display-item.citation.isi??? ND
social impact