Jump to main navigation Jump to main navigation Jump to main content Jump to footer content

Information Exchange (MISP)

HITS IS offers a modern Cyber Threat Intelligence (CTI) platform based on MISP (Malware Information Sharing Platform) and operated securely in the LRZ's data center. This platform enables participating colleges and universities to collect, analyze and share security-related information and threat data with each other.

MISP is used to provide and share information about threat indicators and events, such as malware installation detection, phishing attacks, or attack techniques. This service supports universities in reacting to cyber threats at an early stage and in taking protective measures. HITS IS ensures that access to MISP is state-of-the-art and offers support for setting up and using the platform.

Scope of Services and Service Specifics

  • MISP Instance Deployment: Access to the MISP platform for threat intelligence sharing and analysis.
  • Data enrichment and correlation: Analyze threat indicators shared in the MISP instance to gain insights into current threat trends and attack patterns.
  • Support and training variants:
    • Provision of materials,
    • Introductory workshop,
    • technical support
    • Connection of internal systems to the MISP instance to use the MISP platform.
  • Intelligence delivery: The platform provides threat intelligence in standardized formats for easy use and integration with internal security systems. This information can be accessed independently – either via web-based access to the platform or by downloading it in standardized formats such as:
    • MISP JSON (Native Format for MISP Data)
    • STIX (Structured Threat Information eXpression)
    • CSV
    • OpenIOC
  • Regular updates and maintenance: Ensuring continuous operation and updating of the platform.

Service Parameters

  • MISP Platform Operating Hours: The service is available around the clock.
  • Data sources and threat indicators: The MISP platform collects data from trusted sources and partner organizations, including CERTs, ISPs, and other higher education institutions.
  • Deployment lead time: Once ordered, access to the MISP platform will be set up within 2 weeks.

 

Requirements

  • Designation of a security contact person to coordinate the use of the MISP platform.
  • Responsibility for their own threat data: Universities should share relevant threat indicators via the platform.
  • Protective measures for confidential data: Higher education institutions must implement locally appropriate procedures for classifying and releasing data on the MISP platform.
  • Responsible use of data: The data stored on the MISP platform is classified according to the Traffic Light Protocol (TLP), which governs the sharing and use of the information. The responsibility for compliance with this classification and the correct use of the data lies with the respective organization administrators (org admins). If there are other users within a university, the security contact person of the respective organization is responsible for educating and raising awareness.

 

User / Customers

This service is made available to the following categories of users.

 

User classNote
(1), (2)only for members of the Digital Network of Bavaria
(3), (4), (5), (6)not available for these customers

 

The service can be requested by CIO, CISO, ISB or data center management of the universities in the digital network via e-mail to informationssicherheit@remove-this.digitalverbund.bayern .