<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title>Open Data at CIRCL on CIRCL</title>
		<link>https://www.circl.lu/opendata/</link>
		<description>Recent content in Open Data at CIRCL on CIRCL</description>
		<generator>Hugo</generator>
		<language>en-us</language>
		
		
		
		
			<atom:link href="https://www.circl.lu/opendata/rss.xml" rel="self" type="application/rss+xml" />
			<item>
				<title>CIRCL Images AIL Dataset - Open Data at CIRCL</title>
				<link>https://www.circl.lu/opendata/circl-ail-dataset-01/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www.circl.lu/opendata/circl-ail-dataset-01/</guid>
				<description>&lt;h2 id=&#34;introduction&#34;&gt;Introduction&lt;/h2&gt;&#xA;&lt;p&gt;CERTs such as CIRCL and security teams collect and process content such as images (at large from photos, screenshots of websites or screenshots of sandboxes).&#xA;Datasets become larger - e.g. on average 10000 screenshots of onion domains websites are scrapped each day in &lt;a href=&#34;https://github.com/ail-project/ail-framework&#34;&gt;AIL - Analysis Information Leak framework&lt;/a&gt;, an analysis tool of information leak - and analysts need to classify, search and correlate through all the images.&lt;/p&gt;&#xA;&lt;p&gt;Automatic tools can help them in this task. Less research about image matching and image classification seems to have been conducted  exclusively on websites screenshots. However, a classification of this kind of pictures needs to be addressed.&lt;/p&gt;</description>
			</item>
			<item>
				<title>CIRCL Images Phishing Dataset - Open Data at CIRCL</title>
				<link>https://www.circl.lu/opendata/circl-phishing-dataset-01/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www.circl.lu/opendata/circl-phishing-dataset-01/</guid>
				<description>&lt;h2 id=&#34;introduction&#34;&gt;Introduction&lt;/h2&gt;&#xA;&lt;p&gt;CERTs such as CIRCL and security teams collect and process content such as images (at large from photos, screenshots of websites or screenshots of sandboxes).&#xA;Datasets become larger - e.g. on average 10000 screenshots of onion domains websites are scrapped each day in &lt;a href=&#34;https://github.com/ail-project/ail-framework&#34;&gt;AIL - Analysis Information Leak framework&lt;/a&gt;, an analysis tool of information leak - and analysts need to classify, search and correlate through all the images.&lt;/p&gt;&#xA;&lt;p&gt;Automatic tools can help them in this task. Less research about image matching and image classification seems to have been conducted  exclusively on websites screenshots. However, a classification of this kind of pictures needs to be addressed.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Operational Statistics</title>
				<link>https://www.circl.lu/opendata/statistics/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www.circl.lu/opendata/statistics/</guid>
				<description>&lt;div class=&#34;statistics-page&#34;&gt;&#xA;&#xA;&lt;div class=&#34;top&#34;&gt;&#xA;    &lt;div class=&#34;top-content&#34;&gt;&#xA;        &lt;span class=&#34;sep_holder &#34;&gt;&lt;span class=&#34;sep_line&#34;&gt;&lt;/span&gt;&lt;/span&gt;&#xA;        &lt;div class=&#34;titl&#34;&gt;CIRCL Operational Statistics&lt;/div&gt;&#xA;        &lt;span class=&#34;sep_holder &#34;&gt;&lt;span class=&#34;sep_line&#34;&gt;&lt;/span&gt;&lt;/span&gt;&#xA;    &lt;/div&gt;&#xA;&lt;/div&gt;&#xA;&#xA;&#xA;&lt;div class=&#34;fake-layout-for-css&#34;&gt;&#xA;    &lt;div class=&#34;content&#34;&gt;&#xA;        &lt;article style=&#34;padding-bottom: 0;&#34;&gt;&#xA;            &lt;div class=&#34;.side&#34;&gt;&#xA;                &lt;div class=&#34;details&#34; style=&#34;background-color: rgba(213,222,226,0.7); padding: 20px; max-width: 58.75rem; margin: auto auto;&#34;&gt;&#xA;                    &lt;h3 style=&#34;font-size: 24px; padding-bottom: 16px; color: #3c4042;&#34;&gt;Operational Statistics&lt;/h3&gt;&#xA;                    &lt;ol class=&#34;toc&#34; style=&#34;list-style: none;&#34;&gt;&#xA;                        &lt;li&gt;&lt;a href=&#34;#ticketing-system-statistics&#34;&gt;Ticketing System&lt;/a&gt;&lt;/li&gt;&#xA;                        &lt;li&gt;&lt;a href=&#34;#information-leaks-affecting-luxembourg&#34;&gt;Information Leaks&lt;/a&gt;&lt;/li&gt;&#xA;                        &lt;li&gt;&lt;a href=&#34;#usage-of-misp-offered-as-a-service-by-circl-misppriv-circl-lu&#34;&gt;MISP Usage&lt;/a&gt;&lt;/li&gt;&#xA;                    &lt;/ol&gt;&#xA;                &lt;/div&gt;&#xA;            &lt;/div&gt;&#xA;        &lt;/article&gt;&#xA;    &lt;/div&gt;&#xA;&lt;/div&gt;&#xA;&#xA;&lt;div class=&#34;entry&#34; style=&#34;margin-top: -30px;&#34;&gt;&#xA;&lt;div class=&#34;entry-content&#34;&gt;&#xA;&lt;div class=&#34;highlight statistics-content&#34;&gt;&#xA;&#xA;    &lt;div&gt;&#xA;        &lt;h1 style=&#34;margin-top: 3rem;&#34;&gt;CIRCL Operational Statistics&lt;/h1&gt;&#xA;&#xA;        &lt;div&gt;&#xA;            The operational statistics cover the activities related to the incident response activities of CIRCL especially in regards to the reporting (e.g. incident reports, request for analysis or support during computer security incident) and notifications (e.g. take-down notification, notification about vulnerability) from/to third parties. The statistics exclude automatic structured notifications and information exchange happening via threat intelligence platforms such as the &lt;a href=&#34;../../services/misp-malware-information-sharing-platform/&#34;&gt;CIRCL MISP information sharing platform&lt;/a&gt; or any other automatic exchange setup with partners.&#xA;        &lt;/div&gt;&#xA;&#xA;        &lt;div&gt;&#xA;            In this section some statistics are presented about incidents handled by CIRCL between 2016 and 2026. During this time frame the attackers evolved, forcing CIRCL to adapt its internal procedures. Although the reporting to CIRCL is not mandatory, the reporting behaviour of constituents has changed. On one hand, the reputation of CIRCL increased, thereby increasing the amount of reporting to CIRCL. On the other hand, due to the trainings such as Introduction to incident response, forensic analysis and many others offered by CIRCL, have helped local organisations build up their own incident response capacities thereby reducing the number of reported incidents. This makes comparing the statistics of successive years challenging.  Tickets are no indicators for the overall workload as there are some tickets that are very resource intensive whereas others are quickly solved.  Nevertheless, the workload for the overall triage of the tickets is increasing and showing an increase in diversity when it comes to attacker practices.&#xA;        &lt;/div&gt;&#xA;&#xA;        &lt;span id=&#34;ticketing-system-statistics&#34;&gt;&lt;/span&gt;&#xA;        &lt;h1 id=&#34;ticketing&#34; style=&#34;margin-top: 3rem;&#34;&gt;Ticketing System Statistics&lt;/h1&gt;&#xA;        &lt;div&gt;&#xA;            Tickets can contain one or more incidents and only represent the reporting or notification which was performed by CIRCL analysts.&#xA;        &lt;/div&gt;&#xA;        &lt;div&gt;&#xA;            Small precision regarding the charts:&#xA;            &lt;ul&gt;&#xA;                &lt;li&gt;&lt;b&gt;- Manual Ticket&lt;/b&gt;: Ticket that has to be handled and classified manually by an analyst.&lt;/li&gt;&#xA;                &lt;li&gt;&lt;b&gt;- Automatic Ticket&lt;/b&gt;: Ticket that was created in an automated fashion. Could be report from third parties or self generated report from our constituency. Tickets from not fully trusted sources involve a manual validation by a human CIRCL operator.&lt;/li&gt;&#xA;                &lt;li&gt;&lt;b&gt;- Services offered by CIRCL&lt;/b&gt;: CIRCL offers multiple services such as MISP, PassiveDNS, PassiveSSL, AILFramework and many more to organisations. Tickets for services are usually questions or request for access.&lt;/li&gt;&#xA;            &lt;/ul&gt;&#xA;        &lt;/div&gt;&#xA;&#xA;        &lt;p class=&#34;chart-scroll-help&#34; id=&#34;chart-scroll-help&#34;&gt;&#xA;            On smaller screens, scroll the charts horizontally to view all of their content.&#xA;        &lt;/p&gt;</description>
			</item>
	</channel>
</rss>
