CTI, or in short TI, is a key component of defending against complex and coordinated cyber threats. CTI is shared across organizations to enhance collective cyber defense. However, the effective use of CTI is often hampered by organizational, technical, and contextual challenges, such as low information quality, a lack of actionable relevance, and insufficient integration with operational processes. This dissertation addresses these challenges by examining four interrelated dimensions of CTI exchange. First, it analyzes the structures and functions of sharing communities based on 25 expert interviews to better understand their organizational and socio-technical dynamics. Second, drawing on the same empirical foundation, it investigates current practices for CTI quality assurance and derives recommendations for improving the operational reliability of CTI. Third, it develops and validates a conceptual model for determining the relevance of shared CTI by systematically matching observed attack techniques with an organization’s defensive capabilities using the ATT&CK and D3FEND frameworks. Fourth, this dissertation evaluates the adoption and conformity of security.txt, a structured vulnerability disclosure mechanism that supports cross-organizational coordination within CTI sharing environments and contributes to more effective vulnerability reporting. The findings show that sharing communities vary widely in structure, rely heavily on trust-based collaboration, and function as complex socio-technical systems. In practice, quality assurance of CTI is often informal and relies on expert judgment, with limited use of systematic methods. The proposed relevance model helps identify defense gaps and supports the prioritization of relevant CTI. The large-scale analysis of security.txt reveals substantial adoption across high-profile domains but also reveals implementation inconsistencies that limit its practical utility. Together, these results offer new perspectives on how CTI can be shared and utilized in a high-quality, context-relevant, and operationally actionable form. This dissertation offers conceptual and empirical tools for strengthening collaborative cyber defense.
Thomas Geras (Thu,) studied this question.