{"id":"1f5f62f0-f74d-49b9-b3d3-9726fbad81ed","arxiv_id":"2412.19086","paper_version":1,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":5.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":0,"one_line_summary":"IoC publication for six critical CVEs often follows a slow-sudden-slow temporal pattern that the authors liken to an epidemic curve.","lead":"This paper tracks when security indicators (compromised IP addresses and domains) for six serious software vulnerabilities appear in commercial and open threat feeds. It finds a common three-phase pattern: slow start after disclosure, sudden burst, long slow tail, and suggests defenders keep updating indicators long after a CVE is published.","discovery_kind":"extension","skeptic_critique":{"model":"deepseek-v4-flash","headline":"The claimed recurrent epidemic-like publication pattern is contradicted by the paper's own figures: three CVEs publish 68-79% of IoCs in the first batch after a 2-12 day delay, and two others show no post-initial surge.","rationale":"The paper is an honest preliminary descriptive study, and the authors explicitly ask for more CVE examples, which deserves credit. However, the Abstract and Section III-A make a strong positive claim about a 'recurring pattern akin to an epidemic model.' That claim is not supported by the six plotted curves: the reported first-batch fractions and delays show that the evidence is either an immediate large batch after a short delay or a steady trickle, with only MOVEit resembling the full slow-fast-slow shape. This is a direct correctness issue, not a matter of differing from external consensus, and it can be settled from the paper's own reported numbers, so no new data are needed. The reader's weakest assumption about completeness and attribution remains important for generalizing the result, but the pattern assertion would already fail on the reported examples if those examples are taken at face value. Because the required check is feasible from the manuscript itself, the conditional verdict is appropriate: the paper should be accepted only if the authors either provide quantitative evidence for distinct phases or substantially soften the claim to 'IoC publication often occurs in bursts after a delay.' This does not move the overall verdict, but it sharpens the condition under which the paper should be accepted.","tokens_in":7361,"tokens_out":9115,"duration_ms":90052,"concrete_test":"From the text and Figures 1-6, tabulate for each CVE (i) days from CVE disclosure to first IoC publication and (ii) fraction of the final IoC count published in the first publication event. If at least three of six CVEs have first-event fraction >=0.68 with delay <=12 days, the 'sparse initial phase' is not recurrent; if the largest rate increase in most curves occurs at first publication, there is no distinct surge phase. Then fit a two-phase initial-bulk-plus-exponential-decay model and an SIR-like logistic to the cumulative coverage curves; the epidemic claim requires the logistic to fit substantially better, not merely to be drawable.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The central claim in the Abstract and Section III-A is that IoC publication follows a sparse-initial/surge/slow-tail epidemic shape. The paper's own data do not establish this as a recurring pattern. CVE-2023-35078 had 78% of 23 IoCs at first publication, 12 days after the CVE; CVE-2023-37470 had 79% of 63 IoCs two days after the CVE; CVE-2023-21409 had 68% of 16 IoCs three days after the CVE. These three have essentially no low-rate initial phase. Among the other three, CVE-2023-34362 shows a 30-day empty phase followed by 44% then 98%, which is one plausible epidemic-like instance, but CVE-2023-39143 had a 39% first batch followed by a steady trickle with no surge, and CVE-2023-2868 had a 38% first batch followed by a slow period and then a higher rate, which is not the described slow-fast-slow progression. The conclusion is a post-hoc three-phase narrative imposed on step-function coverage curves without a fitted model or a formal definition of the phases. This is an internal-consistency problem: even granting complete and correctly attributed IoC sets, the six exhibits contradict the Abstract's strongest claim. The reader's data-completeness concern is legitimate, but it is secondary to this direct contradiction.","agreement_with_reader":"partial"},"referee_report":{"model":"deepseek-v4-flash","summary":"This paper investigates the temporal publication of indicators of compromise (IoCs) for six critical CVEs using data from 16 threat intelligence providers whose names are withheld. For each CVE, the authors plot cumulative IoC coverage over days since disclosure and describe the resulting curves. The central claim is that IoC publication often follows an epidemic-like three-phase pattern: a sparse initial period after CVE disclosure, a sudden surge, and then a slower final phase. The paper concludes that defenders should continuously update IoC sets and suggests future work with more CVE examples.","tokens_in":7656,"tokens_out":6484,"duration_ms":61584,"significance":"If the claimed recurrent epidemic-like pattern were established, the practical contribution would be real: defenders would know that early IoC snapshots systematically understate eventual coverage and should expect late indicators. The paper has useful features: it uses recent high-severity CVEs, aggregates multiple commercial and open feeds, presents simple coverage curves that are easy to interpret, and does not fit the SIR model to the data, so the analogy is not circular. The main weakness is that the presented data do not actually support the pattern as a recurrent generalization: three of six cases show an initial majority of IoCs, and the analysis is purely visual, with no formal phase definitions, no statistical comparison, no baseline, and no data release.","major_comments":[{"comment":"The central claim that IoC publication follows a sparse-initial/surge/slow-tail epidemic pattern is contradicted by three of the six presented cases. For CVE-2023-35078 (Fig. 2), 78% of 23 IoCs were present at first publication; for CVE-2023-37470 (Fig. 3), 79% of 63; for CVE-2023-21409 (Fig. 4), 68% of 16. These cases have no low-rate initial phase, and two of the remaining three cases (CVE-2023-2868, Fig. 5, and CVE-2023-39143, Fig. 6) do not show the described slow-fast-slow progression. Only CVE-2023-34362 (Fig. 1) clearly matches the narrative. The abstract's 'recurring pattern' and the Section III-A generalization therefore overstate what the data show; at most 'some cases' or 'one clear case' is supported.","section":"Abstract; Section III-A"},{"comment":"The three phases are never defined quantitatively. The text labels a first batch of 7 of 18 IoCs (39%) for CVE-2023-39143 as a 'relatively small initial spike,' while calling 44% for CVE-2023-34362 a low-rate initial phase, but no threshold or rate criterion separates 'sparse,' 'surge,' and 'slow tail.' Without such definitions, the epidemic-like reading is a post-hoc narrative imposed on step-function coverage curves, and the claimed recurrence cannot be independently tested.","section":"Section III-A"},{"comment":"The completeness and attribution of the IoC sets is load-bearing but unverifiable. The coverage denominator is 'all known IoCs related to the respective CVE' from 16 providers whose names cannot be disclosed, and the analysis stops when coverage reaches 100% for those known IoCs. If any provider misses IoCs, misattributes indicators to a CVE, or the observation window is truncated, the phase boundaries and spike sizes change. No data release or per-day aggregate counts are provided, so the central empirical result cannot be reproduced or independently checked.","section":"Section III; Figures 1-6"},{"comment":"No statistical comparison or control or baseline is provided. The paper compares six observed curves to an epidemic shape by visual inspection only; it does not test whether a random or constant publication process could produce similar coverage curves, nor does it report confidence intervals or any measure of fit. Given n=6 and the authors' own acknowledgement in Section IV that 'more CVE examples should be analyzed,' the conclusion that this is a recurring temporal dynamic is under-supported.","section":"Section IV; Section III-A"}],"minor_comments":[{"comment":"The figure caption says 'CVE-2022-35078' but the text and the CVE identifier used throughout describe CVE-2023-35078; the caption should be corrected.","section":"Figure 2"},{"comment":"There are inconsistencies between text and figure captions: the CVE-2023-35078 text says 23 IoCs were published 'over a period of 38 days' while Figure 2 says 'over 49 successive days,' and the CVE-2023-21409 text says 'over 55 days' while Figure 4 says 'over 25 successive days'; these numbers should be reconciled.","section":"Section III-A; Figure captions"},{"comment":"The first paragraph contains a formatting artifact in 'CVE-2023-391431) 1'; the CVE is otherwise given as CVE-2023-39143, so the stray digit and footnote marker should be cleaned up.","section":"Section III-A"},{"comment":"CVE-2023-37470 is described as having experienced 'an large IoC coverage increase' (should be 'a large'), and the prose could be polished for grammatical consistency; in addition, Reference [7] has a truncated URL and Reference [5] has line breaks that should be fixed.","section":"Section III-A; References"}],"recommendation":"major_revision","confidential_remarks":"I debated between major revision and reject. The paper's strongest abstract-level claim is directly contradicted by three of its own figures, and the lack of any quantitative phase definition or data release makes the empirical contribution difficult to verify. However, the underlying dataset is relevant and the authors could substantially rework the paper into an honest, preliminary observational study of heterogeneous IoC publication dynamics, with the epidemic-like pattern presented as one case among several rather than as a recurring law. If the authors do not make that reframing and address the internal inconsistencies, the paper should not be accepted."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"The paper's real contribution is a modest empirical one: for six critical CVEs, it plots the rate at which IoCs appear across 16 aggregated CTI feeds, showing that indicators keep trickling out for weeks after disclosure and that an early feed snapshot will understate the full set. That is a useful operational observation, and the coverage-curve presentation makes it easy to see. The authors are also appropriately tentative in the body, using phrases like 'in several cases' and 'preliminary findings.'\n\nThe soft spot is the central claim, which the data do not support. The abstract and Section III-A promise a recurring epidemic-like pattern: sparse initial publication, sudden surge, then a slow tail. Only CVE-2023-34362 (MOVEit) actually fits that shape, with a 30-day quiet period before a 44% first batch and then a jump to 98%. The other five do not. Three examples (CVE-2023-35078, CVE-2023-37470, CVE-2023-21409) publish 68-79% of IoCs in the very first batch, so there is no sparse initial phase at all. CVE-2023-39143 has a small first batch and then a steady trickle, with no surge, while CVE-2023-2868 has a moderate first batch followed by a slow period and then a faster rate. The 'recurring pattern' is an artifact of narrating six different curves through the same three-phase story.\n\nThere is also an independent verification problem. The denominators are 'all known IoCs,' assembled from 16 providers whose names cannot be disclosed, so the phase boundaries and spike sizes are not reproducible from the information given. No statistical comparison, formal phase definition, or baseline is offered. These are not fatal to the descriptive core, but they are fatal to the broad generalization.\n\nWho is this for? Practitioners who set feed-refresh policies and want a rough sense of how long IoCs keep arriving. It is a descriptive note, not a breakthrough, and it should be published only after the claims are scaled back to match the exhibits. The right revision would report the six curves individually, drop the forced SIR analogy, release as much data as contracts allow, and replace 'recurring pattern' with 'one observed instance among several.'\n\nA serious referee could fix this in a few rounds. The empirical question is real and underexplored, and the paper's own figures are enough to demonstrate the gap between claim and evidence. I would send it to review, but the decision letter should make clear that the abstract and conclusions need substantial rework.","headline":"Interesting descriptive data undercut by an overgeneralized epidemic claim: only one of six CVEs actually shows the slow-fast-slow pattern described in the abstract.","tokens_in":8159,"tokens_out":2091,"would_cite":false,"duration_ms":24130,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"deepseek-v4-flash","headline":"IoCs for a disclosed CVE arrive in an epidemic-like sequence: slow, spike, slow.","keywords":["Indicators of Compromise","Cyber Threat Intelligence","CVE","IoC publication rate","threat intelligence feeds","epidemic model","SIR model","IoC coverage"],"falsifier":"Take a new critical CVE with an independent ground-truth list of indicators compiled from vendor advisories, private sandbox detections, and takedown telemetry; if the cumulative publication curve of the 16-feed union does not show a slow start, a sharp surge, and a prolonged tail for most such CVEs, or if a single early snapshot already contains nearly all indicators that ever appear, the claimed epidemic-like pattern would be contradicted.","tokens_in":1477,"feed_emoji":"📈","tokens_out":2082,"duration_ms":177061,"temperature":0.7,"pith_summary":"The paper tries to establish that the publication of Indicators of Compromise (IoCs)—the IP addresses, domains, and hashes defenders use to block attacks—is not a one-time event after a vulnerability is disclosed. Tracking six critical CVEs across 16 threat-intelligence providers, it finds a recurring pattern: a quiet period after the CVE announcement, a sudden surge of IoC publications, then a long tail of slower additions until coverage is complete. If this pattern holds, a single early snapshot of a threat feed systematically understates the indicators that will eventually become known, so defenders need to keep pulling updates for weeks. The paper frames the pattern as analogous to the susceptible-infected-recovered (SIR) epidemic model.","feed_headline":"New cyber threat indicators arrive in epidemic-like bursts","feed_subtitle":"Study of six critical CVEs finds IoC publication runs slow, spikes, then trails off for weeks.","key_machinery":"The central object is the IoC coverage curve: for a given CVE, the percentage of all known IoCs associated with that CVE that have been published by each day since the CVE was disclosed. The publication rate is the number of IoCs published per unit time, and the paper reads the shape of the coverage curve against the Susceptible-Infected-Removed (SIR) epidemic model, where the slow initial rise, sudden surge, and flattening tail correspond to susceptible, infectious, and recovered stages. The curve does the argument's work: it turns scattered feed timestamps into a single shape that can be compared across vulnerabilities.","core_discovery":"For each of the six CVEs studied, when the observation window starts at the CVE disclosure date ('Day 0') and runs until all known IoCs have appeared, the cumulative IoC coverage graph has three phases: sparse publication, a sharp spike, and a protracted slower tail. In examples such as MOVEit (CVE-2023-34362), the first batch was 44% of the eventual 149 IoCs, then coverage jumped to 98% within five days, and the last IoCs took another 24 days; in other cases like PaperCut the initial batch was small and the tail was steady. The paper concludes that IoC publication rates fluctuate over time and that the timing resembles the three stages of the SIR epidemic model, with the slow start matching limited exploit availability and visibility, the spike matching automated exploitation and campaigns, and the final slow phase matching maturing defenses and mitigation.","pith_inferences":["If the pattern generalizes beyond six critical CVEs, feed providers could advertise expected coverage curves per CVE, letting defenders schedule re-pulls based on time since disclosure.","The SIR analogy suggests a quantitative model: fit a three-phase curve to early IoC timestamps and predict when a CVE's indicator set will reach saturation; the paper does not fit such a model, but its data would support one.","The paper's reliance on the union of 16 undisclosed feeds means its phase boundaries are tied to that particular aggregation; a testable extension would be to see whether the same slow-spike-slow shape appears within individual providers' feeds, which would determine whether the pattern is a property of the threat or of the aggregation.","IoC expiration and churn, which the paper lists as future work, could change the tail shape: if old indicators stop being observed, the effective coverage curve may peak and decline rather than simply saturating at 100%."],"forward_implications":["Defenders who take a single snapshot of an IoC feed soon after a CVE is published will systematically underestimate the indicators that will become known; coverage can jump from under half to near-complete within days.","Because the tail phase can last weeks, blocks and detection rules should be refreshed on a schedule that extends well past the CVE disclosure date, not just at disclosure.","The three-phase shape gives operators a rough sense of where in the vulnerability's lifecycle they are: sparse early indicators suggest exploitation and discovery are still ramping up.","Differences in initial batch size across CVEs mean no single ingestion policy fits all vulnerabilities; some show a large early batch, while others start small and grow steadily."],"supporting_citations":[{"why":"Supplies the finding that CTI provider overlap averages at most 4.5%, justifying the paper's use of 16 providers to maximize IoC coverage.","marker":"[1]"},{"why":"Defines volume and timeliness as the quality metrics the paper builds on for measuring IoC publication.","marker":"[2]"},{"why":"Provides the definition of Indicators of Compromise and their role in attack and defense, grounding the object of study.","marker":"[3]"},{"why":"Provides the SIR/SEIQV epidemic model used to interpret the slow-spike-slow IoC publication pattern.","marker":"[6]"},{"why":"Establishes the timeliness framing for threat intelligence that motivates studying when IoCs are published.","marker":"[8]"}],"fun_headline_variants":["CVE threat data spikes like an epidemic, then fades","IoC publication mimics epidemic curve for major CVEs","Cyber threat intel arrives in three waves, not a steady stream","Threat indicator releases surge then slow, study finds","Epidemic-like bursts govern new cyber threat data"],"cache_read_input_tokens":10240,"weakest_assumption_plain":"The analysis assumes the union of IoCs from the 16 (undisclosed) providers is complete and correctly attributed to each CVE; if feeds miss indicators, misattribute them, or the observation window ends before all indicators appear, the phase boundaries and the epidemic-like shape could be artifacts of the dataset rather than properties of real-world IoC publication.","fun_headline_variants_meta":{"raw":{"variants":["CVE threat data spikes like an epidemic, then fades","IoC publication mimics epidemic curve for major CVEs","Cyber threat intel arrives in three waves, not a steady stream","Threat indicator releases surge then slow, study finds","Epidemic-like bursts govern new cyber threat data"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000216,"raw_usage":{"total_tokens":1443,"prompt_tokens":967,"completion_tokens":476,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":583,"completion_tokens_details":{"reasoning_tokens":395}},"tokens_in":583,"tokens_out":476,"duration_ms":5437,"temperature":1.0,"reasoning_tokens":395,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-11T00:56:51.464764+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Take a new critical CVE with an independent ground-truth list of indicators compiled from vendor advisories, private sandbox detections, and takedown telemetry; if the cumulative publication curve of the 16-feed union does not show a slow start, a sharp surge, and a prolonged tail for most such CVEs, or if a single early snapshot already contains nearly all indicators that ever appear, the claimed epidemic-like pattern would be contradicted.","supporting_citations":[{"cited_title":"Reading the tea leaves: A comparative analysis of threat in telligence,","cited_arxiv_id":null,"evidence_quote":"Supplies the finding that CTI provider overlap averages at most 4.5%, justifying the paper's use of 16 providers to maximize IoC coverage."},{"cited_title":"Quality evaluation of cyber threat intelligence feeds,","cited_arxiv_id":null,"evidence_quote":"Defines volume and timeliness as the quality metrics the paper builds on for measuring IoC publication."},{"cited_title":"Indic ators of compromise (IoCs) and their role in attack defence,","cited_arxiv_id":null,"evidence_quote":"Provides the definition of Indicators of Compromise and their role in attack and defense, grounding the object of study."},{"cited_title":"Stability a nalysis of a SEIQV epidemic model for rapid spreading worms,","cited_arxiv_id":null,"evidence_quote":"Provides the SIR/SEIQV epidemic model used to interpret the slow-spike-slow IoC publication pattern."},{"cited_title":"A different cup of TI? the added value of commercial t hreat intelligence,","cited_arxiv_id":null,"evidence_quote":"Establishes the timeliness framing for threat intelligence that motivates studying when IoCs are published."}],"review_version":1}