Sharing is Caring: Collaborative Analysis and Real-time Enquiry for Security Analytics

被引:2
作者
Webster, George D. [1 ]
Harris, Ryan L. [2 ]
Hanif, Zachary D. [3 ]
Hembree, Bruce A. [4 ]
Grossklags, Jens [1 ]
Eckert, Claudia [1 ]
机构
[1] Tech Univ Munich, Munich, Germany
[2] Zions Bancorp, Salt Lake City, UT USA
[3] Univ Maryland, Baltimore, MD 21201 USA
[4] Palo Alto Networks, Santa Clara, CA USA
来源
IEEE 2018 INTERNATIONAL CONGRESS ON CYBERMATICS / 2018 IEEE CONFERENCES ON INTERNET OF THINGS, GREEN COMPUTING AND COMMUNICATIONS, CYBER, PHYSICAL AND SOCIAL COMPUTING, SMART DATA, BLOCKCHAIN, COMPUTER AND INFORMATION TECHNOLOGY | 2018年
关键词
Threat Intelligence; Information Sharing; Malware; Computer Security; ECONOMICS;
D O I
10.1109/Cybermatics_2018.2018.00240
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
For decades it has been acknowledged that sharing security information and collaboration between security practitioners are a necessity. Yet, effective sharing and collaboration are rare. A gamut of legislative acts, executive orders, academic works, and private sector initiatives have discussed aspects of the problem and aimed to be the catalyst needed to fix the situation. But almost 30 years since these efforts started, the state of sharing and collaboration is still technically complicated, slow, untrusted, and impeded by bureaucratic woes. This work identifies the challenges of sharing security artifacts and uses real-world examples to illustrate our findings. Based on this knowledge, we propose a new model for sharing and collaboration, CARE. The CARE architecture eases many of the privacy, secrecy, lineage, and structure issues that plague current sharing communities and platforms. We then build upon this foundation to introduce a marketplace based on smart contracts with transactional privacy over a distributed blockchain. Therefore, CARE incentivizes sharing, combats free riding, and provides an immutable ledger for the attribution of events. This paradigm shift, overcomes the challenges of sharing while providing new opportunities for business models, insurance risk assessments, and government backed incentivisation.
引用
收藏
页码:1402 / 1409
页数:8
相关论文
共 50 条
  • [1] Ackoff R.L., 1989, J. Appl. Syst. Anal, V16, P39
  • [2] [Anonymous], 2003, Journal of Accounting and Public Policy, DOI [10.1016/j.jaccpubpol.2003.09.001, DOI 10.1016/J.JACCPUBPOL.2003.09.001]
  • [3] [Anonymous], 2018, P 22 INT C FIN CRYPT
  • [4] Bergin Tom, 2016, REUTERS
  • [5] Bianco D., 2013, Enterprise Detection & Response
  • [6] Bitcoin: Economics, Technology, and Governance
    Boehme, Rainer
    Christin, Nicolas
    Edelman, Benjamin
    Moore, Tyler
    [J]. JOURNAL OF ECONOMIC PERSPECTIVES, 2015, 29 (02) : 213 - 238
  • [7] Boyd A., 2015, FEDERAL TIMES OCT
  • [8] BUTERIN V, 2017, Notes on Blockchain Governance
  • [9] CERT-Coordination Center, 2016, CSIRT FREQ ASK QUEST, P1
  • [10] Cichonski Paul., 2012, NIST SPECIAL PUBLICA