首页> 外文会议>Computer safety, reliability, and security >Public Disclosure of Cyber Threat Information: Risks and Benefits (of an Invited Paper) Francesco
【24h】

Public Disclosure of Cyber Threat Information: Risks and Benefits (of an Invited Paper) Francesco

机译:网络威胁信息的公开披露:(邀请论文的)风险和收益Francesco

获取原文
获取原文并翻译 | 示例

摘要

A growing number of actors perpetrate cyber attacks to various targets, be them public entities, ISPs, enterprises or citizens. Supported by governments or aiming at criminal activities, attackers dispose of channels for sharing and obtaining undisclosed vulnerabilities, attack toolkits and information. On the other hand, attack targets need to react quickly and effectively but they risk to be alone if they do not join forces with others. However timely reactions depend on the quality and timeliness of interactions among peers (e.g. CERTs, public security bodies, ISPs, service providers). There is a need for automated cyber information preparation, sharing and consumption, being fulfilled by initiatives like CybOX [4], STIX [2], Taxii [5] and MISP [1]. However, concerns exist, related to confidential details withing cyber threat information reports, their usage as well as potential data protection laws violations. These constraints render the actual collaboration quite limited in terms of scope. A number of initiatives are focussing on CTI sharing, tackling the most significant obstacles and aiming at bringing benefits to all stakeholders involved in the process. In the talk, risks and benefits will be presented, together with an overview of existing initiatives active in the field.
机译:越来越多的参与者对公共目标,ISP,企业或公民等各种目标实施网络攻击。攻击者在政府的支持下或针对犯罪活动,处置了共享和获取未公开的漏洞,攻击工具包和信息的渠道。另一方面,攻击目标需要快速有效地做出反应,但是如果他们不与他人合力,他们就有可能独自一人。但是,及时的反应取决于对等方(例如,CERT,公共安全机构,ISP,服务提供商)之间交互的质量和及时性。需要通过CybOX [4],STIX [2],Taxii [5]和MISP [1]等计划来实现自动化的网络信息准备,共享和使用。但是,存在与网络威胁信息报告一起使用的机密详细信息,其使用情况以及潜在的违反数据保护法相关的担忧。这些限制使实际的协作在范围方面受到很大限制。许多举措都集中在CTI共享上,解决最大的障碍,并旨在使参与此过程的所有利益相关者受益。在演讲中,将介绍风险和收益,并概述在该领域的活动。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号