首页> 外文会议>International Conference on Computer Safety, Reliability, and Security >Public Disclosure of Cyber Threat Information: Risks and Benefits (Abstract of an Invited Paper)
【24h】

Public Disclosure of Cyber Threat Information: Risks and Benefits (Abstract of an Invited Paper)

机译:网络威胁信息公开披露:风险和福利(邀请纸的摘要)

获取原文

摘要

A growing number of actors perpetrate cyber attacks to various targets, be them public entities, ISPs, enterprises or citizens. Supported by governments or aiming at criminal activities, attackers dispose of channels for sharing and obtaining undisclosed vulnerabilities, attack toolkits and information. On the other hand, attack targets need to react quickly and effectively but they risk to be alone if they do not join forces with others. However timely reactions depend on the quality and timeliness of interactions among peers (e.g. CERTs, public security bodies, ISPs, service providers). There is a need for automated cyber information preparation, sharing and consumption, being fulfilled by initiatives like CybOX [4], STIX [2], Taxii [5] and MISP [1]. However, concerns exist, related to confidential details withing cyber threat information reports, their usage as well as potential data protection laws violations. These constraints render the actual collaboration quite limited in terms of scope. A number of initiatives are focussing on CTI sharing, tackling the most significant obstacles and aiming at bringing benefits to all stake-holders involved in the process. In the talk, risks and benefits will be presented, together with an overview of existing initiatives active in the field.
机译:越来越多的演员对各种目标犯下网络攻击,成为他们的公共实体,ISP,企业或公民。政府支持或旨在犯罪活动,攻击者处理分享和获取未公开的漏洞,攻击工具包和信息的渠道。另一方面,攻击目标需要快速有效地反应,但如果他们不与他人联系起来,他们就会抵达。然而,及时反应取决于同行之间的互动的质量和及时性(例如证书,公安机构,ISP,服务提供商)。需要自动化网络信息准备,共享和消费,通过Cybox [4],Stix [2],Taxii [5]和Misp [1]等举措来实现。但是,与通过网络威胁信息报告的机密详情,其使用以及潜在的数据保护法违规,有关的问题。这些约束使实际协作在范围范围内非常有限。许多举措侧重于CTI共享,解决最重要的障碍,旨在为所有参与该过程中的所有利益持有人带来利益。在谈话中,将提出风险和福利,并概述现有领域中活跃的现有举措。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号