DocumentCode :
3454499
Title :
Trustworthy incident information sharing in social cyber defense alliances
Author :
Skopik, Florian ; Qin Li
Author_Institution :
Safety & Security Dept., AIT Austrian Inst. of Technol., Vienna, Austria
fYear :
2013
fDate :
7-10 July 2013
Abstract :
The Internet threat landscape is fundamentally changing today. A major shift away from hobby hacking towards well-organized cyber crimes can be observed. The aim of these criminal organizations is the commercial exploitation of vulnerabilities in ICT infrastructures. Since attacks become more and more coordinated, we argue that counter measures must be properly coordinated too. Additionally, networks have grown to a scale and complexity, and have reached a degree of interconnectedness, that their protection can often only be guaranteed and financed as shared efforts. In this paper, we therefore introduce the concept of social cyber defense alliances. These alliances are shaped by social networks which connect information security stakeholders from various domains and facilitate the sharing of incident information. Some primary challenges include: 1) how to encourage participating stakeholders to contribute, and 2) how to ensure the quality and reliability of shared incident information. Here, we discuss an incentive model, which encourages information security stakeholders to share incident information. Furthermore, we highlight an architectural blueprint which is able to support the establishment of our proposed social cyber defense alliances in a real world context, and evaluate its applicability using agent-based simulations.
Keywords :
Internet; information technology; security of data; ICT infrastructures; Internet threat landscape; agent-based simulations; architectural blueprint; commercial exploitation; criminal organizations; hobby hacking; incentive model; information security stakeholders; social cyber defense alliances; social networks; trustworthy incident information sharing; well-organized cyber crimes; Cryptography; Information management; Internet; Investment; Malware; Organizations; cyber alliances; incentive model; information exchange format; security incident sharing architecture;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Computers and Communications (ISCC), 2013 IEEE Symposium on
Conference_Location :
Split
Type :
conf
DOI :
10.1109/ISCC.2013.6754951
Filename :
6754951
Link To Document :
بازگشت