Building Collaborative Cybersecurity for Critical Infrastructure Protection: Empirical Evidence of Collective Intelligence Information Sharing Dynamics on ThreatFox

被引:0
|
作者
Jolles, Eric [1 ]
Gillard, Sebastien [2 ,3 ]
David, Dimitri Percia [1 ,4 ]
Strohmeier, Martin [1 ,5 ]
Mermoud, Alain [1 ]
机构
[1] Armasuisse Sci & Technol, Cyber Def Campus, Zurich, Switzerland
[2] Univ Geneva, Inst Informat Sci, Geneva Sch Econ & Management, Geneva, Switzerland
[3] Swiss Fed Inst Technol, Mil Acad, Dept Def Econ, Zurich, Switzerland
[4] Univ Appl Sci HES SO Valais Wallis, Inst Entrepreneurship & Management, Sierre, Switzerland
[5] Univ Oxford, Dept Comp Sci, Oxford, England
关键词
Information Sharing and Analysis Center; Threat Intelligence; Sharing Platform; Security Information Sharing; Collaborative Cybersecurity; Collective Intelligence; Indicator of Compromise; PROSPECT-THEORY; LOSS AVERSION; DECISION; INCENTIVES;
D O I
10.1007/978-3-031-35190-7_10
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
This article describes three collective intelligence dynamics observed on ThreatFox, a free platform operated by abuse.ch that collects and shares indicators of compromise. These three dynamics are empirically analyzed with an exclusive dataset provided by the sharing platform. First, participants' onboarding dynamics are investigated and the importance of building collaborative cybersecurity on an established network of trust is highlighted. Thus, when a new sharing platform is created by abuse.ch, an existing trusted community with 'power users' will migrate swiftly to it, in order to enact the first sparks of collective intelligence dynamics. Second, the platform publication dynamics are analyzed and two different superlinear growths are observed. Third, the rewarding dynamics of a credit system is described - a promising incentive mechanism that could improve cooperation and information sharing in open-source intelligence communities through the gamification of the sharing activity. Overall, our study highlights future avenues of research to study the institutional rules enacting collective intelligence dynamics in cybersecurity. Thus, we show how the platform may improve the efficiency of information sharing between critical infrastructures, for example within Information Sharing and Analysis Centers using ThreatFox. Finally, a broad agenda for future empirical research in the field of cybersecurity information sharing is presented - an important activity to reduce information asymmetry between attackers and defenders.
引用
收藏
页码:140 / 157
页数:18
相关论文
共 8 条
  • [1] On building cybersecurity expertise in critical infrastructure protection
    Mishra, Sumita
    Raj, Rajendra K.
    Romanowski, Carol J.
    Schneider, Jennifer
    Critelli, Anthony
    2015 IEEE INTERNATIONAL SYMPOSIUM ON TECHNOLOGIES FOR HOMELAND SECURITY (HST), 2015,
  • [2] Technical Framework Research on Critical Information Infrastructure Cybersecurity Classified Protection
    Ren Weihong
    Yuan Jing
    Jiang Lei
    Zhao Tai
    Proceedings of the 2016 4th International Conference on Machinery, Materials and Information Technology Applications, 2016, 71 : 1177 - 1181
  • [3] Freedom of information implications of information sharing networks for critical infrastructure protection
    Lane, Bill
    Corones, Stephen
    Hedge, Susan
    Clapperton, Dale
    AUSTRALIAN JOURNAL OF ADMINISTRATIVE LAW, 2008, 15 (04):
  • [4] Information Sharing and Trust Between Sharing Parties: Sharing Sensitive Information With Regards to Critical Information Infrastructure Protection
    Mohideen, Feroze
    Ellefsen, Ian
    PROCEEDINGS OF THE 10TH INTERNATIONAL CONFERENCE ON CYBER WARFARE AND SECURITY (ICCWS-2015), 2015, : 197 - 206
  • [5] Managing trust in critical infrastructure protection information sharing systems
    Sabo, JT
    ISSE 2004 - SECURING ELECTRONIC BUSINESS PROCESSES, 2004, : 271 - 280
  • [6] Governance Models Preferences for Security Information Sharing: An Institutional Economics Perspective for Critical Infrastructure Protection
    Mermoud, Alain
    Keupp, Marcus Matthias
    David, Dimitri Percia
    CRITICAL INFORMATION INFRASTRUCTURES SECURITY (CRITIS 2018), 2019, 11260 : 179 - 190
  • [7] Legal Issues Related to Cyber Threat Information Sharing Among Private Entities for Critical Infrastructure Protection
    Nweke, Livinus Obiora
    Wolthusen, Stephen
    2020 12TH INTERNATIONAL CONFERENCE ON CYBER CONFLICT (CYCON): 20/20 VISION - THE NEXT DECADE, 2020, : 63 - 78
  • [8] Using Incentives to Foster Security Information Sharing and Cooperation: A General Theory and Application to Critical Infrastructure Protection
    Mermoud, Alain
    Keupp, Marcus Matthias
    Ghernaouti, Solange
    David, Dimitri Percia
    CRITICAL INFORMATION INFRASTRUCTURES SECURITY (CRITIS 2016), 2018, 10242 : 150 - 162