DEALER: decentralized incentives for threat intelligence reporting and exchange

被引:10
|
作者
Menges, Florian [1 ]
Putz, Benedikt [1 ]
Pernul, Gunther [1 ]
机构
[1] Univ Regensburg, Univ Str 31, D-93053 Regensburg, Germany
关键词
Threat intelligence sharing; Blockchain; Smart contract;
D O I
10.1007/s10207-020-00528-1
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The exchange of threat intelligence information can make a significant contribution to improving IT security in companies and has become increasingly important in recent years. However, such an exchange also entails costs and risks, preventing many companies from participating. In addition, since legal reporting requirements were introduced in various countries, certain requirements must be taken into account in the exchange process. However, existing exchange platforms neither offer incentives to participate in the exchange process, nor fulfill requirements resulting from reporting obligations. With this work, we present a decentralized platform for the exchange of threat intelligence information. The platform supports the fulfillment of legal reporting obligations for security incidents and provides additional incentives for information exchange between the parties involved. We evaluate the platform by implementing it based on the EOS blockchain and IPFS distributed hash table. The prototype and cost measurements demonstrate the feasibility and cost-efficiency of our concept.
引用
收藏
页码:741 / 761
页数:21
相关论文
共 50 条