DEALER: decentralized incentives for threat intelligence reporting and exchange

被引:10
|
作者
Menges, Florian [1 ]
Putz, Benedikt [1 ]
Pernul, Gunther [1 ]
机构
[1] Univ Regensburg, Univ Str 31, D-93053 Regensburg, Germany
关键词
Threat intelligence sharing; Blockchain; Smart contract;
D O I
10.1007/s10207-020-00528-1
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The exchange of threat intelligence information can make a significant contribution to improving IT security in companies and has become increasingly important in recent years. However, such an exchange also entails costs and risks, preventing many companies from participating. In addition, since legal reporting requirements were introduced in various countries, certain requirements must be taken into account in the exchange process. However, existing exchange platforms neither offer incentives to participate in the exchange process, nor fulfill requirements resulting from reporting obligations. With this work, we present a decentralized platform for the exchange of threat intelligence information. The platform supports the fulfillment of legal reporting obligations for security incidents and provides additional incentives for information exchange between the parties involved. We evaluate the platform by implementing it based on the EOS blockchain and IPFS distributed hash table. The prototype and cost measurements demonstrate the feasibility and cost-efficiency of our concept.
引用
收藏
页码:741 / 761
页数:21
相关论文
共 50 条
  • [41] Incentives of a monopolist for innovation under regulatory threat
    Ismail Saglam
    Economics of Governance, 2023, 24 : 41 - 66
  • [42] Balancing Organizational Incentives to Counter Insider Threat
    Moore, Andrew P.
    Cassidy, Tracy M.
    Theis, Michael C.
    Bauer, Daniel
    Rousseau, Denise M.
    Moore, Susan B.
    2018 IEEE SYMPOSIUM ON SECURITY AND PRIVACY WORKSHOPS (SPW 2018), 2018, : 237 - 246
  • [43] Emergency transshipment in decentralized dealer networks: When to send and accept transshipment requests
    Zhao, Hui
    Deshpande, Vinayak
    Ryan, Jennifer K.
    NAVAL RESEARCH LOGISTICS, 2006, 53 (06) : 547 - 567
  • [44] The 'Threat to Proust':: An exchange
    Compagnon, A
    Tadié, JY
    Shattuck, R
    NEW YORK REVIEW OF BOOKS, 1999, 46 (08) : 53 - 53
  • [45] Management reporting incentives and classification credibility: The effects of reporting discretion and reputation
    Hodge, Frank
    Hopkins, Patrick E.
    Pratt, Jamie
    ACCOUNTING ORGANIZATIONS AND SOCIETY, 2006, 31 (07) : 623 - 634
  • [46] IFRS adoption, reporting incentives and financial reporting quality in private firms
    Bassemir, Moritz
    Novotny-Farkas, Zoltan
    JOURNAL OF BUSINESS FINANCE & ACCOUNTING, 2018, 45 (7-8) : 759 - 796
  • [47] TRIDEnT: Towards a Decentralized Threat Indicator Marketplace
    Alexopoulos, Nikolaos
    Vasilomanolakis, Emmanouil
    Le Roux, Stephane
    Rowe, Steven
    Muehlhaeuser, Max
    PROCEEDINGS OF THE 35TH ANNUAL ACM SYMPOSIUM ON APPLIED COMPUTING (SAC'20), 2020, : 332 - 341
  • [48] THE SUPPOSED THREAT OF DECLINING INTELLIGENCE
    Penrose, Lionel S.
    AMERICAN JOURNAL OF MENTAL DEFICIENCY, 1948, 53 (01): : 114 - 118
  • [49] Unifying Cyber Threat Intelligence
    Menges, Florian
    Sperl, Christine
    Pernul, Guenther
    TRUST, PRIVACY AND SECURITY IN DIGITAL BUSINESS, TRUSTBUS 2019, 2019, 11711 : 161 - 175
  • [50] Intelligence Analyses and the Insider Threat
    Santos, Eugene, Jr.
    Hien Nguyen
    Yu, Fei
    Kim, Keum Joo
    Li, Deqing
    Wilkinson, John T.
    Olson, Adam
    Russell, Jacob
    Clark, Brittany
    IEEE TRANSACTIONS ON SYSTEMS MAN AND CYBERNETICS PART A-SYSTEMS AND HUMANS, 2012, 42 (02): : 331 - 347