信任关系中的网络防御信息共享概念框架,2011年11月

VIP文档

ID:69475

大小:0.51 MB

页数:17页

时间:2024-02-13

金币:10

上传者:战必胜
429
Conceptual Framework
for Cyber Defense
Information Sharing
within Trust Relationships
Abstract: Information and Communication Technologies are increasingly intertwined across
the economies and societies of developed countries. Protecting these technologies from cyber-
threats requires collaborative relationships for exchanging cyber defense data and an ability to
establish trusted relationships. The fact that Communication and Information Systems (CIS)
security
1
is an international issue increases the complexity of these relationships. Cyber defense
collaboration presents speci c challenges since most entities would like to share cyber-related
data but lack a successful model to do so.
We will explore four aspects of cyber defense collaboration to identify approaches for improving
cyber defense information sharing. First, incentives and barriers for information sharing, which
includes the type of information that may be of interest to share and the motivations that cause
social networks to be used or stagnate. Second, collaborative risk management and information
value perception. This includes risk management approaches that have built-in mechanisms
for sharing and receiving information, increasing transparency, and improving entity peering
relationships. Third, we explore procedural models for improving data exchange, with a focus
on inter-governmental collaborative challenges. Fourth, we explore automation of sharing
mechanisms for commonly shared cyber defense data (e.g., vulnerabilities, threat actors, black/
white lists).
In order to reach a common understanding of terminology in this paper, we leverage the NATO
CIS Security Capability Breakdown
[19], published in November 2011, which is designed to
Diego Fernández Vázquez,
Oscar Pastor Acosta
Defence and Security Division
ISDEFE
Madrid, Spain
{dfvazquez, opastor}@isdefe.es
Christopher Spirito
International Operations
The MITRE Corporation
Bedford, MA 01730
cspirito@mitre.org
Sarah Brown,
Emily Reid
Cyber Security Division
The MITRE Corporation
Bedford, MA 01730
{sbrown, ereid}@mitre.org
2012 4th International Conference on Cyber Con ict
C. Czosseck, R. Ottis, K. Ziolkowski (Eds.)
2012 © NATO CCD COE Publications, Tallinn
Permission to make digital or hard copies of this publication for internal use within
NATO and for personal or educational use when for non-pro t or non-commercial
purposes is granted providing that copies bear this notice and a full citation on the
rst page. Any other reproduction or transmission requires prior written permission
by NATO CCD COE.
1
The ability to adequately protect the con dentiality, integrity, and availability of Communication and
Information Systems (CIS) and the information processed, stored or transmitted.
资源描述:

当前文档最多预览五页,下载文档查看全文

此文档下载收益归作者所有

当前文档最多预览五页,下载文档查看全文
温馨提示:
1. 部分包含数学公式或PPT动画的文件,查看预览时可能会显示错乱或异常,文件下载后无此问题,请放心下载。
2. 本文档由用户上传,版权归属用户,天天文库负责整理代发布。如果您对本文档版权有争议请及时联系客服。
3. 下载前请仔细阅读文档内容,确认文档内容符合您的需求后进行下载,若出现内容与标题不符可向本站投诉处理。
4. 下载文档时可能由于网络波动等原因无法下载或下载错误,付费完成后未能成功下载的用户请联系客服处理。
关闭