DocumentCode :
565397
Title :
Conceptual framework for cyber defense information sharing within trust relationships
Author :
Vázquez, Diego Fernández ; Acosta, Oscar Pastor ; Brown, Sarah ; Reid, Emily ; Spirito, Christopher
Author_Institution :
Defence & Security Div., ISDEFE, Madrid, Spain
fYear :
2012
fDate :
5-8 June 2012
Firstpage :
1
Lastpage :
17
Abstract :
Information and Communication Technologies are increasingly intertwined across the economies and societies of developed countries. Protecting these technologies from cyberthreats requires collaborative relationships for exchanging cyber defense data and an ability to establish trusted relationships. The fact that Communication and Information Systems (CIS) security1 is an international issue increases the complexity of these relationships. Cyber defense collaboration presents specific challenges since most entities would like to share cyber-related data but lack a successful model to do so. We will explore four aspects of cyber defense collaboration to identify approaches for improving cyber defense information sharing. First, incentives and barriers for information sharing, which includes the type of information that may be of interest to share and the motivations that cause social networks to be used or stagnate. Second, collaborative risk management and information value perception. This includes risk management approaches that have built-in mechanisms for sharing and receiving information, increasing transparency, and improving entity peering relationships. Third, we explore procedural models for improving data exchange, with a focus on inter-governmental collaborative challenges. Fourth, we explore automation of sharing mechanisms for commonly shared cyber defense data (e.g., vulnerabilities, threat actors, black/ white lists). In order to reach a common understanding of terminology in this paper, we leverage the NATO CIS Security Capability Breakdown [19], published in November 2011, which is designed to identify and describe (CIS) security and cyber defense terminology and definitions to facilitate NATO, national, and multi-national discussion, coordination, and capability development.
Keywords :
electronic data interchange; groupware; risk management; security of data; social networking (online); NATO CIS Security Capability Breakdown; collaborative risk management; communication-and-information systems security; conceptual framework; cyber defense collaboration; cyber defense data exchange; cyber defense information sharing; cyberthreats; entity peering relationships; information value perception; information-and-communication technologies; intergovernmental collaborative challenges; social networks; trust relationships; trusted relationships; Automation; Collaboration; Communities; Data models; Information systems; Risk management; Security; cyber defense; framework; information sharing;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Cyber Conflict (CYCON), 2012 4th International Conference on
Conference_Location :
Tallinn
Print_ISBN :
978-1-4673-1270-7
Type :
conf
Filename :
6243990
Link To Document :
بازگشت