Top Banner
Blockchain-based Cybersecurity Informa8on Sharing for Improved Resiliency Dr. Deepak K. Tosh Assistant Professor Department of Computer Science University of Texas at El Paso Email: [email protected]
25

Blockchain-based Cybersecurity Informa8on …credit.pvamu.edu/MCBDA2019/UTEP_Tosh.pdfBlockchain-based Cybersecurity Informa8on Sharing for Improved Resiliency Dr. Deepak K. Tosh Assistant

May 25, 2020

Download

Documents

dariahiddleston
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Blockchain-based Cybersecurity Informa8on …credit.pvamu.edu/MCBDA2019/UTEP_Tosh.pdfBlockchain-based Cybersecurity Informa8on Sharing for Improved Resiliency Dr. Deepak K. Tosh Assistant

Blockchain-based Cybersecurity Informa8on Sharing for Improved Resiliency

Dr.DeepakK.ToshAssistantProfessor

DepartmentofComputerScienceUniversityofTexasatElPaso

Email:[email protected]

Page 2: Blockchain-based Cybersecurity Informa8on …credit.pvamu.edu/MCBDA2019/UTEP_Tosh.pdfBlockchain-based Cybersecurity Informa8on Sharing for Improved Resiliency Dr. Deepak K. Tosh Assistant

Outline

• MoBvaBon• Cyber-ThreatInformaBon(CTI)sharing• CurrentEfforts• Modelinga“Specific”Problem:SharingParBcipaBon• BlockchainforInformaBonSharing• ResearchChallenges• ConcludingRemarks

Page 3: Blockchain-based Cybersecurity Informa8on …credit.pvamu.edu/MCBDA2019/UTEP_Tosh.pdfBlockchain-based Cybersecurity Informa8on Sharing for Improved Resiliency Dr. Deepak K. Tosh Assistant

Growth of Cyber Threats

• AdvancedcyberaOacksarewellorganizedandhardtodetect

•  ExploitsareeasilyacquiredandcanbereusedonmulBpletargets• ReacBvestrategiesareinsufficienttodealwiththethreats

Page 4: Blockchain-based Cybersecurity Informa8on …credit.pvamu.edu/MCBDA2019/UTEP_Tosh.pdfBlockchain-based Cybersecurity Informa8on Sharing for Improved Resiliency Dr. Deepak K. Tosh Assistant

Need of Threat Intelligence

• CyberaOacksmaynotbepreventedbuttheirimpactscanbereducedby•  Improvingcyber-awarenessandunderstandingthreatlandscape•  CollaboraBveeffortfromenterprisesaswellasgovernment•  Imposingsecuritypolicies/laws(e.g.GDPR)

• Cyber-ThreatIntelligence(CTI)canderive•  AcBonableinformaBonfromvariouslowlevelthreatindicators(likeIP,email,maliciousURLs,domainnames,aOackpaOern,geo-locaBoninfo,malwarehash)•  Findingtargetedresources,threatactors,methods/toolsused,aOackcharacterisBcs,IoC,etc.

Page 5: Blockchain-based Cybersecurity Informa8on …credit.pvamu.edu/MCBDA2019/UTEP_Tosh.pdfBlockchain-based Cybersecurity Informa8on Sharing for Improved Resiliency Dr. Deepak K. Tosh Assistant

Handling Cybersecurity Threats

•  Securityinvestmenthelpsin•  Discoveringsystemloopholes,bugs,vulnerabiliBes•  IdenBfymaliciousacBviBes•  DevelopinganB-threatstrategies

Improvesdefenders’abilitytopredicta2ackerbehaviorandcreatemoredynamicdefenses• Demerits:•  Costly•  Timeconsuming

Page 6: Blockchain-based Cybersecurity Informa8on …credit.pvamu.edu/MCBDA2019/UTEP_Tosh.pdfBlockchain-based Cybersecurity Informa8on Sharing for Improved Resiliency Dr. Deepak K. Tosh Assistant

Cybersecurity Informa8on Sharing

• AnecosystemwhereacBonablecyber-threatintelligenceissharedautomaBcallyacrossverBcalsandpublic/privatesectorsinnearreal-Bmetocombatcyberthreatlandscape• Benefits•  AccesstoIndicators,TacBcs,techniques,andprocedures(TTPs),Securityalerts,Threatintelligencereports,ToolconfiguraBons•  EnhanceoperaBonalunderstandingofcyberthreats•  ProacBveDefense•  ReduceCyberRisk•  PrioriBzedMiBgaBonPlan•  CosteffecBvedefensestrategy

Page 7: Blockchain-based Cybersecurity Informa8on …credit.pvamu.edu/MCBDA2019/UTEP_Tosh.pdfBlockchain-based Cybersecurity Informa8on Sharing for Improved Resiliency Dr. Deepak K. Tosh Assistant

Limita8ons of Informa8on Sharing

•  SomethingstopsorganizaBonsfromsharing!!!•  JeopardizethesecuritypostureofthesharingorganizaBon•  Externalimpactssuchasmarketvalue,reputaBon,etc.•  InformaBonfree-riding•  SpuriousinformaBonandprocessingoverheads

Page 8: Blockchain-based Cybersecurity Informa8on …credit.pvamu.edu/MCBDA2019/UTEP_Tosh.pdfBlockchain-based Cybersecurity Informa8on Sharing for Improved Resiliency Dr. Deepak K. Tosh Assistant

How did we get here?

Following9-11FederalInformaBonSharinggrows-failuretoconnectthedots

In2007,PresidentBushcreatesComprehensiveNaEonalCyberIniEaEve(CNCI)-ConnecttheFedCyberCentersinordertoaddresscyberthreatlandscape

In2013,EnhanceSharedSituaEonAwarenessProject(ESSA)createdtoautomatecyberthreatinformaBonsharingbetweenFedCyberCenters.-StandardsharinglanguagesSTIX/TAXII,sharedcapabilityproviders,andcommonsharingagreement(MISA).

In2015,CybersecurityInformaEonSharingAct(CISA)passed.-EstablishestheDHSAutomatedIndicatorSharing(AIS)ProgramforsharingcyberthreatindicatorsanddefensivemeasuresbetweentheFederalGovernmentandNon-FederalEnBBes.

In2016thelegacyofESSAisleveragedbyDHSforconBnuaBonofFederalCyberThreatInformaBonSharingandcoordinaBonthroughtheFederalCybersecurityInteragencyGroup(FCIG).

Page 9: Blockchain-based Cybersecurity Informa8on …credit.pvamu.edu/MCBDA2019/UTEP_Tosh.pdfBlockchain-based Cybersecurity Informa8on Sharing for Improved Resiliency Dr. Deepak K. Tosh Assistant

Cybersecurity Informa8on Sharing Today

• CybersecurityInformaBonsharinghasbeengoingonthroughISACs,ISAOs,eco-systems,opensource,andcommercialofferings•  LimitaBons•  Generallyunstructureddata•  Ad-hocmanualcommunicaBonssuchasemail/IM/IRC/paper•  Fewautomatedtools•  LackofincenBvemodelforvoluntaryparBcipaBon

Page 10: Blockchain-based Cybersecurity Informa8on …credit.pvamu.edu/MCBDA2019/UTEP_Tosh.pdfBlockchain-based Cybersecurity Informa8on Sharing for Improved Resiliency Dr. Deepak K. Tosh Assistant

Outline

ü MoBvaBonü Cyber-ThreatInformaBon(CTI)sharingü CurrentEfforts• Modelinga“Specific”Problem:SharingParEcipaEon• BlockchainforInformaBonSharing• ResearchChallenges• ConcludingRemarks

Page 11: Blockchain-based Cybersecurity Informa8on …credit.pvamu.edu/MCBDA2019/UTEP_Tosh.pdfBlockchain-based Cybersecurity Informa8on Sharing for Improved Resiliency Dr. Deepak K. Tosh Assistant

CYBEX Self-Coexistence Game

• N-firmsplayindependentlytofigureoutwhethertoparBcipateintheCTIsharingornot

Page 12: Blockchain-based Cybersecurity Informa8on …credit.pvamu.edu/MCBDA2019/UTEP_Tosh.pdfBlockchain-based Cybersecurity Informa8on Sharing for Improved Resiliency Dr. Deepak K. Tosh Assistant

CYBEX Self-Coexistence Game

Conflict:•  Firms’parBcipaBondependonparBcipaBoncostchargedbyCYBEX•  IfCYBEXchargestoohigh,lowparBcipaBonmightberesulted•  IfCYBEXchargestoolow,CYBEXmightnotbeprofitable

•  Firm’snetpayoffdependstwomajorfactors:•  SharingandInvestmentGain•  ParBcipaBoncostandcostofinformaBonshared

Page 13: Blockchain-based Cybersecurity Informa8on …credit.pvamu.edu/MCBDA2019/UTEP_Tosh.pdfBlockchain-based Cybersecurity Informa8on Sharing for Improved Resiliency Dr. Deepak K. Tosh Assistant

CYBEX Self-Coexistence Game

•  Thestrategicformcanbe

•  IfSislow,thenpurestrategyNashequilibriumforthesinglestagegameis:(NotPar)cipate,NotPar)cipate)•  CYBEXcannotsurviveinthiscase

• MulE-stageevoluEonaryanalysisisimportant

Page 14: Blockchain-based Cybersecurity Informa8on …credit.pvamu.edu/MCBDA2019/UTEP_Tosh.pdfBlockchain-based Cybersecurity Informa8on Sharing for Improved Resiliency Dr. Deepak K. Tosh Assistant

Evolu8onary Game Analysis

Goal:FindevoluBonarystablestrategy(ESS)thatcannotbeinvadedbyanyotherstrategyReplicatorDynamics:Assume,𝛼=ProporBonofpopulaBonwhoparBcipateandshareinCYBEX,thetransformaBonrate(𝑔(𝛼))is•  ProporBonaltodifferenceofexpectedindividualuBlityforthatstrategy(𝐸↓𝑠ℎ (𝑢))andexpecteduBlityofthepopulaBono 𝑔(𝛼)=𝛼[ 𝐸↓𝑠ℎ (𝑢)−𝐸(𝑢)]

Where,𝐸(𝑢)isaverageuBlityofthewholepopulaBon

Page 15: Blockchain-based Cybersecurity Informa8on …credit.pvamu.edu/MCBDA2019/UTEP_Tosh.pdfBlockchain-based Cybersecurity Informa8on Sharing for Improved Resiliency Dr. Deepak K. Tosh Assistant

Solving the Game

§  Solvingfor𝑔(𝛼)=0,wefind

§  Tohavestableneighborhood,𝑔↑′ (𝛼)<0§ WisechoiceofincenBveorparBcipaBoncost(c)isneededtomoBvatethesociallyopBmalbehavior

Page 16: Blockchain-based Cybersecurity Informa8on …credit.pvamu.edu/MCBDA2019/UTEP_Tosh.pdfBlockchain-based Cybersecurity Informa8on Sharing for Improved Resiliency Dr. Deepak K. Tosh Assistant

Interes8ng Evolu8onary Strategy

•  ExactESSisdecideddependingoniniBalsharingstrategypopulaBon(𝛼)•  𝛼↓𝑠𝑜𝑙↓1  (NoSharing)isESS,if0<𝛼< 𝑐+𝑥/(𝑆−1)𝑎𝑙𝑜𝑔(1+𝐼) •  𝛼↓𝑠𝑜𝑙↓2  (Share&ParBcipate)isESS,if𝑐+𝑥/(𝑆−1)𝑎𝑙𝑜𝑔(1+𝐼) <𝛼<1

Page 17: Blockchain-based Cybersecurity Informa8on …credit.pvamu.edu/MCBDA2019/UTEP_Tosh.pdfBlockchain-based Cybersecurity Informa8on Sharing for Improved Resiliency Dr. Deepak K. Tosh Assistant

Incen8viza8on through Par8cipa8on Cost

• DynamicincenBve/parBcipaBoncostexploitstheESScondiBons•  RevenueofCYBEXgrowsperiodically

•  StaBccostdemoBvatesfirmsfromparBcipaBon

Page 18: Blockchain-based Cybersecurity Informa8on …credit.pvamu.edu/MCBDA2019/UTEP_Tosh.pdfBlockchain-based Cybersecurity Informa8on Sharing for Improved Resiliency Dr. Deepak K. Tosh Assistant

Other Challenges

• Cyber-investment•  OpBmalsecurityinvestmentwhilesharingisconsidered

•  InformaBonOwnership

•  IntegrityandAuditabilityofsharedinformaBon

Page 19: Blockchain-based Cybersecurity Informa8on …credit.pvamu.edu/MCBDA2019/UTEP_Tosh.pdfBlockchain-based Cybersecurity Informa8on Sharing for Improved Resiliency Dr. Deepak K. Tosh Assistant

Outline

ü MoBvaBonü Cyber-ThreatInformaBon(CTI)sharingü CurrentEffortsü Modelinga“Specific”Problem:SharingParBcipaBon• BlockchainforInformaEonSharing• ResearchChallenges• ConcludingRemarks

Page 20: Blockchain-based Cybersecurity Informa8on …credit.pvamu.edu/MCBDA2019/UTEP_Tosh.pdfBlockchain-based Cybersecurity Informa8on Sharing for Improved Resiliency Dr. Deepak K. Tosh Assistant

Blockchain for Informa8on Sharing

Blockchain(IntegralpartofBitcoin):• AnopendistributedledgertorecordtransacBonsimmutably• Cost-lessverificaEonoftransacBons•  Fault-tolerant

Source:hOps://en.wikipedia.org/wiki/Blockchain

Page 21: Blockchain-based Cybersecurity Informa8on …credit.pvamu.edu/MCBDA2019/UTEP_Tosh.pdfBlockchain-based Cybersecurity Informa8on Sharing for Improved Resiliency Dr. Deepak K. Tosh Assistant

Blockchain-empowered Cybersecurity Informa8on Sharing Goals

What?Real-BmedisseminaBonofrelevantandacBonablecyberthreatindicatorsanddefensivemeasuresWho?Government,militaryandcommercialsectorsWhy?ProacBvedefenseandreducecyberriskWhile?Ensuringintegrity,trust,andprivacy

Page 22: Blockchain-based Cybersecurity Informa8on …credit.pvamu.edu/MCBDA2019/UTEP_Tosh.pdfBlockchain-based Cybersecurity Informa8on Sharing for Improved Resiliency Dr. Deepak K. Tosh Assistant

Blockchain-integrated Informa8on Sharing

Provenance:•  AudiBngprocesswhichmaintainsarecordofalloperaBonsconductedonsharedthreatinformaBon•  MaintainInformaBonIntegrity

Page 23: Blockchain-based Cybersecurity Informa8on …credit.pvamu.edu/MCBDA2019/UTEP_Tosh.pdfBlockchain-based Cybersecurity Informa8on Sharing for Improved Resiliency Dr. Deepak K. Tosh Assistant

Research Challenges

Ø EnsuringinformaBonprivacy

Ø PruningredundantinformaBon

Ø DerivingacBonablethreatintelligence

Ø Qualityvs.quanBty

Ø Enablingsector-wiseinformaBonsharing

Page 24: Blockchain-based Cybersecurity Informa8on …credit.pvamu.edu/MCBDA2019/UTEP_Tosh.pdfBlockchain-based Cybersecurity Informa8on Sharing for Improved Resiliency Dr. Deepak K. Tosh Assistant

Concluding Remarks

• Cybersecuritylandscapeishugeandtherearealottoexplore• Cyber-threatinformaBonsharingisoneimportantiniBaBvetowardproacBvedefense• BlockchaintechnologyisanewfronBertodesigntamper-resistantsystems• Aworkingpladormthatintegratesbothisyettocome

Page 25: Blockchain-based Cybersecurity Informa8on …credit.pvamu.edu/MCBDA2019/UTEP_Tosh.pdfBlockchain-based Cybersecurity Informa8on Sharing for Improved Resiliency Dr. Deepak K. Tosh Assistant

Thank You QuesBons??