skip to main content
10.1145/2808128.2808137acmconferencesArticle/Chapter ViewAbstractPublication PagesccsConference Proceedingsconference-collections
invited-talk

Real World Information Exchange: Challenges and Insights

Published:12 October 2015Publication History

ABSTRACT

CERT-EU's mission is to enhance the security of the information and communications technology infrastructure of the EU institutions, bodies and agencies (its 'constituents'). It supports incident prevention, detection, mitigation and response by acting as the cyber-security information exchange and incident response coordination hub for its constituents. It is based in Brussels. Collecting and managing cyber threat information and using it in the detection infrastructure is key in risk mitigation strategies. Information exchange with external and internal partners is crucially important to realize the potential added value. CERT-EU actively and intensively engages in cooperation and partnerships with its peers and partners in the IT community and as such it is recognised as a leading player in information exchange, both on the theoretical level as in its real world implementation. CERT-EU has also made important advances in the way it exchanges information with its constituents to make the information actionable, relevant, useful and specific and to avoid as much noise and false positives as possible.

A good understanding of the specific threats at any given moment increases the chances of mitigation. An organization may be more concerned by cyber-threats targeting its sector, its supply chain or its geographical area and it may handle in priority cyber-threats potentially causing the most damage, being the most persistent or having a specific motivation. Monitoring these aspects and acting accordingly allows organizations to mitigate the threats that are the most pertinent at a given time. As cyber threat information sharing matures, it is necessary to consider how it should be optimized and what it should deliver on the consuming end. This implies that information exchange should meet minimal quality criteria in terms of contextualization, timeliness and actionability.

Faced with an extremely dynamic cyber-threat landscape, the challenge is also to automate information sharing and make it immediately actionable. But in addition, the process should also include escalation and alerting functions to trigger immediate attention to the most severe of threats.

The talk will highlight the insights derived from CERT-EU practical experience in the past few years, presenting concrete success factors for cyber threat information exchange. It will also highlight some remaining challenges and unresolved problems.

References

  1. Contextualised and actionable information sharing within the cyber-security community -- Frédéric Garnier -- CERT-EUGoogle ScholarGoogle Scholar

Index Terms

  1. Real World Information Exchange: Challenges and Insights

          Recommendations

          Comments

          Login options

          Check if you have access through your login credentials or your institution to get full access on this article.

          Sign in
          • Published in

            cover image ACM Conferences
            WISCS '15: Proceedings of the 2nd ACM Workshop on Information Sharing and Collaborative Security
            October 2015
            84 pages
            ISBN:9781450338226
            DOI:10.1145/2808128

            Copyright © 2015 Owner/Author

            Permission to make digital or hard copies of part or all of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for third-party components of this work must be honored. For all other uses, contact the Owner/Author.

            Publisher

            Association for Computing Machinery

            New York, NY, United States

            Publication History

            • Published: 12 October 2015

            Check for updates

            Qualifiers

            • invited-talk

            Acceptance Rates

            WISCS '15 Paper Acceptance Rate6of16submissions,38%Overall Acceptance Rate23of58submissions,40%

            Upcoming Conference

            CCS '24
            ACM SIGSAC Conference on Computer and Communications Security
            October 14 - 18, 2024
            Salt Lake City , UT , USA
          • Article Metrics

            • Downloads (Last 12 months)4
            • Downloads (Last 6 weeks)0

            Other Metrics

          PDF Format

          View or Download as a PDF file.

          PDF

          eReader

          View online with eReader.

          eReader