25
Blockchain-based Cybersecurity Informa8on Sharing for Improved Resiliency Dr. Deepak K. Tosh Assistant Professor Department of Computer Science University of Texas at El Paso Email: [email protected]

Blockchain-based Cybersecurity Informa8on …credit.pvamu.edu/MCBDA2019/UTEP_Tosh.pdfBlockchain-based Cybersecurity Informa8on Sharing for Improved Resiliency Dr. Deepak K. Tosh Assistant

  • Upload
    others

  • View
    3

  • Download
    0

Embed Size (px)

Citation preview

Page 1: Blockchain-based Cybersecurity Informa8on …credit.pvamu.edu/MCBDA2019/UTEP_Tosh.pdfBlockchain-based Cybersecurity Informa8on Sharing for Improved Resiliency Dr. Deepak K. Tosh Assistant

Blockchain-based Cybersecurity Informa8on Sharing for Improved Resiliency

Dr.DeepakK.ToshAssistantProfessor

DepartmentofComputerScienceUniversityofTexasatElPaso

Email:[email protected]

Page 2: Blockchain-based Cybersecurity Informa8on …credit.pvamu.edu/MCBDA2019/UTEP_Tosh.pdfBlockchain-based Cybersecurity Informa8on Sharing for Improved Resiliency Dr. Deepak K. Tosh Assistant

Outline

• MoBvaBon• Cyber-ThreatInformaBon(CTI)sharing• CurrentEfforts• Modelinga“Specific”Problem:SharingParBcipaBon• BlockchainforInformaBonSharing• ResearchChallenges• ConcludingRemarks

Page 3: Blockchain-based Cybersecurity Informa8on …credit.pvamu.edu/MCBDA2019/UTEP_Tosh.pdfBlockchain-based Cybersecurity Informa8on Sharing for Improved Resiliency Dr. Deepak K. Tosh Assistant

Growth of Cyber Threats

• AdvancedcyberaOacksarewellorganizedandhardtodetect

•  ExploitsareeasilyacquiredandcanbereusedonmulBpletargets• ReacBvestrategiesareinsufficienttodealwiththethreats

Page 4: Blockchain-based Cybersecurity Informa8on …credit.pvamu.edu/MCBDA2019/UTEP_Tosh.pdfBlockchain-based Cybersecurity Informa8on Sharing for Improved Resiliency Dr. Deepak K. Tosh Assistant

Need of Threat Intelligence

• CyberaOacksmaynotbepreventedbuttheirimpactscanbereducedby•  Improvingcyber-awarenessandunderstandingthreatlandscape•  CollaboraBveeffortfromenterprisesaswellasgovernment•  Imposingsecuritypolicies/laws(e.g.GDPR)

• Cyber-ThreatIntelligence(CTI)canderive•  AcBonableinformaBonfromvariouslowlevelthreatindicators(likeIP,email,maliciousURLs,domainnames,aOackpaOern,geo-locaBoninfo,malwarehash)•  Findingtargetedresources,threatactors,methods/toolsused,aOackcharacterisBcs,IoC,etc.

Page 5: Blockchain-based Cybersecurity Informa8on …credit.pvamu.edu/MCBDA2019/UTEP_Tosh.pdfBlockchain-based Cybersecurity Informa8on Sharing for Improved Resiliency Dr. Deepak K. Tosh Assistant

Handling Cybersecurity Threats

•  Securityinvestmenthelpsin•  Discoveringsystemloopholes,bugs,vulnerabiliBes•  IdenBfymaliciousacBviBes•  DevelopinganB-threatstrategies

Improvesdefenders’abilitytopredicta2ackerbehaviorandcreatemoredynamicdefenses• Demerits:•  Costly•  Timeconsuming

Page 6: Blockchain-based Cybersecurity Informa8on …credit.pvamu.edu/MCBDA2019/UTEP_Tosh.pdfBlockchain-based Cybersecurity Informa8on Sharing for Improved Resiliency Dr. Deepak K. Tosh Assistant

Cybersecurity Informa8on Sharing

• AnecosystemwhereacBonablecyber-threatintelligenceissharedautomaBcallyacrossverBcalsandpublic/privatesectorsinnearreal-Bmetocombatcyberthreatlandscape• Benefits•  AccesstoIndicators,TacBcs,techniques,andprocedures(TTPs),Securityalerts,Threatintelligencereports,ToolconfiguraBons•  EnhanceoperaBonalunderstandingofcyberthreats•  ProacBveDefense•  ReduceCyberRisk•  PrioriBzedMiBgaBonPlan•  CosteffecBvedefensestrategy

Page 7: Blockchain-based Cybersecurity Informa8on …credit.pvamu.edu/MCBDA2019/UTEP_Tosh.pdfBlockchain-based Cybersecurity Informa8on Sharing for Improved Resiliency Dr. Deepak K. Tosh Assistant

Limita8ons of Informa8on Sharing

•  SomethingstopsorganizaBonsfromsharing!!!•  JeopardizethesecuritypostureofthesharingorganizaBon•  Externalimpactssuchasmarketvalue,reputaBon,etc.•  InformaBonfree-riding•  SpuriousinformaBonandprocessingoverheads

Page 8: Blockchain-based Cybersecurity Informa8on …credit.pvamu.edu/MCBDA2019/UTEP_Tosh.pdfBlockchain-based Cybersecurity Informa8on Sharing for Improved Resiliency Dr. Deepak K. Tosh Assistant

How did we get here?

Following9-11FederalInformaBonSharinggrows-failuretoconnectthedots

In2007,PresidentBushcreatesComprehensiveNaEonalCyberIniEaEve(CNCI)-ConnecttheFedCyberCentersinordertoaddresscyberthreatlandscape

In2013,EnhanceSharedSituaEonAwarenessProject(ESSA)createdtoautomatecyberthreatinformaBonsharingbetweenFedCyberCenters.-StandardsharinglanguagesSTIX/TAXII,sharedcapabilityproviders,andcommonsharingagreement(MISA).

In2015,CybersecurityInformaEonSharingAct(CISA)passed.-EstablishestheDHSAutomatedIndicatorSharing(AIS)ProgramforsharingcyberthreatindicatorsanddefensivemeasuresbetweentheFederalGovernmentandNon-FederalEnBBes.

In2016thelegacyofESSAisleveragedbyDHSforconBnuaBonofFederalCyberThreatInformaBonSharingandcoordinaBonthroughtheFederalCybersecurityInteragencyGroup(FCIG).

Page 9: Blockchain-based Cybersecurity Informa8on …credit.pvamu.edu/MCBDA2019/UTEP_Tosh.pdfBlockchain-based Cybersecurity Informa8on Sharing for Improved Resiliency Dr. Deepak K. Tosh Assistant

Cybersecurity Informa8on Sharing Today

• CybersecurityInformaBonsharinghasbeengoingonthroughISACs,ISAOs,eco-systems,opensource,andcommercialofferings•  LimitaBons•  Generallyunstructureddata•  Ad-hocmanualcommunicaBonssuchasemail/IM/IRC/paper•  Fewautomatedtools•  LackofincenBvemodelforvoluntaryparBcipaBon

Page 10: Blockchain-based Cybersecurity Informa8on …credit.pvamu.edu/MCBDA2019/UTEP_Tosh.pdfBlockchain-based Cybersecurity Informa8on Sharing for Improved Resiliency Dr. Deepak K. Tosh Assistant

Outline

ü MoBvaBonü Cyber-ThreatInformaBon(CTI)sharingü CurrentEfforts• Modelinga“Specific”Problem:SharingParEcipaEon• BlockchainforInformaBonSharing• ResearchChallenges• ConcludingRemarks

Page 11: Blockchain-based Cybersecurity Informa8on …credit.pvamu.edu/MCBDA2019/UTEP_Tosh.pdfBlockchain-based Cybersecurity Informa8on Sharing for Improved Resiliency Dr. Deepak K. Tosh Assistant

CYBEX Self-Coexistence Game

• N-firmsplayindependentlytofigureoutwhethertoparBcipateintheCTIsharingornot

Page 12: Blockchain-based Cybersecurity Informa8on …credit.pvamu.edu/MCBDA2019/UTEP_Tosh.pdfBlockchain-based Cybersecurity Informa8on Sharing for Improved Resiliency Dr. Deepak K. Tosh Assistant

CYBEX Self-Coexistence Game

Conflict:•  Firms’parBcipaBondependonparBcipaBoncostchargedbyCYBEX•  IfCYBEXchargestoohigh,lowparBcipaBonmightberesulted•  IfCYBEXchargestoolow,CYBEXmightnotbeprofitable

•  Firm’snetpayoffdependstwomajorfactors:•  SharingandInvestmentGain•  ParBcipaBoncostandcostofinformaBonshared

Page 13: Blockchain-based Cybersecurity Informa8on …credit.pvamu.edu/MCBDA2019/UTEP_Tosh.pdfBlockchain-based Cybersecurity Informa8on Sharing for Improved Resiliency Dr. Deepak K. Tosh Assistant

CYBEX Self-Coexistence Game

•  Thestrategicformcanbe

•  IfSislow,thenpurestrategyNashequilibriumforthesinglestagegameis:(NotPar)cipate,NotPar)cipate)•  CYBEXcannotsurviveinthiscase

• MulE-stageevoluEonaryanalysisisimportant

Page 14: Blockchain-based Cybersecurity Informa8on …credit.pvamu.edu/MCBDA2019/UTEP_Tosh.pdfBlockchain-based Cybersecurity Informa8on Sharing for Improved Resiliency Dr. Deepak K. Tosh Assistant

Evolu8onary Game Analysis

Goal:FindevoluBonarystablestrategy(ESS)thatcannotbeinvadedbyanyotherstrategyReplicatorDynamics:Assume,𝛼=ProporBonofpopulaBonwhoparBcipateandshareinCYBEX,thetransformaBonrate(𝑔(𝛼))is•  ProporBonaltodifferenceofexpectedindividualuBlityforthatstrategy(𝐸↓𝑠ℎ (𝑢))andexpecteduBlityofthepopulaBono 𝑔(𝛼)=𝛼[ 𝐸↓𝑠ℎ (𝑢)−𝐸(𝑢)]

Where,𝐸(𝑢)isaverageuBlityofthewholepopulaBon

Page 15: Blockchain-based Cybersecurity Informa8on …credit.pvamu.edu/MCBDA2019/UTEP_Tosh.pdfBlockchain-based Cybersecurity Informa8on Sharing for Improved Resiliency Dr. Deepak K. Tosh Assistant

Solving the Game

§  Solvingfor𝑔(𝛼)=0,wefind

§  Tohavestableneighborhood,𝑔↑′ (𝛼)<0§ WisechoiceofincenBveorparBcipaBoncost(c)isneededtomoBvatethesociallyopBmalbehavior

Page 16: Blockchain-based Cybersecurity Informa8on …credit.pvamu.edu/MCBDA2019/UTEP_Tosh.pdfBlockchain-based Cybersecurity Informa8on Sharing for Improved Resiliency Dr. Deepak K. Tosh Assistant

Interes8ng Evolu8onary Strategy

•  ExactESSisdecideddependingoniniBalsharingstrategypopulaBon(𝛼)•  𝛼↓𝑠𝑜𝑙↓1  (NoSharing)isESS,if0<𝛼< 𝑐+𝑥/(𝑆−1)𝑎𝑙𝑜𝑔(1+𝐼) •  𝛼↓𝑠𝑜𝑙↓2  (Share&ParBcipate)isESS,if𝑐+𝑥/(𝑆−1)𝑎𝑙𝑜𝑔(1+𝐼) <𝛼<1

Page 17: Blockchain-based Cybersecurity Informa8on …credit.pvamu.edu/MCBDA2019/UTEP_Tosh.pdfBlockchain-based Cybersecurity Informa8on Sharing for Improved Resiliency Dr. Deepak K. Tosh Assistant

Incen8viza8on through Par8cipa8on Cost

• DynamicincenBve/parBcipaBoncostexploitstheESScondiBons•  RevenueofCYBEXgrowsperiodically

•  StaBccostdemoBvatesfirmsfromparBcipaBon

Page 18: Blockchain-based Cybersecurity Informa8on …credit.pvamu.edu/MCBDA2019/UTEP_Tosh.pdfBlockchain-based Cybersecurity Informa8on Sharing for Improved Resiliency Dr. Deepak K. Tosh Assistant

Other Challenges

• Cyber-investment•  OpBmalsecurityinvestmentwhilesharingisconsidered

•  InformaBonOwnership

•  IntegrityandAuditabilityofsharedinformaBon

Page 19: Blockchain-based Cybersecurity Informa8on …credit.pvamu.edu/MCBDA2019/UTEP_Tosh.pdfBlockchain-based Cybersecurity Informa8on Sharing for Improved Resiliency Dr. Deepak K. Tosh Assistant

Outline

ü MoBvaBonü Cyber-ThreatInformaBon(CTI)sharingü CurrentEffortsü Modelinga“Specific”Problem:SharingParBcipaBon• BlockchainforInformaEonSharing• ResearchChallenges• ConcludingRemarks

Page 20: Blockchain-based Cybersecurity Informa8on …credit.pvamu.edu/MCBDA2019/UTEP_Tosh.pdfBlockchain-based Cybersecurity Informa8on Sharing for Improved Resiliency Dr. Deepak K. Tosh Assistant

Blockchain for Informa8on Sharing

Blockchain(IntegralpartofBitcoin):• AnopendistributedledgertorecordtransacBonsimmutably• Cost-lessverificaEonoftransacBons•  Fault-tolerant

Source:hOps://en.wikipedia.org/wiki/Blockchain

Page 21: Blockchain-based Cybersecurity Informa8on …credit.pvamu.edu/MCBDA2019/UTEP_Tosh.pdfBlockchain-based Cybersecurity Informa8on Sharing for Improved Resiliency Dr. Deepak K. Tosh Assistant

Blockchain-empowered Cybersecurity Informa8on Sharing Goals

What?Real-BmedisseminaBonofrelevantandacBonablecyberthreatindicatorsanddefensivemeasuresWho?Government,militaryandcommercialsectorsWhy?ProacBvedefenseandreducecyberriskWhile?Ensuringintegrity,trust,andprivacy

Page 22: Blockchain-based Cybersecurity Informa8on …credit.pvamu.edu/MCBDA2019/UTEP_Tosh.pdfBlockchain-based Cybersecurity Informa8on Sharing for Improved Resiliency Dr. Deepak K. Tosh Assistant

Blockchain-integrated Informa8on Sharing

Provenance:•  AudiBngprocesswhichmaintainsarecordofalloperaBonsconductedonsharedthreatinformaBon•  MaintainInformaBonIntegrity

Page 23: Blockchain-based Cybersecurity Informa8on …credit.pvamu.edu/MCBDA2019/UTEP_Tosh.pdfBlockchain-based Cybersecurity Informa8on Sharing for Improved Resiliency Dr. Deepak K. Tosh Assistant

Research Challenges

Ø EnsuringinformaBonprivacy

Ø PruningredundantinformaBon

Ø DerivingacBonablethreatintelligence

Ø Qualityvs.quanBty

Ø Enablingsector-wiseinformaBonsharing

Page 24: Blockchain-based Cybersecurity Informa8on …credit.pvamu.edu/MCBDA2019/UTEP_Tosh.pdfBlockchain-based Cybersecurity Informa8on Sharing for Improved Resiliency Dr. Deepak K. Tosh Assistant

Concluding Remarks

• Cybersecuritylandscapeishugeandtherearealottoexplore• Cyber-threatinformaBonsharingisoneimportantiniBaBvetowardproacBvedefense• BlockchaintechnologyisanewfronBertodesigntamper-resistantsystems• Aworkingpladormthatintegratesbothisyettocome

Page 25: Blockchain-based Cybersecurity Informa8on …credit.pvamu.edu/MCBDA2019/UTEP_Tosh.pdfBlockchain-based Cybersecurity Informa8on Sharing for Improved Resiliency Dr. Deepak K. Tosh Assistant

Thank You QuesBons??