A Trusted, Verifiable and Differential Cyber Threat Intelligence Sharing Framework using Blockchain
Kealan Dunnett, Shantanu Pal, Guntur Dharma Putra, Zahra Jadidi, Raja, Jurdak

TL;DR
This paper introduces a blockchain-based framework for secure, trusted, and selective sharing of cyber threat intelligence, addressing privacy and verification challenges in collaborative cybersecurity efforts.
Contribution
It presents a novel blockchain framework enabling organizations to share sensitive CTI data verifiably and differentially with flexible policies, filling gaps in existing solutions.
Findings
Framework ensures trusted and verifiable CTI sharing
Allows differential sharing with flexible policies
Experimental results show low overheads
Abstract
Cyber Threat Intelligence (CTI) is the knowledge of cyber and physical threats that help mitigate potential cyber attacks. The rapid evolution of the current threat landscape has seen many organisations share CTI to strengthen their security posture for mutual benefit. However, in many cases, CTI data contains attributes (e.g., software versions) that have the potential to leak sensitive information or cause reputational damage to the sharing organisation. While current approaches allow restricting CTI sharing to trusted organisations, they lack solutions where the shared data can be verified and disseminated `differentially' (i.e., selective information sharing) with policies and metrics flexibly defined by an organisation. In this paper, we propose a blockchain-based CTI sharing framework that allows organisations to share sensitive CTI data in a trusted, verifiable and differential…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsCybercrime and Law Enforcement Studies · Advanced Malware Detection Techniques · Information and Cyber Security
