Orchestrating Collaborative Cybersecurity: A Secure Framework for Distributed Privacy-Preserving Threat Intelligence Sharing
Juan R. Trocoso-Pastoriza, Alain Mermoud, Romain Bouy\'e, Francesco, Marino, Jean-Philippe Bossuat, Vincent Lenders, Jean-Pierre Hubaux

TL;DR
This paper introduces a secure, privacy-preserving framework for distributed Cyber Threat Intelligence sharing that enhances data control, reduces bias, and improves threat detection without relying on centralized databases.
Contribution
It presents a novel federated framework combining privacy technologies for distributed CTI sharing, addressing data bias and confidentiality issues in threat intelligence exchange.
Findings
Effective CTI extraction from distributed data sources.
Improved threat detection accuracy in practical scenarios.
Enhanced privacy and control for participating organizations.
Abstract
Cyber Threat Intelligence (CTI) sharing is an important activity to reduce information asymmetries between attackers and defenders. However, this activity presents challenges due to the tension between data sharing and confidentiality, that result in information retention often leading to a free-rider problem. Therefore, the information that is shared represents only the tip of the iceberg. Current literature assumes access to centralized databases containing all the information, but this is not always feasible, due to the aforementioned tension. This results in unbalanced or incomplete datasets, requiring the use of techniques to expand them; we show how these techniques lead to biased results and misleading performance expectations. We propose a novel framework for extracting CTI from distributed data on incidents, vulnerabilities and indicators of compromise, and demonstrate its use…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsCybercrime and Law Enforcement Studies · Information and Cyber Security · Advanced Malware Detection Techniques
