Cybersecurity information sharing (CIS) is envisioned to protect organizations more effectively from advanced cyber attacks. However, a completely automated CIS platform is not widely adopted. The major challenges are: (1) the absence of a robust cyber threat language (CTL) and (2) the concerns over data privacy. This work introduces Cybersecurity Information Exchangewith Privacy (CYBEX-P), as a CIS framework, to tackle these challenges. CYBEX-P allows organizations to share heterogeneous data with granular, attribute based privacy control. It correlates the data to automatically generate intuitive reports and defensive rules. To achieve such versatility, we have developed TAHOE - a graph based CTL. TAHOE is a structure for storing,sharing and analyzing threat data. It also intrinsically correlates the data. We have further developed a universal Threat Data Query Language (TDQL). In this paper, we propose the system architecture for CYBEX-P. We then discuss its scalability and privacy features along with a use case of CYBEX-P providing Infrastructure as a Service (IaaS). We further introduce TAHOE& TDQL as better alternatives to existing CTLs and formulate ThreatRank - an algorithm to detect new malicious even
翻译:网络安全信息交流(CYBEX-P)旨在更有效地保护各组织免遭先进的网络攻击,然而,完全自动化的独联体平台并未被广泛采用,主要挑战包括:(1) 缺乏强大的网络威胁语言(CTL)和(2) 对数据隐私的关切;这项工作引入了网络安全与隐私的网络安全信息交流(CYBEX-P),作为独联体的一个框架,以应对这些挑战。CYBEX-P允许各组织与基于属性的微粒隐私控制共享多种数据。它将数据与自动生成直观报告和防御规则联系起来。为了实现这种多功能性,我们开发了TAHOE-基于图表的CTL。TAHOE是一个储存、共享和分析威胁数据的结构。它也与数据有着内在的联系。我们在本文中提出了CYBEX-P的系统架构。我们随后讨论了其可扩展性和隐私特征,并讨论了使用CYBEX-P提供基础设施作为服务的案例。我们进一步引入了TAHOE和TDQL作为更好的现有替代方法。我们甚至还引入了TAVE和DQL,以更好地探测了新的替代方法。