Efficient collective action for tackling time-critical cybersecurity threats

Author:

Gillard Sébastien12ORCID,Percia David Dimitri134ORCID,Mermoud Alain3ORCID,Maillart Thomas15ORCID

Affiliation:

1. Information Science Institute, Geneva School of Economics & Management, University of Geneva , Boulevard du Pont-d’Arve 40, 1211 Geneva , Switzerland

2. Chair of Defense Economics, Military Academy at ETH Zurich , Kaserne Reppischtal, 8903 Birmensdorf , Switzerland

3. Cyber-Defence Campus, armasuisse Science and Technology , Feuerwerkstrasse 39, 3602 Thun , Switzerland

4. Institute of Entrepreneurship & Management, University of Applied Sciences of Western Switzerland (HES-SO Valais-Wallis) , Techno-Pôle 1, Le Foyer, 3960 Sierre , Switzerland

5. Citizen Cyber Lab, University of Geneva , Avenue de Sécheron 15, 1202 Geneva , Switzerland

Abstract

Abstract The latency reduction between the discovery of vulnerabilities, the build-up, and the dissemination of cyberattacks has put significant pressure on cybersecurity professionals. For that, security researchers have increasingly resorted to collective action in order to reduce the time needed to characterize and tame outstanding threats. Here, we investigate how joining and contribution dynamics on Malware Information Sharing Platform (MISP), an open-source threat intelligence sharing platform, influence the time needed to collectively complete threat descriptions. We find that performance, defined as the capacity to characterize quickly a threat event, is influenced by (i) its own complexity (negatively), by (ii) collective action (positively), and by (iii) learning, information integration, and modularity (positively). Our results inform on how collective action can be organized at scale and in a modular way to overcome a large number of time-critical tasks, such as cybersecurity threats.

Funder

Military Academy

Publisher

Oxford University Press (OUP)

Subject

Law,Computer Networks and Communications,Political Science and International Relations,Safety, Risk, Reliability and Quality,Social Psychology,Computer Science (miscellaneous)

Reference76 articles.

1. Cybersecurity information sharing: analysing an email corpus of coordinated vulnerability disclosure;Sridhar,2021

2. The economic incentives for sharing security information;Gal-Or;Inf Syst Res,2005

3. Given enough eyeballs, all bugs are shallow? Revisiting Eric Raymond with bug bounty programs;Maillart;J Cybersecur,2017

4. Hacking for good: leveraging HackerOne data to develop an economic model of bug bounties;Sridhar;J Cybersecur,2021

5. Back to the roots: information sharing economics and what we can learn for security;Böhme,2016

Cited by 5 articles. 订阅此论文施引文献 订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献

1. Enhancing Intrusion Detection Systems with Adaptive Learning Techniques;2024 IEEE International Conference on Artificial Intelligence and Mechatronics Systems (AIMS);2024-02-21

2. Understanding enterprise cybersecurity information sharing: a theoretical model and empirical analysis;Enterprise Information Systems;2024-01-31

3. Building Collaborative Cybersecurity for Critical Infrastructure Protection: Empirical Evidence of Collective Intelligence Information Sharing Dynamics on ThreatFox;Critical Information Infrastructures Security;2023

4. Improving the Effectiveness of Cyberdefense Measures;International Series in Operations Research & Management Science;2023

5. Trends in Open Source Software for Data Protection and Encryption Technologies;Trends in Data Protection and Encryption Technologies;2023

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3