Peer-to-Peer Enclaves for Improving Network Defence

Information about cyberthreats within networks spreads slowly relative to the speed at which those threats spread. Typical "threat feeds" that are commercially available also disseminate information slowly relative to the propagation speed of attacks, and they often convey irrelevant infor...

Full description

Bibliographic Details
Main Authors: David W. Archer, Adam Wick
Format: Article
Language:English
Published: Carleton University 2013-07-01
Series:Technology Innovation Management Review
Subjects:
Online Access:http://timreview.ca/sites/default/files/article_PDF/ArcherWick_TIMReview_July2013.pdf
_version_ 1819029409827389440
author David W. Archer
Adam Wick
author_facet David W. Archer
Adam Wick
author_sort David W. Archer
collection DOAJ
description Information about cyberthreats within networks spreads slowly relative to the speed at which those threats spread. Typical "threat feeds" that are commercially available also disseminate information slowly relative to the propagation speed of attacks, and they often convey irrelevant information about imminent threats. As a result, hosts sharing a network may miss opportunities to improve their defence postures against imminent attack because needed information arrives too late or is lost in irrelevant noise. We envision timely, relevant peer-to-peer sharing of threat information – based on current technologies – as a solution to these problems and as a useful design pattern for defensive cyberwarfare. In our setting, network nodes form communities that we call enclaves, where each node defends itself while sharing information on imminent threats with peers that have similar threat exposure. In this article, we present our vision for this solution. We sketch the architecture of a typical node in such a network and how it might interact with a framework for sharing threat information; we explain why certain defensive countermeasures may work better in our setting; we discuss current tools that could be used as components in our vision; and we describe opportunities for future research and development.
first_indexed 2024-12-21T06:13:48Z
format Article
id doaj.art-3dee205a13d84535a7c31bdd2a90f255
institution Directory Open Access Journal
issn 1927-0321
language English
last_indexed 2024-12-21T06:13:48Z
publishDate 2013-07-01
publisher Carleton University
record_format Article
series Technology Innovation Management Review
spelling doaj.art-3dee205a13d84535a7c31bdd2a90f2552022-12-21T19:13:27ZengCarleton UniversityTechnology Innovation Management Review1927-03212013-07-01July 2013: Cybersecurity1924Peer-to-Peer Enclaves for Improving Network DefenceDavid W. ArcherAdam WickInformation about cyberthreats within networks spreads slowly relative to the speed at which those threats spread. Typical "threat feeds" that are commercially available also disseminate information slowly relative to the propagation speed of attacks, and they often convey irrelevant information about imminent threats. As a result, hosts sharing a network may miss opportunities to improve their defence postures against imminent attack because needed information arrives too late or is lost in irrelevant noise. We envision timely, relevant peer-to-peer sharing of threat information – based on current technologies – as a solution to these problems and as a useful design pattern for defensive cyberwarfare. In our setting, network nodes form communities that we call enclaves, where each node defends itself while sharing information on imminent threats with peers that have similar threat exposure. In this article, we present our vision for this solution. We sketch the architecture of a typical node in such a network and how it might interact with a framework for sharing threat information; we explain why certain defensive countermeasures may work better in our setting; we discuss current tools that could be used as components in our vision; and we describe opportunities for future research and development.http://timreview.ca/sites/default/files/article_PDF/ArcherWick_TIMReview_July2013.pdfcyber countermeasurescybersecuritydynamic cyberdefenceenclave computingnetwork defencepeer-to-peer
spellingShingle David W. Archer
Adam Wick
Peer-to-Peer Enclaves for Improving Network Defence
Technology Innovation Management Review
cyber countermeasures
cybersecurity
dynamic cyberdefence
enclave computing
network defence
peer-to-peer
title Peer-to-Peer Enclaves for Improving Network Defence
title_full Peer-to-Peer Enclaves for Improving Network Defence
title_fullStr Peer-to-Peer Enclaves for Improving Network Defence
title_full_unstemmed Peer-to-Peer Enclaves for Improving Network Defence
title_short Peer-to-Peer Enclaves for Improving Network Defence
title_sort peer to peer enclaves for improving network defence
topic cyber countermeasures
cybersecurity
dynamic cyberdefence
enclave computing
network defence
peer-to-peer
url http://timreview.ca/sites/default/files/article_PDF/ArcherWick_TIMReview_July2013.pdf
work_keys_str_mv AT davidwarcher peertopeerenclavesforimprovingnetworkdefence
AT adamwick peertopeerenclavesforimprovingnetworkdefence