Peer-to-Peer Enclaves for Improving Network Defence
Information about cyberthreats within networks spreads slowly relative to the speed at which those threats spread. Typical "threat feeds" that are commercially available also disseminate information slowly relative to the propagation speed of attacks, and they often convey irrelevant infor...
Main Authors: | , |
---|---|
Format: | Article |
Language: | English |
Published: |
Carleton University
2013-07-01
|
Series: | Technology Innovation Management Review |
Subjects: | |
Online Access: | http://timreview.ca/sites/default/files/article_PDF/ArcherWick_TIMReview_July2013.pdf |
_version_ | 1819029409827389440 |
---|---|
author | David W. Archer Adam Wick |
author_facet | David W. Archer Adam Wick |
author_sort | David W. Archer |
collection | DOAJ |
description | Information about cyberthreats within networks spreads slowly relative to the speed at which those threats spread. Typical "threat feeds" that are commercially available also disseminate information slowly relative to the propagation speed of attacks, and they often convey irrelevant information about imminent threats. As a result, hosts sharing a network may miss opportunities to improve their defence postures against imminent attack because needed information arrives too late or is lost in irrelevant noise. We envision timely, relevant peer-to-peer sharing of threat information – based on current technologies – as a solution to these problems and as a useful design pattern for defensive cyberwarfare. In our setting, network nodes form communities that we call enclaves, where each node defends itself while sharing information on imminent threats with peers that have similar threat exposure. In this article, we present our vision for this solution. We sketch the architecture of a typical node in such a network and how it might interact with a framework for sharing threat information; we explain why certain defensive countermeasures may work better in our setting; we discuss current tools that could be used as components in our vision; and we describe opportunities for future research and development. |
first_indexed | 2024-12-21T06:13:48Z |
format | Article |
id | doaj.art-3dee205a13d84535a7c31bdd2a90f255 |
institution | Directory Open Access Journal |
issn | 1927-0321 |
language | English |
last_indexed | 2024-12-21T06:13:48Z |
publishDate | 2013-07-01 |
publisher | Carleton University |
record_format | Article |
series | Technology Innovation Management Review |
spelling | doaj.art-3dee205a13d84535a7c31bdd2a90f2552022-12-21T19:13:27ZengCarleton UniversityTechnology Innovation Management Review1927-03212013-07-01July 2013: Cybersecurity1924Peer-to-Peer Enclaves for Improving Network DefenceDavid W. ArcherAdam WickInformation about cyberthreats within networks spreads slowly relative to the speed at which those threats spread. Typical "threat feeds" that are commercially available also disseminate information slowly relative to the propagation speed of attacks, and they often convey irrelevant information about imminent threats. As a result, hosts sharing a network may miss opportunities to improve their defence postures against imminent attack because needed information arrives too late or is lost in irrelevant noise. We envision timely, relevant peer-to-peer sharing of threat information – based on current technologies – as a solution to these problems and as a useful design pattern for defensive cyberwarfare. In our setting, network nodes form communities that we call enclaves, where each node defends itself while sharing information on imminent threats with peers that have similar threat exposure. In this article, we present our vision for this solution. We sketch the architecture of a typical node in such a network and how it might interact with a framework for sharing threat information; we explain why certain defensive countermeasures may work better in our setting; we discuss current tools that could be used as components in our vision; and we describe opportunities for future research and development.http://timreview.ca/sites/default/files/article_PDF/ArcherWick_TIMReview_July2013.pdfcyber countermeasurescybersecuritydynamic cyberdefenceenclave computingnetwork defencepeer-to-peer |
spellingShingle | David W. Archer Adam Wick Peer-to-Peer Enclaves for Improving Network Defence Technology Innovation Management Review cyber countermeasures cybersecurity dynamic cyberdefence enclave computing network defence peer-to-peer |
title | Peer-to-Peer Enclaves for Improving Network Defence |
title_full | Peer-to-Peer Enclaves for Improving Network Defence |
title_fullStr | Peer-to-Peer Enclaves for Improving Network Defence |
title_full_unstemmed | Peer-to-Peer Enclaves for Improving Network Defence |
title_short | Peer-to-Peer Enclaves for Improving Network Defence |
title_sort | peer to peer enclaves for improving network defence |
topic | cyber countermeasures cybersecurity dynamic cyberdefence enclave computing network defence peer-to-peer |
url | http://timreview.ca/sites/default/files/article_PDF/ArcherWick_TIMReview_July2013.pdf |
work_keys_str_mv | AT davidwarcher peertopeerenclavesforimprovingnetworkdefence AT adamwick peertopeerenclavesforimprovingnetworkdefence |