Cargando…

Trusted Threat Intelligence Sharing in Practice and Performance Benchmarking through the Hyperledger Fabric Platform

Historically, threat information sharing has relied on manual modelling and centralised network systems, which can be inefficient, insecure, and prone to errors. Alternatively, private blockchains are now widely used to address these issues and improve overall organisational security. An organisatio...

Descripción completa

Detalles Bibliográficos
Autores principales: Ali, Hisham, Ahmad, Jawad, Jaroucheh, Zakwan, Papadopoulos, Pavlos, Pitropakis, Nikolaos, Lo, Owen, Abramson, Will, Buchanan, William J.
Formato: Online Artículo Texto
Lenguaje:English
Publicado: MDPI 2022
Materias:
Acceso en línea:https://www.ncbi.nlm.nih.gov/pmc/articles/PMC9601302/
https://www.ncbi.nlm.nih.gov/pubmed/37420400
http://dx.doi.org/10.3390/e24101379
_version_ 1784817029854789632
author Ali, Hisham
Ahmad, Jawad
Jaroucheh, Zakwan
Papadopoulos, Pavlos
Pitropakis, Nikolaos
Lo, Owen
Abramson, Will
Buchanan, William J.
author_facet Ali, Hisham
Ahmad, Jawad
Jaroucheh, Zakwan
Papadopoulos, Pavlos
Pitropakis, Nikolaos
Lo, Owen
Abramson, Will
Buchanan, William J.
author_sort Ali, Hisham
collection PubMed
description Historically, threat information sharing has relied on manual modelling and centralised network systems, which can be inefficient, insecure, and prone to errors. Alternatively, private blockchains are now widely used to address these issues and improve overall organisational security. An organisation’s vulnerabilities to attacks might change over time. It is utterly important to find a balance among a current threat, the potential countermeasures, their consequences and costs, and the estimation of the overall risk that this provides to the organisation. For enhancing organisational security and automation, applying threat intelligence technology is critical for detecting, classifying, analysing, and sharing new cyberattack tactics. Trusted partner organisations can then share newly identified threats to improve their defensive capabilities against unknown attacks. On this basis, organisations can help reduce the risk of a cyberattack by providing access to past and current cybersecurity events through blockchain smart contracts and the Interplanetary File System (IPFS). The suggested combination of technologies can make organisational systems more reliable and secure, improving system automation and data quality. This paper outlines a privacy-preserving mechanism for threat information sharing in a trusted way. It proposes a reliable and secure architecture for data automation, quality, and traceability based on the Hyperledger Fabric private-permissioned distributed ledger technology and the MITRE ATT&CK threat intelligence framework. This methodology can also be applied to combat intellectual property theft and industrial espionage.
format Online
Article
Text
id pubmed-9601302
institution National Center for Biotechnology Information
language English
publishDate 2022
publisher MDPI
record_format MEDLINE/PubMed
spelling pubmed-96013022022-10-27 Trusted Threat Intelligence Sharing in Practice and Performance Benchmarking through the Hyperledger Fabric Platform Ali, Hisham Ahmad, Jawad Jaroucheh, Zakwan Papadopoulos, Pavlos Pitropakis, Nikolaos Lo, Owen Abramson, Will Buchanan, William J. Entropy (Basel) Article Historically, threat information sharing has relied on manual modelling and centralised network systems, which can be inefficient, insecure, and prone to errors. Alternatively, private blockchains are now widely used to address these issues and improve overall organisational security. An organisation’s vulnerabilities to attacks might change over time. It is utterly important to find a balance among a current threat, the potential countermeasures, their consequences and costs, and the estimation of the overall risk that this provides to the organisation. For enhancing organisational security and automation, applying threat intelligence technology is critical for detecting, classifying, analysing, and sharing new cyberattack tactics. Trusted partner organisations can then share newly identified threats to improve their defensive capabilities against unknown attacks. On this basis, organisations can help reduce the risk of a cyberattack by providing access to past and current cybersecurity events through blockchain smart contracts and the Interplanetary File System (IPFS). The suggested combination of technologies can make organisational systems more reliable and secure, improving system automation and data quality. This paper outlines a privacy-preserving mechanism for threat information sharing in a trusted way. It proposes a reliable and secure architecture for data automation, quality, and traceability based on the Hyperledger Fabric private-permissioned distributed ledger technology and the MITRE ATT&CK threat intelligence framework. This methodology can also be applied to combat intellectual property theft and industrial espionage. MDPI 2022-09-28 /pmc/articles/PMC9601302/ /pubmed/37420400 http://dx.doi.org/10.3390/e24101379 Text en © 2022 by the authors. https://creativecommons.org/licenses/by/4.0/Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (https://creativecommons.org/licenses/by/4.0/).
spellingShingle Article
Ali, Hisham
Ahmad, Jawad
Jaroucheh, Zakwan
Papadopoulos, Pavlos
Pitropakis, Nikolaos
Lo, Owen
Abramson, Will
Buchanan, William J.
Trusted Threat Intelligence Sharing in Practice and Performance Benchmarking through the Hyperledger Fabric Platform
title Trusted Threat Intelligence Sharing in Practice and Performance Benchmarking through the Hyperledger Fabric Platform
title_full Trusted Threat Intelligence Sharing in Practice and Performance Benchmarking through the Hyperledger Fabric Platform
title_fullStr Trusted Threat Intelligence Sharing in Practice and Performance Benchmarking through the Hyperledger Fabric Platform
title_full_unstemmed Trusted Threat Intelligence Sharing in Practice and Performance Benchmarking through the Hyperledger Fabric Platform
title_short Trusted Threat Intelligence Sharing in Practice and Performance Benchmarking through the Hyperledger Fabric Platform
title_sort trusted threat intelligence sharing in practice and performance benchmarking through the hyperledger fabric platform
topic Article
url https://www.ncbi.nlm.nih.gov/pmc/articles/PMC9601302/
https://www.ncbi.nlm.nih.gov/pubmed/37420400
http://dx.doi.org/10.3390/e24101379
work_keys_str_mv AT alihisham trustedthreatintelligencesharinginpracticeandperformancebenchmarkingthroughthehyperledgerfabricplatform
AT ahmadjawad trustedthreatintelligencesharinginpracticeandperformancebenchmarkingthroughthehyperledgerfabricplatform
AT jarouchehzakwan trustedthreatintelligencesharinginpracticeandperformancebenchmarkingthroughthehyperledgerfabricplatform
AT papadopoulospavlos trustedthreatintelligencesharinginpracticeandperformancebenchmarkingthroughthehyperledgerfabricplatform
AT pitropakisnikolaos trustedthreatintelligencesharinginpracticeandperformancebenchmarkingthroughthehyperledgerfabricplatform
AT loowen trustedthreatintelligencesharinginpracticeandperformancebenchmarkingthroughthehyperledgerfabricplatform
AT abramsonwill trustedthreatintelligencesharinginpracticeandperformancebenchmarkingthroughthehyperledgerfabricplatform
AT buchananwilliamj trustedthreatintelligencesharinginpracticeandperformancebenchmarkingthroughthehyperledgerfabricplatform