Outi-Marja Latvala, Ivo Emanuilov, Tatu Niskanen, Pia Raitio, J. Salonen, Diogo Santos, K. Yordanova
{"title":"一种粒度事件管理信息共享方案的概念验证","authors":"Outi-Marja Latvala, Ivo Emanuilov, Tatu Niskanen, Pia Raitio, J. Salonen, Diogo Santos, K. Yordanova","doi":"10.1109/aiiot54504.2022.9817254","DOIUrl":null,"url":null,"abstract":"Trust is a key ingredient in collaboration between security operations centers (SOCs). The collaboration can enhance defense and preparedness against cyberattacks, but it is also important to limit the attacker's ability to infer their potential for success from the communication between SOCs. This paper presents a proof-of-concept for a granular information sharing scheme. The information about a security incident is encrypted and the SOCs can decide with great precision which users or user groups can access it. The information is presented in a web-based dasboard visualization, and a user can communicate with other SOCs in order to access relevant incident information.","PeriodicalId":409264,"journal":{"name":"2022 IEEE World AI IoT Congress (AIIoT)","volume":"33 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2022-06-06","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"Proof-of-Concept for a Granular Incident Management Information Sharing Scheme\",\"authors\":\"Outi-Marja Latvala, Ivo Emanuilov, Tatu Niskanen, Pia Raitio, J. Salonen, Diogo Santos, K. Yordanova\",\"doi\":\"10.1109/aiiot54504.2022.9817254\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Trust is a key ingredient in collaboration between security operations centers (SOCs). The collaboration can enhance defense and preparedness against cyberattacks, but it is also important to limit the attacker's ability to infer their potential for success from the communication between SOCs. This paper presents a proof-of-concept for a granular information sharing scheme. The information about a security incident is encrypted and the SOCs can decide with great precision which users or user groups can access it. The information is presented in a web-based dasboard visualization, and a user can communicate with other SOCs in order to access relevant incident information.\",\"PeriodicalId\":409264,\"journal\":{\"name\":\"2022 IEEE World AI IoT Congress (AIIoT)\",\"volume\":\"33 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2022-06-06\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2022 IEEE World AI IoT Congress (AIIoT)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/aiiot54504.2022.9817254\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2022 IEEE World AI IoT Congress (AIIoT)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/aiiot54504.2022.9817254","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
Proof-of-Concept for a Granular Incident Management Information Sharing Scheme
Trust is a key ingredient in collaboration between security operations centers (SOCs). The collaboration can enhance defense and preparedness against cyberattacks, but it is also important to limit the attacker's ability to infer their potential for success from the communication between SOCs. This paper presents a proof-of-concept for a granular information sharing scheme. The information about a security incident is encrypted and the SOCs can decide with great precision which users or user groups can access it. The information is presented in a web-based dasboard visualization, and a user can communicate with other SOCs in order to access relevant incident information.