Proposal for a new model for information sharing between CSIRTs
- Ir. David Durvaux - Security Analyst
Christian Van Heurck – Coordinator
Proposal for a new model for information sharing between CSIRTs Ir. - - PowerPoint PPT Presentation
Proposal for a new model for information sharing between CSIRTs Ir. David Durvaux - Security Analyst Christian Van Heurck Coordinator 24 th annual FIRST conference Malta - 17-22 June 2012 Knowledge is power . Knowledge shared is
Proposal for a new model for information sharing between CSIRTs
Christian Van Heurck – Coordinator
“ Knowledge is power . Knowledge shared is power multiplied.”
Robert Noyce
About CERT.be and us
Malta, 17-22 June 2012 Proposal for a new model for information sharing between CSIRTs 3The federal cyber emergency team
a service of Fedict
Agenda 1 Current situation 2 Proposal for a new model for sharing 3 New issues 4 Sharing time = Q&A
Malta, 17-22 June 2012 Proposal for a new model for information sharing between CSIRTs 4Propagation time
Internet
Propagation time: milliseconds
Malta, 17-22 June 2012 Proposal for a new model for information sharing between CSIRTs 6Internet
Propagation time:
Malta, 17-22 June 2012 Proposal for a new model for information sharing between CSIRTs 7Internet
Propagation time: back to milliseconds
Malta, 17-22 June 2012 Proposal for a new model for information sharing between CSIRTs 8Propagation time: back to seconds
Malta, 17-22 June 2012 Proposal for a new model for information sharing between CSIRTs 9We need to
more efficiently!
Information overflow
Lack of large-scale overview
Malta, 17-22 June 2012 Proposal for a new model for information sharing between CSIRTs 12Contact point issues
Whom
Malta, 17-22 June 2012 Proposal for a new model for information sharing between CSIRTs 13Criminals are organised and DO share
Malta, 17-22 June 2012 Proposal for a new model for information sharing between CSIRTs 14CSIRTs are like islands
Malta, 17-22 June 2012 Proposal for a new model for information sharing between CSIRTs 15Legal issues
Political issues
Malta, 17-22 June 2012 Proposal for a new model for information sharing between CSIRTs 17Technical issues
Malta, 17-22 June 2012 Proposal for a new model for information sharing between CSIRTs 18Proposal for a new model for sharing
Malta, 17-22 June 2012 Proposal for a new model for information sharing between CSIRTs 19Connecting our islands efficiently
Malta, 17-22 June 2012 Proposal for a new model for information sharing between CSIRTs 20Creating archipelagoes
Malta, 17-22 June 2012 Proposal for a new model for information sharing between CSIRTs 21already sharing
incidents?
Creating archipelagoes
Malta, 17-22 June 2012 Proposal for a new model for information sharing between CSIRTs 22since 1944
Creating archipelagoes
Malta, 17-22 June 2012 Proposal for a new model for information sharing between CSIRTs 23Seeds for archipelagoes
Decision tree
Malta, 17-22 June 2012 Proposal for a new model for information sharing between CSIRTs 25Political Support? Don’t Share Filter yes yes yes yes no no no no Event Legal? Need to Know? T
Share
Routing model: top-down
Malta, 17-22 June 2012 Proposal for a new model for information sharing between CSIRTs 26Archipelago Sub Archipelago Sub Sub Archipelago Concerned Constituent Event
Security is no longer an island!
Malta, 17-22 June 2012 Proposal for a new model for information sharing between CSIRTs 27Archipelago ABC Island A Island B Island C Island N Archipelago EF Island E Island F Island Z
How can we share?
Malta, 17-22 June 2012 Proposal for a new model for information sharing between CSIRTs 28Island A Island B Island C Jabber S2S Only Jabber S2S Only Jabber S2S Only events e v e n t s events
What can we share?
Tools already exist … for years!
AbuseHelper: the collaborative agents
Malta, 17-22 June 2012 Proposal for a new model for information sharing between CSIRTs 31?
♫ Notification Parser Agent Experts Reporting StorageMegatron: the central vacuum cleaner
Malta, 17-22 June 2012 Proposal for a new model for information sharing between CSIRTs 32fordrop: human collaboration
Malta, 17-22 June 2012 Proposal for a new model for information sharing between CSIRTs 33Correlated events: rating & feedback
Malta, 17-22 June 2012 Proposal for a new model for information sharing between CSIRTs 35Event B Event A Source A Source B
Processing
A Correlated Events Concerned Constituent
You can share too
Malta, 17-22 June 2012 Proposal for a new model for information sharing between CSIRTs 37Please
and help us do that
EFFICIENTLY
You are in good company
Malta, 17-22 June 2012 Proposal for a new model for information sharing between CSIRTs 38CERT .is
Sharing time!
Malta, 17-22 June 2012 Proposal for a new model for information sharing between CSIRTs 39david@cert.be christian@cert.be