Understanding CSIRT Knowledge Management Needs Oscar Serrano 03 - - PowerPoint PPT Presentation

understanding csirt knowledge management needs
SMART_READER_LITE
LIVE PREVIEW

Understanding CSIRT Knowledge Management Needs Oscar Serrano 03 - - PowerPoint PPT Presentation

Understanding CSIRT Knowledge Management Needs Oscar Serrano 03 April 2013 15/04/2013 NATO UNCLASSIFIED 1 Disclaimer This work was sponsored by NATOs Allied Command Transformation under the 2012 Cyber Defence Programme of Work. This


slide-1
SLIDE 1

Oscar Serrano

03 April 2013

15/04/2013 NATO UNCLASSIFIED 1

Understanding CSIRT Knowledge Management Needs

slide-2
SLIDE 2

This work was sponsored by NATO’s Allied Command Transformation under the 2012 Cyber Defence Programme of Work. This document is a working paper that may not be cited as representing formally approved NCIA, ACT or NATO opinions, conclusions or recommendations, and represents the views of only the authors.

15/04/2013 NATO UNCLASSIFIED 2

Disclaimer

slide-3
SLIDE 3

15/04/2013 NATO UNCLASSIFIED 3

Introduction

Work on what you know best, and connect to the best of the rest

  • Cyber-Defence Data Exchange and

Collaboration Infrastructure

– Facilitate information sharing. – Enable automation. – Facilitate the generation, refinement and vetting

  • f data through burden-sharing collaboration or
  • utsourcing.
slide-4
SLIDE 4

15/04/2013 NATO UNCLASSIFIED 4

Introduction

Work on what you know best, and connect to the best of the rest

  • 11 High level Requirements
  • Comprehensive and sufficient list of CSIRT Knowledge

Management requirements

  • Validation
  • Discussion
slide-5
SLIDE 5

15/04/2013 NATO UNCLASSIFIED 5

CDXI High-Level Requirements

Work on what you know best, and connect to the best of the rest

Provide an adaptable, scalable, secure and decentralized infrastructure based

  • n a freely available core
slide-6
SLIDE 6

15/04/2013 NATO UNCLASSIFIED 6

CDXI High-Level Requirements

Work on what you know best, and connect to the best of the rest

Provide for the controlled evolution of the syntax and semantics of multiple independent data models and their correlation

slide-7
SLIDE 7

15/04/2013 NATO UNCLASSIFIED 7

CDXI High-Level Requirements

Work on what you know best, and connect to the best of the rest

Securely store both shared and private data

slide-8
SLIDE 8

15/04/2013 NATO UNCLASSIFIED 8

CDXI High-Level Requirements

Work on what you know best, and connect to the best of the rest

Provide for customizable, controlled multilateral sharing

slide-9
SLIDE 9

Enable the exchange of data across non- connected domains

15/04/2013 NATO UNCLASSIFIED 9

CDXI High-Level Requirements

Work on what you know best, and connect to the best of the rest

slide-10
SLIDE 10

15/04/2013 NATO UNCLASSIFIED 10

CDXI High-Level Requirements

Work on what you know best, and connect to the best of the rest

Provide human and machine interfaces

slide-11
SLIDE 11

15/04/2013 NATO UNCLASSIFIED 11

CDXI High-Level Requirements

Work on what you know best, and connect to the best of the rest

Provide collaborative tools that enable burden sharing for the generation, refinement, and vetting of data

slide-12
SLIDE 12

15/04/2013 NATO UNCLASSIFIED 12

CDXI High-Level Requirements

Work on what you know best, and connect to the best of the rest

Provide customizable quality-control processes

slide-13
SLIDE 13

15/04/2013 NATO UNCLASSIFIED 13

CDXI High-Level Requirements

Work on what you know best, and connect to the best of the rest

Expose dissension to reach consensus

slide-14
SLIDE 14

15/04/2013 NATO UNCLASSIFIED 14

CDXI High-Level Requirements

Work on what you know best, and connect to the best of the rest

Support continuous availability of data

slide-15
SLIDE 15

15/04/2013 NATO UNCLASSIFIED 15

CDXI High-Level Requirements

Work on what you know best, and connect to the best of the rest

Enable commercial activities

slide-16
SLIDE 16

15/04/2013 NATO UNCLASSIFIED 16

Integration with Other Data Sources

Data Sources Existing DB CDXI Data Sources CDXI

Internal

External CDXI

External

Automation

External Data Sources

slide-17
SLIDE 17

15/04/2013 NATO UNCLASSIFIED 17

Way Forward

  • Feedback
  • Validation of the capability

Questionnaire!

slide-18
SLIDE 18

15/04/2013 NATO UNCLASSIFIED 18

For those interested

  • Leave me your contact information
  • I can provide a copy of the capability definition
  • Paper will be published at the CyCon 2013 conference
  • Preparation of a workshop
slide-19
SLIDE 19

15/04/2013 NATO UNCLASSIFIED 19

Questions?

  • Can it be done?

– Yes, it is complex but think about no-SQL, multi-versioned data Bases, P2P Data Bases, research on Collaborative Data Sharing Systems.

  • It is going to be expensive/complex?

– Yes, but it is cheap compared to the cost of what is being done now (manual and semi-manual data management with limited effectiveness) and the cost of not doing anything (missed opportunities).

  • It would be simpler to …?

– You did not get it… we are not towards something simple, but towards something comprehensive and future-proof.

slide-20
SLIDE 20

15/04/2013 NATO UNCLASSIFIED 20

Back-up

slide-21
SLIDE 21
  • There are no mechanisms available to automate large-scale information

sharing.

  • Many different sources of data containing inconsistent and in some cases

erroneous data exist.

  • It is difficult, in some cases, to access the desired information from the large

volumes of data stored on the Internet or embedded in specific products (e.g. vulnerability repositories, signatures for anti-virus products, etc.).

  • Many protocols and access mechanisms are proprietary or not

interoperable.

  • Incompatible semantics using the same or similar words are used in

different data sources covering the same topics.

  • The quality of data varies and information and assurance regarding the level
  • f quality provided is lacking.
  • There is very limited support for efficient collaboration, despite the

availability of subject-matter experts in a large number of organizations willing to collaborate.

  • Concerns regarding the confidentiality of exchanged data in the absence of

means by which redistribution can be satisfactorily controlled must be addressed.

15/04/2013 NATO UNCLASSIFIED 21

Background