OASIS Open Mailing List Archives  ·  All Lists  ·  cti-taxii  ·  2015-08

cti-taxii — archive

[Date Prev]  |  [Thread Prev]  |  [Thread Next]  |  [Date Next]   —  [Date Index]  |  [Thread Index]  |  [Month Index]  |  [List Home]

RE: [cti-taxii] Query Use Cases Needed! - Privacy Preserving Data Sharing


Hi all, Sorry for the thread roll back - I've been thinking about the True/False use case, and I think there's an interesting avenue to explore here... Combined with this use case: https://github.com/TAXIIProject/TAXII-Specifications/wiki/TAXII-2.0-Use-Cases#government-wants-to-share-intel-but-no-one-to-know-it-was-them ...which is obviously close to my heart  : )  the True/False use case not only allows organisations to protect the 'who' but also potentially the 'what'. There's some great work going on in academia (eg: http://arxiv.org/pdf/1502.05337.pdf ) that investigates the concept of privacy preserving data sharing, allowing organisations to share potentially sensitive data with others without actually revealing what that data is (eg: storing an indicator in encrypted form, encrypting incoming indicators and comparing the cipher text to the stored indicator). The effect is similar to the True/False use case, but allows for a more peer-distributed set up. The advantage being that, when it's identified, the indicator is already shared. Those who work in a classified environment may appreciate the elegance of, what is effectively, automated parallel evidence procedures - it's almost like a massive game of CTF (which would, similarly, need to be really well locked down)! Governments (and other organisations with sensitive / classified data sources) are getting better at data sharing, but can always do more (us included). This might help remove some of the barriers. There's a nice by-product of this use case too (as described in the UCL paper linked above) that organisations can mathematically estimate the value of data sharing. Apart from just proving that sharing data is a good thing (some people still need to be reminded of that) it allows users to assess the 'value' of feeds based on how much they can tell the recipient that they don't already know / create links between objects / <insert your calculation of 'value' here>. With the anticipation of having more feeds than a user has processing power, this could allow them to prioritise feeds based on empirical evidence rather than reputation. Thoughts? This is something we're hoping to experiment with in CERT-UK against our Edge setup. If we can make that help the community then let me know! Cheers, Chris

[Date Prev]  |  [Thread Prev]  |  [Thread Next]  |  [Date Next]   —  [Date Index]  |  [Thread Index]  |  [Month Index]  |  [List Home]