Visible to the public A Model for Secure and Mutually Beneficial Software Vulnerability Sharing

TitleA Model for Secure and Mutually Beneficial Software Vulnerability Sharing
Publication TypeConference Paper
Year of Publication2016
AuthorsDavidson, Alex, Fenn, Gregory, Cid, Carlos
Conference NameProceedings of the 2016 ACM on Workshop on Information Sharing and Collaborative Security
PublisherACM
Conference LocationNew York, NY, USA
ISBN Number978-1-4503-4565-1
KeywordsCollaboration, composability, Human Behavior, information sharing, information theoretic security, Metrics, private set operations, pubcrawl, Resiliency, Scalability, secure multiparty computation, security economics
Abstract

In this work we propose a model for conducting efficient and mutually beneficial information sharing between two competing entities, focusing specifically on software vulnerability sharing. We extend the two-stage game-theoretic model proposed by Khouzani et al. [18] for bug sharing, addressing two key features: we allow security information to be associated with different categories and severities, but also remove a large proportion of player homogeneity assumptions the previous work makes. We then analyse how these added degrees of realism affect the trading dynamics of the game. Secondly, we develop a new private set operation (PSO) protocol that enables the removal of the trusted mediation requirement. The PSO functionality allows for bilateral trading between the two entities up to a mutually agreed threshold on the value of information shared, keeping all other input information secret. The protocol scales linearly with set sizes and we give an implementation that establishes the practicality of the design for varying input parameters. The resulting model and protocol provide a framework for practical and secure information sharing between competing entities.

URLhttp://doi.acm.org/10.1145/2994539.2994547
DOI10.1145/2994539.2994547
Citation Keydavidson_model_2016