90 likes | 201 Views
CERTs as effective Networks. Dr. Serge Droz serge.droz@switch.ch. Zürich, XX. July 2010. Factoids. CERTs (Computer Emergency Response Teams) are successful CERTs are increasingly taken as “the solution™” However … CERTs cannot solve all Problems (But hey, some really good!).
E N D
CERTs as effective Networks Dr. Serge Droz serge.droz@switch.ch Zürich, XX. July 2010
Factoids • CERTs (Computer Emergency Response Teams) are successful • CERTs are increasingly taken as “the solution™” However … • CERTs cannot solve all Problems (But hey, some really good!)
CERT-Theory: Network Governance 6. CRN Roundtable, Fall 2009: “Network Governance and the Role of Public-Private Partnerships in New Risks” In particular the contributions by Patrick Kenis and Erik-Hans Klijn Different types of governance: Market Hierachy Collaboration Network
2009 Nobel prize in Economy: Elinor Ostrom Governing the Commons Networks • Informal collaboration • Actors don’t necessarily have the same agenda • Come in different flavours • Need a clear goal • Need a high level of trust • Aren’t always easy to handle • Networks need a: • clear goal • high level of trust
Trust Brooker CERT Common Interest GroupFIRST, TF-CSIRT, .. CERT CERT Constituency AbuseDesk NOC Organisation Organisation CERT Computer Emergency Response Teams Goal: Fight internet crime Trust model: Trust relationship CERT
Example • Analyse Attacks CH-Banks • Inform Customer • Use the Net, Luke! • Other Countries are affected • Agree on next steps • Exchange Know-How • Prevent damage! • However, no arrests :-( … +konto.baaderbank.de +rentenbank.de +clientcenter.ikb.de +online-banking.eurohypo.com +customer.mysql.com +globenewswire.com +businesswire.com +marketwire.com +unionfinancieredefrance.fr +groupama.fr +afub.org +cpr-online.net +cpr-online.com +bcinet.nc …
Ingredients • Clear Goal: Prevent an attacker from succeeding • High level of Trust: Exchange of confidential info and agreement on common action • Technical Know-How: CERT specific • Networks need a: • clear goal • high level of trust
Open issues • CERTs do good stuff • But they don’t solve all the problems • Some Questions • Should CERTs be regulated? • By whom? • How could CERTs supplement other entities (LEO, ..) ? • Some Questions • How could CERTs supplement other entities (LEO, ..) ? • Where is the Missing Link? • + • Quick • Crossborader • Skilled • Neutral • - • No authority • No legal entity • Weak in formal processes