the governance of internet security › activities › tf-csirt › meeting25 › ...studies on the...

17
the governance of internet security a starting research project andreas schmidt vienna, tf-cert, 25.9.08

Upload: others

Post on 07-Jul-2020

1 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: the governance of internet security › activities › tf-csirt › meeting25 › ...studies on the “economics of malware”, “the governance of cybersecurity” • ties to ISPs

the governance of internet security

a starting research projectandreas schmidt

vienna, tf-cert, 25.9.08

Page 2: the governance of internet security › activities › tf-csirt › meeting25 › ...studies on the “economics of malware”, “the governance of cybersecurity” • ties to ISPs

meresearcher at TU Delft since 1.9.08

experience: sw dev; consulting ICT service industry; service mgt, project mgt; org. aspects of security in IT operations

education: M.A. polsci/hist, focus on role of ICT in IR

Page 3: the governance of internet security › activities › tf-csirt › meeting25 › ...studies on the “economics of malware”, “the governance of cybersecurity” • ties to ISPs

me.residingAtDelft: between The Hague (8 km) and Rotterdam (15 km) and the Sea (15 km); 120.00 inhabitants

TU Delft: 16.000 students, staff of some 4.400 fte (2600 scientific, roughly 1000 PhDs)

TPM: Faculty of Technology, Policy and Managment, some 1000 students

Page 4: the governance of internet security › activities › tf-csirt › meeting25 › ...studies on the “economics of malware”, “the governance of cybersecurity” • ties to ISPs

me.supervisor

• Milton Mueller

• prof @ school of info studies, syracuse, US

• xs4all prof @ tudelft

• internet governance project, ICANN, WSIS

• communication technologies and global governance institutions

Page 5: the governance of internet security › activities › tf-csirt › meeting25 › ...studies on the “economics of malware”, “the governance of cybersecurity” • ties to ISPs

me.workingWith

• Michel van Eeten

• assoc. prof @ TU Delft, Faculty of TPM

• focus on reliability and security of crit infra, studies on the “economics of malware”, “the governance of cybersecurity”

• ties to ISPs via production of study on Internet security for OECD

Page 6: the governance of internet security › activities › tf-csirt › meeting25 › ...studies on the “economics of malware”, “the governance of cybersecurity” • ties to ISPs

research.question

Which international institutions and organizational forms are developing in response to security problems on the Internet?

Page 7: the governance of internet security › activities › tf-csirt › meeting25 › ...studies on the “economics of malware”, “the governance of cybersecurity” • ties to ISPs

research.field

Which international institutions and organizational forms are developing in response to security problems on the Internet?

spambotnetphishingvirusesDoSstate-sponsoredattacks

UN, Nato, EU, OECDENISA, ITUCERTs, NANOG, LAG, APWGLaw enforcementnorms & standards

hierarchiesmarketsnetworks

status quocurrent devolopmentsgeneralizations / options

Page 8: the governance of internet security › activities › tf-csirt › meeting25 › ...studies on the “economics of malware”, “the governance of cybersecurity” • ties to ISPs

a network of expertsWhich international institutions and organizational forms are developing in response to security problems on the Internet?

spam, botnet, phishing, viruses, DoS, state-sponsored, attacks

UN, Nato, EU, OECD, ENISA,

ITU, CERTs, NANOG,

LAG, APWG, Law enforcement, norms & standards

hierarchiesmarkets

networks

status quocurrent devolopments

generalizations / options

„network form of organisation“ (Powell 1990)

rationale for networks: knowledge, speed, trust

operational execution of internet security by a network of experts

ISPsSW vendos

CERTsIT deps

discussion forums

Page 9: the governance of internet security › activities › tf-csirt › meeting25 › ...studies on the “economics of malware”, “the governance of cybersecurity” • ties to ISPs

forms of organizing security

Which institutions and organizational forms are developing in response to security problems?

territorial threats, street riots, food security issues, etc.

UN, DoD, DHS, Nato, EU,Law

enforcement, norms & standards

hierarchiesmarketsnetworks

status quocurrent devolopmentsgeneralizations / options

Is the network of internet security experts a transnational institutional innovation?

Do loose security networks function as substitutes or supplementaries to formal institutions?

Page 10: the governance of internet security › activities › tf-csirt › meeting25 › ...studies on the “economics of malware”, “the governance of cybersecurity” • ties to ISPs

analyzing a network of experts

operations, processes, communications

products

internal rules

external relations

ISPsSW vendos

CERTsIT deps

discussion forums

Which international institutions and organizational forms are developing in response to security problems on the Internet?

Page 11: the governance of internet security › activities › tf-csirt › meeting25 › ...studies on the “economics of malware”, “the governance of cybersecurity” • ties to ISPs

community.processes

• mutual requests

• intra/inter-organizational incident management

• relationship between community and corporates‘ internal business processes

• communications

• activites

Page 12: the governance of internet security › activities › tf-csirt › meeting25 › ...studies on the “economics of malware”, “the governance of cybersecurity” • ties to ISPs

community.products

• fixingPhishing

• fixingSpambots

• fixingBotnets

• LESupportAntiterror

• LESupportAntichildporn

• LESupportAntiporn

• InformationExchange

• Training

• …

Page 13: the governance of internet security › activities › tf-csirt › meeting25 › ...studies on the “economics of malware”, “the governance of cybersecurity” • ties to ISPs

community.internals

• norms, priciples, values

• members / participants

Page 14: the governance of internet security › activities › tf-csirt › meeting25 › ...studies on the “economics of malware”, “the governance of cybersecurity” • ties to ISPs

community.externalrelations

• to CIP community

• to regulators

• to law enforcements

Page 15: the governance of internet security › activities › tf-csirt › meeting25 › ...studies on the “economics of malware”, “the governance of cybersecurity” • ties to ISPs

research.methods

• qualitative interviews

• participatory oberservations

Page 16: the governance of internet security › activities › tf-csirt › meeting25 › ...studies on the “economics of malware”, “the governance of cybersecurity” • ties to ISPs

research.goals

• understanding factors that support the role of networks-of-experts within an institutional setting that includes stake-claiming hierarchical organisations

• understanding links, collaboration and communication between networks of experts and more hierachically organized institutions

• check some social scientific theories/models with networks of experts as case studies