Developing Security Reputation Metrics for Hosting Providers

نویسندگان

  • Arman Noroozian
  • Maciej Korczynski
  • Samaneh Tajalizadehkhoob
  • Michel van Eeten
چکیده

Research into cybercrime often points to concentrations of abuse at certain hosting providers. The implication is that these providers are worse in terms of security; some are considered ‘bad’ or even ‘bullet proof’. Remarkably little work exists on systematically comparing the security performance of providers. Existing metrics typically count instances of abuse and sometimes normalize these counts by taking into account the advertised address space of the provider. None of these attempts have worked through the serious methodological challenges that plague metric design. In this paper we present a systematic approach for metrics development and identify the main challenges: (i) identification of providers, (ii) abuse data coverage and quality, (iii) normalization, (iv) aggregation and (v) metric interpretation. We describe a pragmatic approach to deal with these challenges. In the process, we answer an urgent question posed to us by the Dutch police: ‘which are the worst providers in our jurisdiction?’. Notwithstanding their limitations, there is a clear need for security metrics for hosting providers in the fight against cybercrime.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Trust, Reputation and Quality of E-Banking Services (Case Study: Melli Bank Customers)

In today’s very competitive world gaining competitive advantage is bound to arranging products and services of companies and businesses in accordance with customers’ needs. For this purpose, gaining reputation in E-service can be quite helpful. Thus the goal of the present research is studying the effect of E-Banking Service Quality on Bank Reputation. So a coherent collection of structures wer...

متن کامل

Reputation Risk Management in the Framework of Enterprise Risk Management: Evidences from an Active Financial Institution in the Capital Market of Iran

Reputation risk as one of the most important risks in any competitive industry and market should be considered before all the risks of the enterprise which also affects other risks. This research aims to review and manage reputation risk in the framework of enterprise risk management. Considering the importance of the subject and lack of available studies in this field, the innovation of presen...

متن کامل

A Reputation System for Uncertain Assertions

We investigate reputation systems that rate the performance of analysts who make uncertain assertions (claims accompanied by estimated probabilities). Accuracy metrics (based on the fraction correct) are fair only if all analysts handle identical or statistically similar cases. Furthermore, accuracy metrics discourage analysts from offering predictions on difficult-to-predict events. Because of...

متن کامل

Rotten Apples or Bad Harvest? What We Are Measuring When We Are Measuring Abuse

Internet security and technology policy research regularly uses technical indicators of abuse in order to identify culprits and to tailor mitigation strategies. As a major obstacle, readily available data are often misaligned with actual information needs. They are subject to measurement errors relating to observation, aggregation, attribution, and various sources of heterogeneity. More precise...

متن کامل

SilverLine: Data and Network Isolation for Cloud Services

Although cloud computing service providers offer opportunities for improving the administration, reliability, and maintenance of hosted services, they also concentrate network resources and data in a small number of cloud service providers. The concentration of data and resources also entails various associated risks, including sharing the underlying infrastructure with unknown (and untrusted) ...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:
  • CoRR

دوره abs/1612.03641  شماره 

صفحات  -

تاریخ انتشار 2016