Loading...
Paper Type
Complete
Abstract
Cyber threat intelligence (CTI) sharing is widely regarded as essential for collective cyber defense; however, its effectiveness depends on fragile institutional incentives and timing, particularly concerning zero-day vulnerabilities. This paper conceptualizes CTI sharing as a dynamic interaction between attackers and defenders, shaped by information asymmetry, disclosure, and mitigation delays. Using a system dynamics approach, we develop and validate a state-based model of vulnerability lifecycles by reproducing empirical zero-day survival curves and historical Common Vulnerabilities and Exposures (CVE) disclosure patterns 0f two different datasets. Simulation results indicate that weakening centralized disclosure mechanisms significantly increases societal cyber risk, whereas improvements in secure-by-design practices, accelerated patching, and stronger disclosure incentives reduce vulnerability accumulation. The findings underscore CTI sharing as a critical public good and emphasize the dual role of artificial intelligence in amplifying both software risk and defensive capacity.
Paper Number
1520
Recommended Citation
Zeijlemaker, Sander; Pal, Ranjan; and Siegel, Michael, "A Systems Dynamics Approach to Understand Threat Intelligence Sharing" (2026). AMCIS 2026 Proceedings. 22.
https://aisel.aisnet.org/amcis2026/sig_sec/sig_sec/22
A Systems Dynamics Approach to Understand Threat Intelligence Sharing
Cyber threat intelligence (CTI) sharing is widely regarded as essential for collective cyber defense; however, its effectiveness depends on fragile institutional incentives and timing, particularly concerning zero-day vulnerabilities. This paper conceptualizes CTI sharing as a dynamic interaction between attackers and defenders, shaped by information asymmetry, disclosure, and mitigation delays. Using a system dynamics approach, we develop and validate a state-based model of vulnerability lifecycles by reproducing empirical zero-day survival curves and historical Common Vulnerabilities and Exposures (CVE) disclosure patterns 0f two different datasets. Simulation results indicate that weakening centralized disclosure mechanisms significantly increases societal cyber risk, whereas improvements in secure-by-design practices, accelerated patching, and stronger disclosure incentives reduce vulnerability accumulation. The findings underscore CTI sharing as a critical public good and emphasize the dual role of artificial intelligence in amplifying both software risk and defensive capacity.
When commenting on articles, please be friendly, welcoming, respectful and abide by the AIS eLibrary Discussion Thread Code of Conduct posted here.
Comments
SIG SEC