Loading...

Media is loading
 

Paper Type

Complete

Abstract

Cyber threat intelligence (CTI) sharing is widely regarded as essential for collective cyber defense; however, its effectiveness depends on fragile institutional incentives and timing, particularly concerning zero-day vulnerabilities. This paper conceptualizes CTI sharing as a dynamic interaction between attackers and defenders, shaped by information asymmetry, disclosure, and mitigation delays. Using a system dynamics approach, we develop and validate a state-based model of vulnerability lifecycles by reproducing empirical zero-day survival curves and historical Common Vulnerabilities and Exposures (CVE) disclosure patterns 0f two different datasets. Simulation results indicate that weakening centralized disclosure mechanisms significantly increases societal cyber risk, whereas improvements in secure-by-design practices, accelerated patching, and stronger disclosure incentives reduce vulnerability accumulation. The findings underscore CTI sharing as a critical public good and emphasize the dual role of artificial intelligence in amplifying both software risk and defensive capacity.

Paper Number

1520

Comments

SIG SEC

Share

COinS
 
Aug 15th, 12:00 AM

A Systems Dynamics Approach to Understand Threat Intelligence Sharing

Cyber threat intelligence (CTI) sharing is widely regarded as essential for collective cyber defense; however, its effectiveness depends on fragile institutional incentives and timing, particularly concerning zero-day vulnerabilities. This paper conceptualizes CTI sharing as a dynamic interaction between attackers and defenders, shaped by information asymmetry, disclosure, and mitigation delays. Using a system dynamics approach, we develop and validate a state-based model of vulnerability lifecycles by reproducing empirical zero-day survival curves and historical Common Vulnerabilities and Exposures (CVE) disclosure patterns 0f two different datasets. Simulation results indicate that weakening centralized disclosure mechanisms significantly increases societal cyber risk, whereas improvements in secure-by-design practices, accelerated patching, and stronger disclosure incentives reduce vulnerability accumulation. The findings underscore CTI sharing as a critical public good and emphasize the dual role of artificial intelligence in amplifying both software risk and defensive capacity.

When commenting on articles, please be friendly, welcoming, respectful and abide by the AIS eLibrary Discussion Thread Code of Conduct posted here.