Over the last several years, there has been an emerging interest in the development of widearea data collection and analysis centers to help identify, track, and formulate responses to the ever-growing number of coordinated attacks and malware infections that plague computer networks worldwide. As large-scale network threats continue to evolve in sophistication and extend to widely deployed applications, we expect that interest in collaborative security monitoring infrastructures will continue to grow, because such attacks may not be easily diagnosed from a single point in the network. The intent of this position paper is not to argue the necessity of Internet-scale security data sharing infrastructures, as there is ample research [XN05, YBU03, SY05, VFS06, Spi05] and operational examples[Sym06, DSh06, myN06, YBP04] that already make this case. Instead, we observe that these well-intended activities raise a unique set of risks and challenges. We outline some of the most salient issues...
Phillip A. Porras, Vitaly Shmatikov