We introduce the Coverage Gap as a measurable distance between the observable public exposure of critical-infrastructure operators and their declared capability to coordinate vulnerability disclosure. We instantiate it against the 915 Chilean Operadores de Importancia Vital (OIVs -- Operators of Vital Importance) designated by the National Cybersecurity Agency (ANCI) under Ley 21.663 (Resolucion Exenta No. 87, 16 December 2025). Using a passive-only, OSINT-based method consistent with the principles of ISO/IEC 29147:2018 and Chile's computer-crimes safe harbour (Ley 21.459), we conduct a full-universe census of the foundational disclosure-capability layer (Layer 1, verifiable disclosure contact) across approximately 98.7% of the official catalogue. Only 16 of 915 OIVs (1.7%) publish a verifiable RFC 9116 disclosure channel; among operators of physical-world infrastructure -- energy, health, banking, telecommunications, fuel, water, transport, and state administration -- fewer than ten do so, and all four major banks and both telecommunications incumbents lack one entirely. This compares with over 99% adherence in the U.S. federal civilian branch under CISA Binding Operational Directive 18-01. Email-authentication misconfiguration affects 766 of 915 (84%) OIVs, and end-of-life or known-vulnerable stack components an estimated 23.5% (Wilson 95% CI [12%, 38%]). Cross-jurisdictional benchmarking situates Chile roughly eight years behind the USA, the UK, and the Netherlands on email-authentication mandates, and three years behind Denmark. We propose a four-stage roadmap modelled on BOD 18-01 and the UK Public-Sector DMARC Toolkit, and release the open-source tool anci-oiv-resolver (Apache 2.0) to enable independent reproduction of the OIV-domain mapping that underpins universe-scale auditing.


翻译:我们引入“覆盖缺口”这一概念,将其定义为关键基础设施运营者可观察的公众暴露程度与其所宣称的漏洞披露协调能力之间的可衡量差距。我们以智利国家网络安全局(ANCI)根据第21.663号法律(第87号豁免决议,2025年12月16日)指定的915家“关键重要性运营者”(OIVs)为实例进行验证。采用一种仅基于被动方法、符合ISO/IEC 29147:2018原则及智利计算机犯罪安全港(第21.459号法律)的开源情报(OSINT)方法,我们对基础披露能力层(第一层,可验证的披露联系人)进行了全量普查,覆盖了约98.7%的官方目录。在915家OIV中,仅有16家(1.7%)发布了可验证的RFC 9116披露渠道;在实体基础设施领域的运营者(能源、医疗、银行、电信、燃料、水务、交通及国家行政管理)中,少于10家做到这一点,而所有四大主要银行及两家现有电信运营商均完全缺失此类渠道。相比之下,根据网络安全和基础设施安全局(CISA)约束性操作指令18-01,美国联邦民事部门的合规率超过99%。电子邮件认证配置错误影响了915家OIV中的766家(84%),而使用生命周期终止或已知存在漏洞的堆栈组件的比例估计为23.5%(Wilson 95%置信区间[12%, 38%])。通过跨司法管辖区基准比较,智利在电子邮件认证强制要求方面落后于美国、英国和荷兰约八年,落后丹麦约三年。我们提出一个以BOD 18-01及英国公共部门DMARC工具包为蓝本的四阶段路线图,并发布开源工具anci-oiv-resolver(Apache 2.0许可证),以支持独立复现支撑全量审计规模的OIV域名映射。

0
下载
关闭预览

相关内容

美国国防工业网络保护框架和启示
专知会员服务
45+阅读 · 2022年8月22日
《网络拦截--博弈论方法》美国MITRE公司
专知会员服务
34+阅读 · 2022年8月19日
《人工智能安全测评白皮书》,99页pdf
专知
36+阅读 · 2022年2月26日
缺失数据统计分析,第三版,462页pdf
专知
50+阅读 · 2020年2月28日
艾瑞咨询2019中国智慧城市发展报告,附PPT下载
智能交通技术
25+阅读 · 2019年4月18日
【知识图谱】知识图谱+人工智能=新型网络信息体系
产业智能官
14+阅读 · 2018年11月18日
国家自然科学基金
4+阅读 · 2017年12月31日
国家自然科学基金
2+阅读 · 2017年12月31日
国家自然科学基金
18+阅读 · 2017年12月31日
国家自然科学基金
6+阅读 · 2017年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
5+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
4+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
Arxiv
0+阅读 · 6月10日
VIP会员
最新内容
分层反无人机系统发展新趋势
专知会员服务
7+阅读 · 9月3日
何为协作武器?
专知会员服务
10+阅读 · 9月1日
《理解认知战:超越信息》
专知会员服务
13+阅读 · 9月1日
美国战争部在GenAI.mil上推出OpenAI的ChatGPT Mil
专知会员服务
8+阅读 · 8月31日
人工智能赋能军事维护:重新定义国防战备
专知会员服务
5+阅读 · 8月31日
《美陆军野战手册(2026年):特种部队》
专知会员服务
9+阅读 · 8月31日
相关VIP内容
美国国防工业网络保护框架和启示
专知会员服务
45+阅读 · 2022年8月22日
《网络拦截--博弈论方法》美国MITRE公司
专知会员服务
34+阅读 · 2022年8月19日
相关基金
国家自然科学基金
4+阅读 · 2017年12月31日
国家自然科学基金
2+阅读 · 2017年12月31日
国家自然科学基金
18+阅读 · 2017年12月31日
国家自然科学基金
6+阅读 · 2017年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
5+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
4+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
Top
微信扫码咨询专知VIP会员