electricsheepafrica/africa-crypto-incident-history
收藏资源简介:
该数据集名为非洲加密事件历史,是Electric Sheep Africa发布的后量子密码暴露集群中的一部分,版本为v0.1。它专注于记录非洲数字基础设施中的加密相关事件历史,旨在为非洲特定证据提供支持,以证明国家行为体正在记录这些基础设施数据,并假设一旦量子计算机问世(根据NIST/NCSC/ENISA预测为2030-2035年),这些数据将可解密。数据集通过回答非洲数字基础设施中加密失败的历史记录显示了什么系统性风险?这一问题,来揭示风险。关键发现包括9个来源事件(2018-2025年),涵盖电信、银行和政府领域,并指出重复出现的弱点,如未经认证的SS7信令导致SIM卡交换,以及单一外国路由路径因电缆切割而暴露。数据集文件为ds6_incidents.csv,包含9行数据,列包括年份、国家代码、部门、类别、标题、加密相关性、来源和类别标签。方法涉及精心策划的来源事件种子,每个事件都注释了部门、类别、加密相关性和来源。数据来源包括公共报告、NIBSS欺诈报告、新闻和CERT公告。局限性在于这是v0.1种子版本,第二阶段将通过AfricaCERT/CERT-NG公告和CVE解析进行扩展,并非详尽的事件普查。数据集是非洲加密暴露与后量子风险集群中的八个数据集之一,其他数据集涵盖TLS部署、证书颁发机构依赖性、算法清单、海底电缆拓扑、IXP/路由暴露、监管差距、事件历史和PQC迁移成本。所有数据收集均为被动使用公开数据,或对公开可访问端点进行标准TLS握手,无拦截、利用或私人访问。
The dataset is named Africa Cryptographic Incident History, part of the Post-Quantum Cryptographic Exposure cluster by Electric Sheep Africa, version v0.1. It focuses on recording the history of cryptographic-related incidents in African digital infrastructure, aiming to provide Africa-specific evidence for the claim that state actors are recording this infrastructure today under the assumption it will be decryptable once quantum computers arrive (2030–2035 per NIST/NCSC/ENISA). The dataset addresses the question: What does the historical record of cryptographic failure in African digital infrastructure show about systemic risk? Key findings include 9 sourced incidents (2018–2025) spanning telco, banking, and government sectors, with recurring weaknesses such as unauthenticated SS7 signalling enabling SIM-swap, and single foreign-routed paths exposed by cable cuts. The data file is ds6_incidents.csv with 9 rows, containing columns like year, country_code, sector, category, title, crypto_relevance, source, and category_label. The method involves a curated, sourced seed of well-documented crypto-relevant incidents, each annotated with sector, category, cryptographic relevance, and source. Sources include public reporting, NIBSS fraud reports, press, and CERT advisories. Limitations note it is a v0.1 seed, with Phase-2 extending via AfricaCERT/CERT-NG advisory and CVE parsing, and it is not an exhaustive incident census. It is one of eight datasets in the African Cryptographic Exposure & Post-Quantum Risk cluster, covering TLS deployment, certificate-authority dependency, algorithm inventory, submarine cable topology, IXP/routing exposure, regulatory gap, incident history, and PQC migration cost. All collection is passive using public data or standard TLS handshakes against publicly reachable endpoints, with no interception, exploitation, or private access.




