Build the right Threat Intelligence Team
-
Upload
james-dietle -
Category
Technology
-
view
200 -
download
0
Transcript of Build the right Threat Intelligence Team
You need to develop people to have an
understanding of how bad guys operate to protect your friends, family, and company.
Intelligence is:
Information used to make a decision.
Threat Intelligence is:
Information about adversaries which is used
to make a decision.
Information Received
Info
Info
Analyst
Information
Decision
Decision
Decision
IntelligenceAnalyst
Feed
Information Received
Info
Info
Analyst
Information
Decision
Decision
Decision
IntelligenceAnalyst
Feed
In the past information was expensive
Now information is cheap
Where can we get it?• Open source• Proprietary Feeds• Social Media sites• Twitter• Researcher Sites• You-Tube• Podcasts• Special Sites• Deep Web
Threat Actors
• Hacktivists• Criminals• Insider threats• Competitors• Advanced Persistent Threats (APT)
Indicators/Pyramid of Pain
Information Received
Info
Info
Analyst
Information
Decision
Decision
Decision
IntelligenceAnalyst
Feed
What makes intel good or bad?
• Actionable: Can make a decision with it?• Certainty: How likely it is to happen?• Timeliness: Can we mitigate damage?
Good!
Bad!
Know yourself, Optimize the info
Qualitative– The network is safe– The sky is blue– Bueller is a righteous dude
Quantitative– Missing 9 2 days of class– 28 Incidents last year– Saved $100 of recovery for every
dollar on security
LVL Plan Personnel Increased Spending
Additional Benefit
1 No Plan IT professionals
2 No Plan + Dedicated Security
3 Simple Plan
+ experienced Security
4 Better Plan
+ dedicated intel analyst
5 Amazing Plan
+ dedicated intel team
Finding the right people• Build internally– Look for passionate employees– First line of defense
• Hire experienced people– Look early
• Hire Vendors– Check their work
Train people• Security Conferences• Meet-ups• Hands on experience• Training/Certifications• Online training• Vendors
Function
Device
No Separation
Time
Help desk Security Architecture Application
Information Received
Info
Info
Analyst
Information
Decision
Decision
Decision
IntelligenceAnalyst
Feed
Distribution of your good intel
• To your peers!• Personal Visits/Talks• Email• Texts• Pamphlets• Distribution lists• Taxii/STIX
Which Intel to action
Incident Response• Responders are the best people to give
intelligence to and be close friends with. • They are closest to the action and are most
likely to benefit from it. • Refine feeds
War Gaming
Information Received
Info
Info
Analyst
Information
Decision
Decision
Decision
IntelligenceAnalyst
Feed