Upgrade to Pro — share decks privately, control downloads, hide ads and more …

Finding the Best Threat Intelligence Provider f...

Finding the Best Threat Intelligence Provider for a specific purpose - #trials and #tribulations

Identifying the "best" Threat Intelligence Provider for a specific purpose is quite difficult - for technical and organizational reasons.
We present some of the more annoying challenges encountered and share some of our results.

follow us on twitter: @lonelypeanut and @droecher

Dror-John Roecher

March 21, 2019
Tweet

Other Decks in Technology

Transcript

  1. NETWORK SECURITY MONITORING Customer A Network Sensor Network Sensor Network

    Sensor Our Backend Rule Engine
 (Yara, Suricata, Indicators) Analyst Workbench Customer B Network Sensor Network Sensor Network Sensor
  2. ‘Best’?! Labelling an IoC as ‘APT’ Setting up a controlled

    experiment Standardising the data Timestamps *sigh*
  3. ‘BEST’ FOR US Low False-Positive rate High quality context (targets,

    kill chain…) Quick to publish Expiry dates Machine readable … labelled data!
  4. ‘BEST’ FOR US Low False-Positive rate High quality context (targets,

    kill chain…) Quick to publish Expiry dates Machine readable … labelled data!
  5. CHALLENGE: WHAT MAKES AN IOC ‘APT’? Data: I need labels

    Security: It is not about the labels Data: I need labels
  6. Assumption: An IoC is considered ‘APT’ if there is a

    direct mention to an APT actor in its metadata.
  7. DATA FORMATS {…, info: ‘Charming Kitten 2017’} {…, info: ‘Charming

    Kittens’} {…, info: ‘Report XXX XXX’} {…, type: [threat- actor]} {…, actors: [FANCYBEAR]}
  8. FIRST SEEN ? time Infrastructure used by Threat Actor A

    Activities discovered
 by researcher B Indicators available
 to customers C
  9. DATA FORMATS {…, ‘date’: XXX, …} {…,{ {‘created_on’: XXX, 'last_valid_on':

    XXX, 'last_updated': XXX, ‘published_date': XXX, ‘created_date': XXX, 'last_valid_date': XXX, …}}
  10. RESULTS: GEOGRAPHIC FOCUS China Iran North Korea Russia Other Unknown

    Network Files Network Files China Iran North Korea Russia Other Unknown Vendor 2 Vendor 1 China Iran North Korea Russia Other Unknown Network Files Network Files
  11. Q&A

  12. CREDITS Photo by Asa Rodger on Unsplash Photo by Jamie

    Haughton on Unsplash Photo by Paolo Nicolello on Unsplash http://clipart-library.com/clipart/51476.htm http://clipart-library.com/clipart/310528.htm http://clipart-library.com/clipart/8TznLgpRc.htm http://clipart-library.com/clipart/99389.htm