Syngress Publishing How to Define and Build an Effective Cyber Threat Intelligence Capability (2015) by Unknown

Syngress Publishing How to Define and Build an Effective Cyber Threat Intelligence Capability (2015) by Unknown

Author:Unknown
Format: epub
Published: 0101-01-01T00:00:00+00:00


5.1. Illustration: translating the objective into concrete intelligence needs

Let us continue with concrete, tangible cases to make this as real as possible. For each of the examples above, if the objective is to prevent, identify, and investigate losses of sensitive internal data or intellectual property, then what are the actual mission activities carried out by the group of people who will sit in a room and do the actual work? And how does that list of activities translate into the actual intelligence needs (i.e., the “what” you need to develop or go out and buy)?

One activity might include understanding hacker and threat actor “TTPs” or tactics, techniques and procedures. How are they attacking other organizations? How did that recent breach in the news happen? How did they get into that organization? Who was responsible and what kinds of things do they commonly use to accomplish their goals? If gaining that knowledge is the required activity, then your intelligence need might be defined as a feed, content stream, education program, or other on-going service that educates your team about those threat actors and their TTPs.

Here is another aspect that might tie to this example. Suppose an activity that supports your mission is attempting to detect when data exfiltration is under way, or that a host on your network has been compromised. If that is a key activity, then what types of data could you use to support it so that you can in turn, generate intelligence? (You may recall that what many people sell as intelligence, by our definition, is not. But it may be the data you can turn into intelligence.) A vendor might offer a feed of IP addresses and domain names for current drop sites to which exfiltrated data is being transmitted. By taking that list of IPs and putting it into your infrastructure to prevent or monitor data egress, you now have something that can be applied to your organization, has potential business value, and produces an action or response. Thus, data from the vendor can actually become intelligence.

Another related activity you might define to support this mission is to detect or discover when sensitive data has already left the organization. One activity in support of this would be to scour the internet for internally sourced, or authored data, or documents, focusing in part on some of the sites and markets that are known to deal in such data, for example, PasteBin, Pastey, Pirate Pad, and the likes, hacker Internet Relay Chat (IRC) channels, and forums, document sharing sites like Scribed, Docstock, and Slideshare, or “leak” sites like OpenLeaks, Wikileaks. In this scenario, then, the activity is to monitor or check such sources for your own internal materials, and the data or intelligence need might be defined as a feed or service that automates or supports you by doing such searching or monitoring, gathering, screening, and delivering to you any sensitive materials that appear in these forums.

So to summarize, if, for example, the objective is to prevent



Download



Copyright Disclaimer:
This site does not store any files on its server. We only index and link to content provided by other sites. Please contact the content providers to delete copyright contents if any and email us, we'll remove relevant links or contents immediately.
Popular ebooks
Eco-friendly approach of bio-indigo synthesis and developing purification methods towards isolation of indigo from indirubin and bacterial fragments by Ramalingam Manivannan & Kaliyan Prabakaran & Young-A Son(217499)
Personalized inhaled bacteriophage therapy for treatment of multidrug-resistant Pseudomonas aeruginosa in cystic fibrosis by unknow(185991)
CONSORT 2025 statement: updated guideline for reporting randomized trials by unknow(94357)
Critical evaluation of the ProfiLER-02 study design and outcomes by Vivek Subbiah & Razelle Kurzrock(94165)
Cardiac gene therapy makes a comeback by Oliver J. Müller & Susanne Hille & Anca Kliesow Remes(93799)
Whisky: Malt Whiskies of Scotland (Collins Little Books) by dominic roskrow(74474)
Unveiling the design rules for tunable emission in graphene quantum dots: A high-throughput TDDFT and machine learning perspective by Şener Özönder & Mustafa Coşkun Özdemir & Caner Ünlü(50916)
A yeast-based oral therapeutic delivers immune checkpoint inhibitors to reduce intestinal tumor burden by unknow(40300)
Covalent hitchhikers guide proteins to the nucleus by Alexander F. Russell & Madeline F. Currie & Champak Chatterjee(40237)
Meet the Authors: Christopher R. Mansfield and Emily R. Derbyshire by Christopher R. Mansfield & Emily R. Derbyshire(40124)
Alkaline-earth metals promote propane dehydrogenation with carbon dioxide through geometric effects: Altering the reaction pathway by unknow(32762)
Induced iron vacancies boosting FeOOH loaded on sustainable Fenton-like collagen fiber membrane for efficient removal of emerging contaminants by unknow(32544)
Efficient electric-field-assisted photochemical conversion of methane to n-propanol exclusively over penetrated TiO2Ti hollow fibers by Guanghui Feng(32476)
Bi2SiO5 nanosheets as piezo-photocatalyst for efficient degradation of 2,4-Dichlorophenol by Hangyu Shi & Yifu Li & Lishan Zhang & Guoguan Liu & Qian Zhang & Xuan Ru & Shan Zhong(32415)
A novel NDIPTA organic heterojunction photocatalyst with built-in electric field for efficient hydrogen production by Jiahui Yang & Baojun Ma & Yongfa Zhu(32390)
Enhanced conversion of methane to liquid-phase oxygenates via hollow ferrite nanotube@horseradish peroxidase based photoenzymatic catalysis by Jun Duan & Shiying Fan & Xinyong Li & Shaomin Liu(32353)
Ordered macroporous superstructure of defective carbon adorned with tiny cobalt sulfide for selective electrocatalytic hydrogenation of cinnamaldehyde by Xiao-Shi Yuan & Sheng-Hua Zhou & San-Mei Wang & Wenbo Wei & Xiaofang Li & Xin-Tao Wu & Qi-Long Zhu(32275)
What's Done in Darkness by Kayla Perrin(27168)
Topological analysis of non-conjugated ethylene oxide cored dendrimers decorated with tetraphenylethylene: Insights from degree-based descriptors using the polynomial approach by A Theertha Nair & D Antony Xavier & Annmaria Baby & S Akhila(26557)
Investigation of mechanical and self-healing properties of hydroxyl-terminated polybutadiene functionalized with 2-ureido-4-pyrimidinone by Mohsen Kazazi & Mehran Hayaty & Ali Mousaviazar(26491)