Collaborative Cyber Threat Intelligence: Detecting and Responding to Advanced Cyber Attacks at the National Level by Florian Skopik

Collaborative Cyber Threat Intelligence: Detecting and Responding to Advanced Cyber Attacks at the National Level by Florian Skopik

Author:Florian Skopik
Language: eng
Format: azw3, pdf
Publisher: CRC Press
Published: 2017-10-16T04:00:00+00:00


Figure 5.7 Simple schematic of NDN architecture.

Concerning the latter, both target groups have similar (browser-based) web access to their respective MISP environments. Specialists in the respective partner organizations can use this channel to log on to the appropriate MISP instantiation and review the threat information that is in store. On top of this, NDN encompasses specific technical interfaces that facilitate automation. Here the following applies:

The platform for private partners is equipped with an API32 through which native security solutions can be integrated with the NDN’s threat information feed. Partners can for instance use this to automatically feed detection signatures into their SIEM solutions, similar to the setup seen in the telco community (see previous section). The extent to which such integration is indeed established is currently left at the discretion of each partner.

The MISP instance maintained for government bodies can interface directly with IDS sensors in governmental ICT networks. These sensors are offered by the NCSC but installed and maintained by the government agencies themselves. They interact with the NCSC’s MISP environment (see Figure 5.7) on a bidirectional basis. Specifically, IDS sensors are automatically fed with detection signatures (deduced from threat information), and the IDS reports so called “sightings” (i.e., actual “hits” on a particular threat indicator) back to the centralized CTI platform. Such “sightings” alert the NCSC of potential incidents and strengthen its overall situational awareness.

This differentiated setup stems from the fact that the NCSC is itself part of the national government, and as such is considered the same legal entity as other government bodies.33 Having said this, the NCSC would like to extend the NDN with threat information (voluntarily) supplied by private partners. The aforementioned API was in fact already prepared for such collection. At present, however, the interaction with private partners is largely one-way. This will be addressed further in the “lessons learned” section.

Participation in NDN is strictly voluntary, for both private organizations and the government. In its daily practice, NDN is operated by a dedicated team of analysts. For governance purposes, the community established a formal steering committee comprised of the NCSC itself and a selection of public and private partners. This steering committee serves to govern the NDN road map (e.g., platform functionality, member expansion) and resolve any operational or organizational issues.



Download



Copyright Disclaimer:
This site does not store any files on its server. We only index and link to content provided by other sites. Please contact the content providers to delete copyright contents if any and email us, we'll remove relevant links or contents immediately.
Popular ebooks
Eco-friendly approach of bio-indigo synthesis and developing purification methods towards isolation of indigo from indirubin and bacterial fragments by Ramalingam Manivannan & Kaliyan Prabakaran & Young-A Son(217316)
Personalized inhaled bacteriophage therapy for treatment of multidrug-resistant Pseudomonas aeruginosa in cystic fibrosis by unknow(185824)
CONSORT 2025 statement: updated guideline for reporting randomized trials by unknow(94156)
Critical evaluation of the ProfiLER-02 study design and outcomes by Vivek Subbiah & Razelle Kurzrock(93962)
Cardiac gene therapy makes a comeback by Oliver J. Müller & Susanne Hille & Anca Kliesow Remes(93573)
Whisky: Malt Whiskies of Scotland (Collins Little Books) by dominic roskrow(74473)
Unveiling the design rules for tunable emission in graphene quantum dots: A high-throughput TDDFT and machine learning perspective by Şener Özönder & Mustafa Coşkun Özdemir & Caner Ünlü(50916)
A yeast-based oral therapeutic delivers immune checkpoint inhibitors to reduce intestinal tumor burden by unknow(40299)
Covalent hitchhikers guide proteins to the nucleus by Alexander F. Russell & Madeline F. Currie & Champak Chatterjee(40237)
Meet the Authors: Christopher R. Mansfield and Emily R. Derbyshire by Christopher R. Mansfield & Emily R. Derbyshire(40124)
Alkaline-earth metals promote propane dehydrogenation with carbon dioxide through geometric effects: Altering the reaction pathway by unknow(32761)
Induced iron vacancies boosting FeOOH loaded on sustainable Fenton-like collagen fiber membrane for efficient removal of emerging contaminants by unknow(32544)
Efficient electric-field-assisted photochemical conversion of methane to n-propanol exclusively over penetrated TiO2Ti hollow fibers by Guanghui Feng(32476)
Bi2SiO5 nanosheets as piezo-photocatalyst for efficient degradation of 2,4-Dichlorophenol by Hangyu Shi & Yifu Li & Lishan Zhang & Guoguan Liu & Qian Zhang & Xuan Ru & Shan Zhong(32415)
A novel NDIPTA organic heterojunction photocatalyst with built-in electric field for efficient hydrogen production by Jiahui Yang & Baojun Ma & Yongfa Zhu(32387)
Enhanced conversion of methane to liquid-phase oxygenates via hollow ferrite nanotube@horseradish peroxidase based photoenzymatic catalysis by Jun Duan & Shiying Fan & Xinyong Li & Shaomin Liu(32353)
Ordered macroporous superstructure of defective carbon adorned with tiny cobalt sulfide for selective electrocatalytic hydrogenation of cinnamaldehyde by Xiao-Shi Yuan & Sheng-Hua Zhou & San-Mei Wang & Wenbo Wei & Xiaofang Li & Xin-Tao Wu & Qi-Long Zhu(32275)
What's Done in Darkness by Kayla Perrin(27168)
Topological analysis of non-conjugated ethylene oxide cored dendrimers decorated with tetraphenylethylene: Insights from degree-based descriptors using the polynomial approach by A Theertha Nair & D Antony Xavier & Annmaria Baby & S Akhila(26557)
Investigation of mechanical and self-healing properties of hydroxyl-terminated polybutadiene functionalized with 2-ureido-4-pyrimidinone by Mohsen Kazazi & Mehran Hayaty & Ali Mousaviazar(26491)