SESSION ID: AIR-W01 Intelligent Threat Intel ‘LEAD’ Framework Filip Stojkovski Threat Intel Manager Adobe #RSAC AIR-W01 Threat Intel - ‘LEAD’ Framework - 101 CTI (Cyber Threat Intelligence) pain points Efficiently and effectively solve the CTI problems. LEADing Threat Intelligence Program Threat Intel Pain Points LEAD CTI Framework Threat Intel Values Threat Intel Pain Points - Requirements No clear CTI Requirements = Time Bomb Source Ref: https://www.sans.org/reading-room/whitepapers/threats/paper/38790 AIR-W01 AIR-W01 Threat Intel Pain Points - Data Satisfaction with CTI Analytics Cleanliness and quality of data Context Comprehensiveness of coverage Automation and integration of CTI information with detection and response systems Location-based visibility Identification and removal of expired indicators of compromise (IoCs) and other old data Machine learning Source Ref: https://www.sans.org/reading-room/whitepapers/threats/paper/38790 Not Satisfied 34.3% 37.4% 35.4% 37.4% 39.4% 42.5% 47.6% 55.9% List of the biggest pain points for CTI The Threat Intel Problems AIR-W01 AIR-W01 The Non-Essential Problem MUST HAVE MUST HAVE MUST HAVE NICE TO HAVE MUST HAVE Ref: https://www.sans.org/reading-room/whitepapers/ActiveDefense/sliding-scale-cyber-security-36240 The Threat Intel Data AIR-W01 #RSAC Solving the CTI Problem AIR-W01 How To Solve The TI Problem RELEVANT EFFICIENT ANALYST DRIVEN DELIVERABLE AIR-W01 ‘LEAD’ Framework Structure RELEVANT Threat Profile + TI Program Requirements EFFICIENT TI Scoring + TI Categorization ANALYST DRIVEN Feedback Loop + Machine Learning DELIVERABLE Standardized TI Data + Metrics RELEVANT- Creating Threat Profile AIR-W01 RELEVANT – TI Program Requirements AIR-W01 AIR-W01 RELEVANT – Non-IR TI Consumers E-commerce (Fraudulent Payments) Code repositories (0-day exploits) Customer Content Moderation Piracy EFFICIENT - TI Scoring & Categorization Scoring >>> AIR-W01 <<< Categorization ANALYST DRIVEN - Feedback loop Automation Orchestration AIR-W01 ANALYST DRIVEN - Feedback loop & Machine Learning AIR-W01 ANALYST DRIVEN - Machine Learning Use-cases Dynamic TI Apply ML on Feedback Loop for automated scoring and categorization Data Mining Predict Adversary TTPs and Infrastructure AIR-W01 DELIVERABLE - Standardized Threat Intel Format AIR-W01 AIR-W01 DELIVERABLE - Metrics Actor Driven Actor Driven metrics will betray you on the long run. How and Where Start by how and where is used Threat Intelligence. Audience Tactical / Operational / Strategic #RSAC LEAD CTI Framework Key Takeaways

pdf文档 2020_USA20_AIR-W01_01_Intelligent-Threat-Intel-LEAD-Framework

安全研究库 > 国外研究报告 > 分析、情报和响应 > 文档预览
22 页 0 下载 28 浏览 0 评论 0 收藏 3.0分
温馨提示:如果当前文档出现乱码或未能正常浏览,请先下载原文档进行浏览。
2020_USA20_AIR-W01_01_Intelligent-Threat-Intel-LEAD-Framework 第 1 页 2020_USA20_AIR-W01_01_Intelligent-Threat-Intel-LEAD-Framework 第 2 页 2020_USA20_AIR-W01_01_Intelligent-Threat-Intel-LEAD-Framework 第 3 页 2020_USA20_AIR-W01_01_Intelligent-Threat-Intel-LEAD-Framework 第 4 页 2020_USA20_AIR-W01_01_Intelligent-Threat-Intel-LEAD-Framework 第 5 页
下载文档到电脑,方便使用
还有 17 页可预览,继续阅读
本文档由 张玉竹2022-04-08 09:41:41上传分享
给文档打分
您好可以输入 255 个字符
安信天行文库的中文名是什么?( 答案:安信天行 )
评论列表
  • 暂时还没有评论,期待您的金玉良言