SESSION ID: EZCL-R07 The Attribution Game: When Knowing Your Adversary Matters Katie Nickels Principal Intelligence Analyst, Red Canary #RSAC #RSAC Why We’re Here • What is our goal? – Better understand attribution and how we should handle it • How will we achieve it? – Gain this understanding by discussing with each other 2 #RSAC Agenda • • Frame Our Topic Ask Questions – Ask and answer questions as a large group • Dive Deeper – Discuss further in small groups • Share Our Takeaways – Provide read-outs from each small group to the large group • Wrap Up 3 #RSAC Frame Our Topic Let’s talk about attribution What Attribution Can Feel Like 5 #RSAC #RSAC What is Attribution? • • Associating adversary activity with something else Many different definitions → confusion 6 What are Different Types of Attribution? • We can attribute to… The “who” The “how” – A person – Tools/malware – A team or unit – Other code – An organization – Tactics, techniques, and procedures (TTPs) – A government – Infrastructure 7 #RSAC How Do We Perform Attribution? • • • • Find patterns and connections Look for human fingerprints – Personas, email addresses, passwords – Reusing account names (e.g. UglyGorilla) or infrastructure Use operational security failures by adversaries Leverage different sources depending on collection – – – HUMINT (human sources) SIGINT (intercepted communications) OSINT (news stories, WhoIs, Passive DNS, malware research) 8 #RSAC #RSAC Different Methods of Attribution • • Associate what you find with someone else’s research Create your own clusters https://www.fireeye.com/blog/threat-research/2019/03/clustering-andassociating-attacker-activity-at-scale.html https://www.activeresponse.org/wp-content/uploads/2013/07/diamond.pdf 9 #RSAC Does Attribution Matter? • • It depends on what you need: your requirements Sometimes it matters a lot – – Making business decisions Using instruments of power • • Diplomatic, Informational, Military, Economic Sometimes it matters less – – Defending networks Responding to incidents (what about red teams?) 10 #RSAC Ask Questions Ask and answer questions as a large group #RSAC Dive Deeper Discuss further in small groups Possible Discussion Questions • • • • • • How does your team define attribution? What are your key requirements for your cyber threat intelligence team? When does attribution matter to your team? When does it NOT matter? How does your team go about performing attribution? What limitations do you have in performing attribution? What additional collection or information could help you? How can we better communicate clearly about attribution? 13 #RSAC #RSAC Share Our Takeaways Provide read-outs from each small group to the large group #RSAC Wrap up Talk about how you can apply what you’ve learned Apply What You’ve Learned Today • • • Decide how your team defines attribution Identify your team’s requirements around attribution Determine how you will track adversaries given those requirements 16 #RSAC #RSAC Thank you! Katie Nickels Principal Intelligence Analyst, Red Canary @LiketheCoins @RedCanaryCo 17

pdf文档 2020_USA20_EZCL-R07_01_The-Attribution-Game-When-Knowing-Your-Adversary-Matters

安全研究库 > 国外研究报告 > 其它 > 文档预览
17 页 0 下载 40 浏览 0 评论 0 收藏 3.0分
温馨提示:如果当前文档出现乱码或未能正常浏览,请先下载原文档进行浏览。
2020_USA20_EZCL-R07_01_The-Attribution-Game-When-Knowing-Your-Adversary-Matters 第 1 页 2020_USA20_EZCL-R07_01_The-Attribution-Game-When-Knowing-Your-Adversary-Matters 第 2 页 2020_USA20_EZCL-R07_01_The-Attribution-Game-When-Knowing-Your-Adversary-Matters 第 3 页 2020_USA20_EZCL-R07_01_The-Attribution-Game-When-Knowing-Your-Adversary-Matters 第 4 页 2020_USA20_EZCL-R07_01_The-Attribution-Game-When-Knowing-Your-Adversary-Matters 第 5 页
下载文档到电脑,方便使用
还有 12 页可预览,继续阅读
本文档由 张玉竹2022-04-08 09:49:24上传分享
给文档打分
您好可以输入 255 个字符
安信天行文库的中文名是什么?( 答案:安信天行 )
评论列表
  • 暂时还没有评论,期待您的金玉良言