Julian Waits – How to Extract Maximum Value From Your Threat Intelligence
This session offers best practices on how security teams can integrate cyberthreat intelligence into their organization (including the SOC, incident response, engineering, architecture, budgeting, planning and risk management functions) to reduce cyberrisks as part of an overall cybersecurity strategy.
Transcript
This is texturing TV. I'm very happy to be here with everyone that text wrong and cybersecurity live. And actually to his point.
Because we're talking about thread intelligence. I guess I need to start with some facts. most right intelligence programs fail and when I say most greater than 70% and I forget exactly which studies that have been done but several to just look at hey, how did it straight Intel thing work with our security program?
And and there's a reason for that I think and the reason is is you know cyber security like everything else is a book written by Simon sinek that I love where it says start with why? The number one issue and most Security Programs is people forget the purpose of cybersecurity which is a function of supporting your business or your mission that you're in. Often, you know, we become tankers we get the next tool we get more data.
This looks really cool. But we never map it back to the purpose of how do we really support the business and admission for the entity that we're serving and that's it. Let's just get through the agenda so we can talk about all of it.
I think it's just four of them. So we're gonna talk about today the current challenges and threat intelligence. And by the way, I'm happy to make this interactive.
I'm not good at talking this life. So somebody thinks I'm bullshiting or what I said wasn't true or you want to challenge me. Please feel welcome to do that.
So little challenges and threat intelligence how to collect red intelligence that's actionable keep performance indicators. And and how do we measure it whether it's effective or not? And then what's most key my belief about threat Intel is threat Intel in and of itself is worthless.
It's really how do I integrated into everything else that I'm doing inside of my my security program? Saluda current challenges and threat intelligence the first one before I go into slide is exactly what I said in my opening statement. forget threat intelligence forget Sims or seams forget all the different technologies that you will use and security if you don't start with an understanding of what risk means to your environment, whatever you do will fail.
period so organizations struggled to derive value from threat intelligence programs. We already said that. And why is that cyberpress continue to evolve at a rapid pace?
So in I'm not supposed to move. and 2015 and 2016 I ran an antivirus company called. Viper we were doing about on a 50 millionaire Revenue.
We had tons of customers and we were struggling to keep up with the threat landscape and specifically new threats and at that point in time there were maybe maybe four new families of malware a month And today's environment. They're now several hundred new families of malware a day. And I shouldn't just say malware but mail intent code that runs around on the internet.
So it just tells you how things have changed and how the pace continues to grow. again Security Programs are not optimized for thread Intel inputs. I think they're multiple reasons behind that start with why why are we doing this?
But then too is how do we most effectively use this to judge the risk in our environment? And then ref data is often not customized for for organizational organizational relevance. It's all saying the same thing what good is it for me to get all this data about things that are in my environment.
If I don't understand what risk is represented by various entities that are in my environment the applications that are used the the the various infrastructure platforms that I use what real risk, does it pose to my business or my mission and that allows me to then prioritize everything in my security program starting with how I'm going to use straight into but if you don't do that, then you just looking at a bunch of noise and maybe you get lucky every now and then And of course hardly anyone can never give an Roi for what they're doing in it right into our program. Let me just build all of these up. So oversighting a governance again mature Security Programs always start with kind of a business impact analysis.
If if I'm a retailer and tee, what's the thing that somebody's gonna want if I'm a retailer, they're gonna want this credit card information and personally identifiable information. I need to have defenses everywhere. I need to support defense and deaf, but that's my crown jewels.
I really make sure I need to make sure that stuff is really covered and then everything I do from a security perspective and my security is posture should Orient that way right common sense. You would think so, where's that governance? People so, you know true threat Hunters really understanding threat intelligence.
It's it's a science and an art and not everybody's designed to do it. It really takes very analytical thinking and someone who can think out of the box. And then, you know technology.
I would tell you that the biggest problem with with Fred and tell Technologies is not the technology themselves. Every threat platform vendor has an area that they emphasize with the data that they collect and again if you're not really thinking about your risk what it means to your business, how can you really pick the most effective one? They're working your environment do I get recorded future do I go with connectwise?
What do I get? And it really means understanding your risk first. So thought I had this built out.
Hmm and then most importantly I would tell you you seem or your sore but being able to correlate the data in such a way that it gives you the ding ding ding ding ding that there's a problem in the environment. very important I'm having a problem moving slides again. So this data was put together by Forester.
Can't move and I'm sorry and you can read it for yourselves. Right this this went out to I want to say over a thousand entities with more than a thousand employees in the company. You guys have a threat Intel program or if you do in your mature enough to do it.
What are the things that you're having issues with? Number one which which makes complete sense to me is the fact that they're host of new threats every day every hour. Complexity of the it environment is as Miss.
Minnelli said in her keynote when the biggest problems is what is on the network? What should be there more importantly what shouldn't be there? Detection Technologies are ineffective.
There's lots of reasons for that one. You need to hold us the vendors like rapid 7 more accountable. But two is you need to do your job too.
What are you trying to detecting for what purpose? Again, if you don't understand what the risk are to your business you will fail in cybersecurity program. and then keeping Up.
We see requirements. not such a big deal in the United States, but if you're in a multinational business and you're storing data about people in the UK and Europe in other places in the world, there's a host of regulations and laws that you can be breaking if not done properly and then you can read the rest for yourself, but the top four All very relevant to what you do in a day-to-day basis. so security Pros require multiple intelligence offerings I don't know if I agree with that statement, but let's look at what other people talked about.
cyber threat capabilities number one nonetheless cyber threat infrastructure number two compromise account data I would think that would be number one. Vulnerability intelligence definitely should be in the top five and Insider threat monitoring. Also from Forester does this data make sense to everyone?
So let's talk about how we collect it. Now there's really a rapid 7 thing. I've seen people talk about this with different models.
This is the way we see the world. You start with again. Why what's the direction in which I want to go with this program.
What am I trying to accomplish? What are the assets the people and the resources that I'm trying to protect and once I understand that what are the ttps that are most important to those things? Because I can't protect against everything.
So once I know what I want to collect then I start to collect that data. Then I process and analyze that data but when we say process and analyze I process and analyze the data against the threats and the risk that's represented in my environment. I disseminate that information which comes in two forms auditory people who do things or technologies that are automated automated to stop things.
and the process continues there's really three areas that you think about where this data is most important. Obviously for the folks in the security operations center your analysts. It's very tactical real-time very busy tons of noise.
How do I focus on the things that I'm most important? Operationally when I get a little more strategic it becomes you know, how should we be using this data? What's the type of algorithms?
We need to create against the data that the best folks is on the threats that are most important to our environment. And then ultimately how do I communicate that information to the board and to the executives that need to use it so we can all cooperate in this together. And again, when most times when you look at people talking about threat Intel.
The only way it rises to the Strategic level is if they spend enough money on it. But if they don't spend a lot of money on it, it usually stays tactical in the sock. Usually very, you know, haphazard and if you catch something, you're lucky it's not because you were looking for something.
specifically Wow. To drive that so what did we see or what he was going through? So let me correct.
The one thing though when I said spent money meaning if it's a large organization and all of a sudden it's a it's a six six figure number versus a 50K by it gets somebody's attention because it's a big dollar amount but to your point about how do you make it more important? I think it starts with having a very strong sense of that has the ear of at least the executive team, but certainly the board if possible. um, actually In a dinner that we did for this event one gentleman had mentioned that he's in a publicly traded company and the board opted that they didn't need a system.
So how important do you think threaten tell and protecting the environment is going to be in that environment? Because if you don't drive it down, it can never drive itself up. How do you either rise them up together or which going to be you know latch on to to get the best operational movement right show the best help the superior responses that perspective I see.
Students incredible well it but I would stay differently because I think the technology technology itself is an attribute of the culture. The real question is as the organization have a culture that understands how important Security is to the business. Have they move beyond the point where they see security as a cost center and he's now see it as a business enabler.
In those environments that are more mature than from the top down. It's understood that this is the way things have to happen. But unfortunately usually until somebody gets hit themselves or it's really close to home.
Even in this environment is not it's not a priority for the corporation. So I still think it starts with strong leadership. All right.
Next slide four qualities of actionable threat intelligence. Let's just build it out. If I knew this was a build I would have fixed it.
I apologize. So completeness accuracy relevance and timeliness and those all four. Absolutely correct in my book.
So one it must include inference that's necessary again to make a risk informed business decision the biggest fault and most threat Intel programs and the most Security Programs, especially thread Intel is everybody looks at all the data all the ttps everything that's coming in the environment without some reflection of what that data means to the risk in their environment meaning. So what if I find out that there's a set of ttps that are coming across the wires actively happening right now for technologies that I have in my environment, but those Technologies in no way shape or form represent a risk to my business while I still want to stop and it doesn't get the same priority or shouldn't get the same priority. It's something that I know can cost me money or cost my reputation in the market.
But if you look at everything with the same priority you wind up failing at everything. So risk-based business decision key. Accuracy must save to our more in success than it cost and wasted resources.
So I have a close friend. And I'll mention his name because he writes books on what it means to be a sister's name Gary haslip. And and Gary says something to me many years ago that I still live by and security environment.
These deal is as Julian if you don't make it faster or replace something that I have and make it more efficient. Why are you talking to me? Those are the two things.
He always looks for and that's again. Make it faster. It doesn't matter if it's necessarily cheaper, but if you can optimize the human so they can focus on the things that are more important.
Let's do that. Relevance again must address within the Orcs And the threat landscape again that matter to your business or to you know, if it's a military to your mission. You know threaded thread Intel handle the wrong way in the Army Air Force means somebody gets shot in the head.
And for most of our businesses, it means that we're in the Wall Street Journal in a way that we really didn't want to be. Right and then timeliness everything is security is about time with us. You know, if you go back to the miter attack framework, what stage are they at?
Because the question is not can I keep them out is how quickly can I stop them before it becomes material? That's the only thing that I didn't say that I usually do for shock value before we start all of this. We have to remember that cybersecurity protection.
is broken basically doesn't exist. Or we wouldn't be talking about threat in time. Now, how do you how do you measure this?
And I'm gonna I'm gonna offer up a little bit. This is Julian's view on it. There are other people who certainly disagree with me or have more things, but I think these are the core components to me a little build out the model that you can show others specifically business Executives and organization.
That this stuff actually matters. So, you know, let's let's start with with the easy stuff right IDs IPS alerts, of course that needs to be a component of what you're collecting and what you're what you're measuring against. Quarantine is affected.
I would tell you not just emails but also files. I mean if you know something as a known bat, even if it's not known bad to quote unquote the rest of the world that's just certainly going to list of things that that you need to stop. You know, a number of iocs, you're having an environment, but I would tell you again I separate iocs ilcs that are generic and denials that are specific to what I'm doing in a technologies that I have.
Number of reports that I've read about what's going on in the environment and a number of reports that were producing to help everybody understand what the threat landscape is and what we should be doing for our posture to protect ourselves. I think this is kind of the core set of things that are necessary to build a quantifiable program. So you got to measure incidents and when I say incidents I'm not talking about events.
To me an incident. It's something where I got an event in my environment and it's demonstrates to me that I'm either under attack. Meaning somebody's already attacked me or I'm highly vulnerable to attack and I need to resolve this right away.
Signal to noise ratio, you know the more you can cut down the noise and demonstrate here real things that are happening in environment that we can quantify to show that we stopped. That's a great thing. And more the most important thing out of all of this would any program is once you know that you're under attack being able to demonstrate here's when they started here's when everything began to happen.
Here's the things they did and here's what we stopped them. Making it quantifiable and it's it's not as hard to do as you would think as long as you have the right data feeds along with the threat Intel. And then the meantime the recover we caught him and here's what we did to resolve the situation.
The breaches is subjective if you can do it. If you do a real business impact analysis that can be done at some level. I was talking to someone last night about using Monte Carlo method around doing scenarios of attacks that can happen in your environment based on.
Revenue or market cap or something like that that you can measure against the performance of your business. And then the most important piece. so detection engineering threat hunting threat intelligence analysis of ventriage and incident response and again, It goes on and on and on.
So first in the Arsenal, and now we're specifically talking technology areas, right? So having a sore platform that can automate specifically to things that you know a problems in your environment and save the time of the humans who would normally do these tasks is extremely important. If you used effectively though most sores are not used effectively if you use the factory, you can probably eliminate 30 to 35% of the grunt work that stock analysts are doing an environment.
Having a same technology or Sim technology. I still say Sam but everybody still seen with content-based High Fidelity information is extremely important because that's the information that you're correlating against in your threat Intel feed to know when something's really important to you and have the right priority. Having the right endpoint technology High Fidelity.
I notice is bad. Stop it now moderate Fidelity. See I need to think about that a little bit and analyze it.
A malicious activity to employment and management how to using you know, if you open Social Hour rules or the EDR rules themselves are both in many cases the network because the easiest thing for security people always to complain about is the problems on the network obviously if it's High Fidelity if I have a IPS system, then you know, it needs to it needs to take it out before it goes any further moderate Fidelity at least flag it to say this is something that I should consider could be malicious activity and then of course being able to manage it obviously since I didn't want to be over prescriptive for Rapid 7 Technologies of suggesting snort is a technology to use and then vulnerability management, of course is according to any you know environment that you have how many times have we seen a breach that occurred sometimes in some very elegant ways but ultimately to reach was still made effective because somebody didn't patch up. almost all action So direction again, why am I doing this? What are the things that are a priority for me based on my bit the rest of my business again to my entity.
Collection. I want to single pane of glass especially for all the things that I know represent high risk to me. processing and Analysis I wish I could have done this slide again.
I wasn't thinking so I'm not a big fan of AI in detection. I am a big fan of AI in response. But you know the way I try and give the analogy to people that I drive a Tesla every day.
And I use full self-driving every day on the way to work and I Marvel. At how well the car is as long as it has lines. If it doesn't have lines, you're gonna die.
You gonna kill somebody too but as long as there's lines on the road and they can figure out where to get off and get on and it figures all this stuff with how to stay relative to other cars is absolutely amazing. What's even more amazing is the way Tesla's database of connected into the various systems that we have in the country to give real time updates about road construction that's happening and all this other stuff. I can see it all popping up on my screen and the car reacting to the information the key thing about that.
Yes, sir. Say to text. Where on the road where there are not lines and therefore turn off the auto drive now, that's why people keep dying.
He needs to fix that or gets through this up. yeah, if it sees the pothole but I got a lot of friends with Teslas here they seem to like it but in fact a new car from 17 Year old well, it's just a drive and it's not that not quite the same. Yeah.
Yeah, I graduate from that. Like I had a bunch of friends talk about it when I got the Tesla. Yeah after several rights, you know.
You know from Nissan all the way up to whatever. I wouldn't blown away. I was like wow, this is a Pocket yes night and day, right?
I think the car is safe for with Tesla than it is with the 17 Euro. That would be my answer but The purpose of all that is is guess what we know everything about the roads including when the roads change it all flies up on the screen. It's it's handed down through Satellite Systems.
It's all real time. That is not the truth in cybersecurity. things change continually if you walking around and you're thinking you're not compromised then you're just not smart.
Everybody in this room has been compromised in some way. The question is does that compromise lead to something that becomes material for me my business or other things that I'm associated with? So the fact that the security day the change is so off.
It means that I can't use AI. It has to be, you know machine models that are based on risk to my business. community And more fun.
Activities well thing is as you can absolutely do it depending on the EDR platform you have on the employee. You can absolutely build it also for whatever gonna quote in juice or do it outside of the network meaning looking at the activities and memory access again, it's all about how important it is it and what's the data that I'm going to Collective how what's going on in the environment? network is the easiest one because you see everything other than necessarily what they're doing if it's encrypted but on the endpoint, but I mean the truth about cybersecurity is cybersecurity begins and ends at the endpoint whether it's a server or end-user or Cloud infrastructure that's actually doing computer.
To me that's still an important. And then transition to automated remediation which is where I can use the AI there's tons of things that stock operators do every day that can be automated. Hey, look, I know this I'll see is bad there.
I'm sorry. apologize I know this ioc is bad. They're you know, Palo Alto next gen firewall shut this down before those anywhere.
All of that can be automated especially if it's a known bad and so again, probably 30% of what stock operators do if it's a really good risk based program with people understand what's important to the environment can be eliminated from the workload through Automation and using AI technology. Didn't start all over again. Come on work with me.
Thank you. And that was actually the last lot. Yes, sir.
I missed your opening you come up through signal Corps. So I have actually never served. I have but I have in the last 20 years of my life that half of that working with the US Military.
And they have fun with it. but I tried. Any other questions comments?
She took what was the question is? Well, thank you very much. And by the way wrap us out of the great company, we sell products and all these places.
I'd love for you to take a look at our website and buy something from us, but that's not why but I can.