How to Use OSINT for Smarter Cyber Defense

429 views
•
August 5, 2019
by
RSAC Cybersecurity
YouTube video player
How to Use OSINT for Smarter Cyber Defense

TL;DR

Open source intelligence helps cybersecurity teams identify threats faster by legally collecting and analyzing publicly available information for a defined purpose. A methodical cycle of planning, collection, processing, analysis, and reporting turns vast online data into useful intelligence, while tools such as Shodan and URLScan can accelerate reconnaissance and support risk-centered defense.

Transcript

Um, so good afternoon. Thank you all for coming back. Uh, I think that's a win for me to start with, actually. Uh, so what I'd like to do in this session, first and foremost, is actually make a promise to you, okay? And, uh, it goes along this line, okay? I, I wanna make a promise to you that by the end of this session, I would have successfully co... Read More

Key Insights

  • Open source intelligence is information collected from overt, publicly available, free, and legal sources for a defined purpose. Its public nature distinguishes it from intelligence gathered through covert or clandestine sources, while its usefulness depends on connecting the collected material to a specific mission or question.
  • The cyber threat landscape is growing alongside digital transformation and increasing technological dependence. The presentation cites more than 16,400 newly disclosed vulnerabilities in 2013, approximately 45 each day, to illustrate the scale at which defenders must monitor and understand emerging risks.
  • Malware development is becoming more targeted rather than relying solely on a scattergun approach. The presentation reports around 8.4 million new malware specimens in 2017, approximately 959 per hour, while noting increased attention to mobile platforms and improved obfuscation techniques.
  • Cloud adoption creates cybersecurity challenges involving jurisdiction, legislation, data location, shared infrastructure, shadow IT, shadow data, and possible privilege abuse by providers. These risks strengthen the case for intelligence methods that help organizations understand exposure and direct defensive resources more effectively.
  • The OSINT process is a repeating cycle of direction and planning, collection, processing, analysis, and reporting. Each stage turns broad public information into focused intelligence that can answer the original question and be communicated to organizational decision-makers.
  • Source selection is determined by the mission and the organization's actual technology environment. A business centered on Windows gains little value from an otherwise excellent Linux information repository if that source does not address its systems, risks, or investigative purpose.
  • Collection methods must account for operational exposure when a source is connected to an active investigation. Investigators may need techniques that obscure their identity so the subject or source does not learn who is gathering the information or recognize that an investigation is underway.
  • OSINT tools can reduce information-gathering time from a vast Internet to seconds or minutes when properly implemented. Shodan searches for connected devices, while URLScan examines website requests and domains to reveal what a site does and support reconnaissance against a specific target.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: What is open source intelligence in cybersecurity?

Open source intelligence is information gathered from overt, publicly available sources and used for a defined purpose or mission. The information must be publicly available, free, and legally obtained. In cybersecurity, teams can use it to accelerate operations and investigations, focus their attention on relevant risks, and assemble separate public artifacts into a coherent picture that answers a specific security question.

Q: How does the OSINT process work?

The OSINT process follows five basic stages: direction and planning, collection, processing, analysis, and reporting. Teams first define the purpose and select relevant sources. They then extract information, sift it to surface useful artifacts, connect those artifacts into a complete picture, and format and communicate the findings. After reporting, the cycle begins again for the next mission.

Q: Why must an OSINT investigation begin with a clear purpose?

A clear purpose determines which sources, information, and artifacts are relevant to the investigation. Without a defined mission or question, teams can become overwhelmed by the Internet's enormous and continually growing volume of data. For example, a Windows-focused organization would gain little from prioritizing an excellent Linux repository if it does not relate to the organization's technology environment or the problem being investigated.

Q: What public sources can cybersecurity teams use for OSINT?

Cybersecurity teams can gather open source intelligence from social media platforms, websites, news articles, audio, video, blogs, posts, and data repositories such as GitHub. These sources contain information about individuals, organizations, systems, and online activity. Because the information appears in many categories and formats, teams need a methodical process and suitable tools to identify, extract, process, and analyze what is relevant.

Q: How can OSINT collection expose an investigator?

OSINT collection can expose an investigator when information is extracted from a source associated with a case under investigation. Direct interaction with that source may reveal the investigator's identity or signal that investigative activity is occurring. The presentation therefore advises teams to consider how collection is performed and, when necessary, use techniques that obscure their identity from the source being examined.

Q: What does Shodan do for cybersecurity investigations?

Shodan is described as a network security monitor and search engine focused particularly on the deep web and Internet-connected devices. It allows investigators to identify and explore devices connected to networks and scan the Internet for many kinds of systems. Examples include PCs, servers, routers, home heating systems, traffic management systems, traffic lights, and even nuclear power plants.

Q: How does URLScan support website reconnaissance?

URLScan helps investigators understand what a website is doing by scanning the site and identifying and analyzing the requests it makes, including domain requests. This activity supports reconnaissance on a specific target by exposing relationships and behavior that may not be obvious from simply viewing the site's pages. It is presented as one tool that can accelerate the extraction of useful public information.

Q: Why is OSINT increasingly useful for cyber defense?

OSINT is increasingly useful because technology dependence, digital transformation, expanding vulnerabilities, targeted malware, ransomware, mobile threats, and cloud risks create a large and complex defensive environment. Properly implemented OSINT can help scale cybersecurity work, speed investigations, focus operations, and reveal relevant information within seconds or minutes, giving organizations a more informed basis for reducing exposure and avoiding public breaches.

Summary & Key Takeaways

  • Open source intelligence uses overt, publicly available, free, and legally obtained information to answer a defined question or mission. Its cybersecurity value comes from helping teams focus investigations, accelerate operations, and understand threats by drawing relevant evidence from websites, social media, news, multimedia, blogs, posts, and public data repositories.

  • A disciplined OSINT process begins by defining the mission and identifying sources relevant to the organization. Teams then collect information, process it to surface useful artifacts, analyze those artifacts to build a coherent picture, and communicate the findings through a formatted report before beginning the cycle again for another mission.

  • OSINT tools make the Internet's enormous information volume more manageable. Shodan identifies and explores network-connected devices, while URLScan reveals website behavior by analyzing requests and domains. Collection still requires operational caution, especially when an investigated source could detect the investigator, so teams may need techniques that conceal their identity.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚