How to Apply the LEAD Threat Intelligence Framework

507 views
•
February 26, 2020
by
RSAC Cybersecurity
YouTube video player
How to Apply the LEAD Threat Intelligence Framework

TL;DR

Effective threat intelligence starts by identifying relevant adversaries, infrastructure, and program requirements before collecting or processing data. The LEAD framework then makes intelligence efficient through scoring and categorization, analyst-driven through feedback and machine learning, and deliverable through standardized formats and metrics that demonstrate value while addressing excessive data, unclear requirements, and high operating costs.

Transcript

Good morning, everyone. Welcome to this morning's session, Intelligent Threat Intel Lead Framework. We have Philippe Stoykovski, Threat Intel Manager from Adobe, speaking to us. And just a quick note that the slides have been posted already online, so feel free to look online or after the presentation. Thank you. Thank you, and good morning, everyo... Read More

Key Insights

  • Threat intelligence requirements are essential because ad hoc support for incidents or SOC analysis does not provide a durable foundation for measuring value. The cited SANS survey found that 70 percent of organizations lacked clear requirements, making structured program objectives a necessary starting point.
  • Threat intelligence has become a data-management problem because organizations have moved from insufficient information to excessive volumes that are difficult to retain and process. A threat intelligence platform must organize incoming feeds and distribute useful results to multiple stakeholders without allowing accumulated data to become an unmanaged burden.
  • Threat intelligence is often treated as optional because its perceived value is small while its cost is high. A sustainable program must reverse this relationship by increasing the relevance and usefulness of intelligence while reducing the effort and expense required to process and deliver it.
  • The LEAD framework consists of four connected stages: Relevant, Efficient, Analyst Driven, and Deliverable. Relevant identifies useful intelligence, Efficient structures the data, Analyst Driven incorporates human feedback, and Deliverable standardizes outputs and creates metrics that communicate value.
  • Relevant intelligence is determined by identifying likely adversaries and understanding the infrastructure being defended. A small e-commerce company may prioritize organized crime and scammers, while an oil company in the Middle East may be more concerned with state-sponsored threat actors.
  • Infrastructure determines which intelligence indicators deserve attention because different systems expose different attack surfaces. Payment systems may require credit card information and IP addresses associated with fraudulent payments, while servers may make file hashes more useful than URLs or email indicators.
  • Efficient threat intelligence depends on scoring and categorization because these processes reveal what collected data contains and which portions matter. Organizing intelligence this way helps teams deliver appropriate information to stakeholders instead of treating every feed or indicator as equally valuable.
  • Analyst-driven intelligence depends on a feedback loop because threat intelligence requires sharing results, evaluating their usefulness, and acting on stakeholder responses. Machine learning can assist with interpreting large amounts of feedback, but the framework retains the human element as a central part of long-term success.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: What is the LEAD threat intelligence framework?

The LEAD framework is a four-stage structure for increasing the value of threat intelligence and making sense of collected data. Its stages are Relevant, Efficient, Analyst Driven, and Deliverable. They cover selecting intelligence based on threats and infrastructure, scoring and categorizing data, incorporating analyst feedback with machine learning support, and standardizing outputs so teams can build metrics and demonstrate value.

Q: How does the LEAD framework make threat intelligence relevant?

The Relevant stage combines a threat profile with defined threat intelligence program requirements. A team first asks which adversaries it is defending against and which infrastructure or attack surface requires protection. Those answers guide the selection of feeds and sources. When an organization has varied infrastructure or operates across sectors, segmentation helps connect each environment with the threat actors and intelligence data that matter to it.

Q: Why are clear threat intelligence requirements important?

Clear requirements connect intelligence work to sustained organizational needs rather than isolated requests. Without them, a program may support a particular incident, SOC investigation, or analysis but struggle to provide continuing value. Requirements also create the basis for deciding what information should be collected, identifying intended stakeholders and uses, and building metrics that show whether the program is delivering useful results.

Q: How should an organization choose threat intelligence sources?

An organization should choose sources only after identifying its likely adversaries and the infrastructure it must defend. A small e-commerce company may focus on scammers or organized crime rather than highly complex state-sponsored activity. The type of system also matters: payment environments may need fraud-related IP and credit card information, while servers may benefit more from file hashes than browsing-related URLs or email indicators.

Q: Why should complex environments segment threat intelligence?

Complex environments should segment threat intelligence because different infrastructure and business sectors can face different adversaries and require different indicators. Treating the entire organization as one uniform target can reduce relevance. Segmentation lets teams match intelligence sources, threat actors, and data types to particular systems, producing a more accurate view of what matters for each part of the network and exposed attack surface.

Q: How does scoring and categorization improve threat intelligence?

Scoring and categorization make threat intelligence more efficient by imposing structure on large collections of data. These processes help teams understand what they possess, distinguish important information from less relevant material, and route useful intelligence to the appropriate stakeholders. Within the LEAD framework, they address the problem of excessive data and reduce the difficulty of managing many feeds through a central platform or repository.

Q: What role does analyst feedback play in threat intelligence?

Analyst feedback provides the human element of the LEAD framework. Threat intelligence depends on sharing results and learning whether stakeholders found those results relevant and actionable. A feedback loop allows the program to evaluate completed work and adjust future processing or delivery. Without a defined way to collect and act on feedback, the program is likely to lose effectiveness over the long run.

Q: How can threat intelligence teams demonstrate program value?

Threat intelligence teams can demonstrate value by producing standardized deliverables and building metrics around them. Standard formats make outputs more consistent for stakeholders, while metrics connect the program's work to clear requirements and observable results. The broader objective is to raise the value of intelligence and reduce its cost, moving it from an optional capability toward a more useful organizational security function.

Summary & Key Takeaways

  • Many organizations struggle to establish clear threat intelligence requirements, determine whether collected data is relevant, and manage growing volumes of retained information. These weaknesses make intelligence expensive and difficult to value. The LEAD framework provides a structured approach for turning fragmented feeds and stakeholder demands into a focused, measurable threat intelligence program.

  • The Relevant stage combines an organizational threat profile with explicit program requirements. Teams identify the adversaries most likely to target them, examine the infrastructure and attack surface they must protect, and select appropriate intelligence sources. Complex environments should be segmented because different systems, business sectors, and threat actors require different intelligence data.

  • The remaining stages organize and operationalize the selected intelligence. Scoring and categorization improve efficiency, while analyst feedback supplies the human context needed for continuous improvement. Machine learning can help interpret feedback at scale. Standardized formats and metrics make intelligence deliverable to stakeholders and allow teams to demonstrate the program's organizational value.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚