How to Curate Threat Intel for Better Detection

231 views
July 18, 2018
by
RSAC Cybersecurity
YouTube video player
How to Curate Threat Intel for Better Detection

TL;DR

Effective threat detection depends on curating intelligence for organizational relevance, risk, and available security architecture, rather than ingesting every indicator. Combine external sources with internal knowledge, translate useful indicators into aligned detection content, and feed incident findings back into an iterative process that improves analyst prioritization and SOC performance.

Transcript

Uh, so I want to introduce my co-speaker today. This is Justin Montie. Justin is the CTO at MKA Cyber. Uh, Justin, uh, brings over twenty years of, uh, highly technical experience in IT and security and, and engineering, uh, to the, to this presentation, and, uh, has some pretty unique and interesting ideas around, uh, threat intel and what we call... Read More

Key Insights

  • Cyber threat intelligence is data that an organization collects, assesses, and applies to security threats. It commonly includes atomic indicators such as malicious IP addresses, domain names, and file hashes, but it can also include vulnerabilities, reports, context, and knowledge developed inside the organization.
  • Threat intelligence can come from open-source websites, GitHub repositories, security researchers, commercial providers, managed security service providers, governments, and internal operations. Each source offers different visibility, formats, and context, so collecting feeds alone does not create an effective detection capability.
  • Internal threat intelligence is knowledge derived from an organization’s assets, architecture, detected exploitation, and security incidents. It is often overlooked, yet it can enrich external intelligence and create a feedback loop that makes later detection efforts more relevant to the organization’s actual environment.
  • Long-form threat reports contain context that can include vulnerability references, additional findings, and indicator appendices. Organizations often extract the indicators, discard the report, and lose the narrative needed to evaluate relevance, credibility, relationships, and potential use within their own security operations.
  • More threat intelligence is not automatically more useful because large volumes can produce more hits than analysts can reasonably review. A SOC must determine what applies to its environment and prioritize intelligence according to organizational risk, internal threat models, use cases, and available resources.
  • Generic vendor detection content is not necessarily tailored to an organization’s environment. Firewall rules, intrusion detection signatures, and SIEM content may come from separate providers and fail to align, creating gaps between the intelligence an organization wants to detect and the controls performing detection.
  • Content curation is the process of prioritizing, organizing, and translating meaningful intelligence into usable detection content. It connects relevant indicators and context to the organization’s SIEM, intrusion detection systems, firewalls, and other security products instead of merely loading undifferentiated data into tools.
  • Analyst prioritization improves when intelligence and detection content are connected to use cases, organizational priorities, and risk. This alignment helps analysts identify the small set of items that deserve attention first when the total number of intelligence hits is too large to review immediately.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: What is cyber threat intelligence used for?

Cyber threat intelligence is collected, assessed, and applied information concerning security threats. Its practical purpose is to help an organization detect malicious activity within its networks and improve defensive operations. It can include IP addresses, domains, hashes, vulnerability references, narrative reports, and internally generated knowledge about assets, architecture, exploitation, and incidents.

Q: Why is ingesting more threat indicators not enough?

Ingesting more indicators is insufficient because a large volume of data can create thousands of hits without showing analysts what deserves attention first. Intelligence may arrive in different formats, lack useful context, or have little relevance to the organization. Effective use requires assessing credibility, applicability, organizational risk, and whether the security architecture can turn the information into detection content.

Q: What are the main sources of threat intelligence?

Threat intelligence comes from four broad source groups discussed in the presentation: open sources, commercial enterprises, governments, and internal organizational knowledge. Open sources include websites, GitHub repositories, blogs, and researcher posts. Commercial providers and managed security service providers add collected visibility, while internal sources include architecture knowledge, detected exploitation, incidents, and other findings from the organization’s environment.

Q: How does internal intelligence improve threat detection?

Internal intelligence adds context about the organization’s assets, architecture, observed exploitation, and security incidents. That context can be combined with externally obtained intelligence to determine what genuinely applies to the environment. Findings produced during detection and incident handling can then feed back into the intelligence process, enriching future analysis and supporting an iterative improvement cycle for detection.

Q: Why should organizations preserve context from threat reports?

Threat reports may contain vulnerability references, related findings, narrative explanations, and lists of indicators. When an organization extracts only IP addresses, domains, hashes, or other indicators and discards the report, it loses information that may help assess relevance and use. Preserving useful context supports better decisions about which intelligence should become detection content and how it should be prioritized.

Q: What is threat intelligence content curation?

Threat intelligence content curation is the process of selecting, prioritizing, organizing, and translating useful intelligence into detection content for an organization’s security architecture. It helps connect external intelligence and internal threat models with SIEM content, intrusion detection signatures, firewall rules, and other controls. The goal is usable detection rather than collecting intelligence mainly for discussion or storage.

Q: Why can vendor-provided detection content create problems?

Vendor-provided content is often generic and distributed to many customers rather than designed for one organization’s risks and architecture. Different vendors may separately provide firewall rules, intrusion detection signatures, and other content, so their outputs may not align. Organizations must curate and coordinate this material with their chosen intelligence and internally created SIEM content to produce consistent detection coverage.

Q: How should a SOC prioritize threat intelligence alerts?

A SOC should connect intelligence and detection content to defined use cases, organizational priorities, internal threat models, and risk. Without that alignment, a high volume of hits can leave analysts unable to decide what matters. Prioritization should identify the items that warrant attention first, particularly when analysts cannot review every intelligence match during the current day or week.

Summary & Key Takeaways

  • Cyber threat intelligence includes collected, assessed, and applied data about security threats. Common sources include open-source feeds, commercial providers, managed security service providers, governments, and the organization’s own environment. Although intelligence can include narratives and vulnerability references, organizations commonly focus on atomic indicators such as IP addresses, domains, and hashes.

  • The central problem is not simply obtaining intelligence, but determining which information is credible, relevant, and usable. Large volumes, inconsistent formats, and generic vendor content can overwhelm analysts. External indicators must be mapped to internal threat models, organizational risks, assets, architecture, and use cases before they can support meaningful detection decisions.

  • Content curation translates selected intelligence into coordinated detection logic for SIEMs, intrusion detection systems, firewalls, and other security products. Content should be organized and prioritized so analysts know which alerts deserve attention first. Findings from detected exploitation and incidents should then enrich internal intelligence through a continuing feedback loop.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚