How to Prioritize Cybersecurity Attack Campaigns

4.4K views
•
April 22, 2015
by
RSAC Cybersecurity
YouTube video player
How to Prioritize Cybersecurity Attack Campaigns

TL;DR

Cybersecurity teams should organize alerts, malware samples, and threat intelligence around attack campaigns that are relevant to their organizations. By emphasizing information quality, probable attack paths, and campaign impact, defenders can prioritize meaningful threats, redesign operations, and act proactively instead of treating growing volumes of security data as evidence of success.

Transcript

Good morning, everyone. Do we have the courage to change the game in our industry? That's one of the questions that really keeps me up at night, and I know that w-when here at this conference, I'm not alone. But really, if you think about it, it's difficult for us to change when we're merely just trying to survive the status quo in our business. Re... Read More

Key Insights

  • Cybersecurity is experiencing a trust crisis even as its visibility, investment, innovation, spending, and threat-detection capabilities continue to grow. These rising measures do not demonstrate success because defenders are still being outplayed, making outcomes more important than the volume of work performed.
  • The Oakland Athletics changed their results by questioning conventional measures of player value. Instead of relying only on familiar statistics and intangible judgments, they identified measurable abilities that better predicted success and used those insights to exploit inefficiencies in an established professional sport.
  • Data analytics creates value only when organizations interpret available information differently. The Athletics had access to information that others could also obtain, but their advantage came from challenging assumptions, selecting more useful measures, and connecting those measures to decisions about talent and operations.
  • Cybersecurity teams often collect more threat intelligence, alerts, indicators of compromise, malware samples, and behavioral anomalies without gaining enough insight into what matters. Accumulating information without a defined purpose can increase investigative work while failing to clarify which threats deserve priority.
  • The key to useful threat analysis is distinguishing suspicious activity from truly malicious activity and opportunistic attacks from focused campaigns. These distinctions help defenders identify threats that matter to their own organization instead of treating every alert as equally significant.
  • Attack campaigns can provide the organizing context for alerts, malware samples, and shared threat intelligence. Mapping individual signals to campaigns that matter to a specific business can reveal relationships, improve prioritization, and make collected information more operationally valuable.
  • Probabilistic ranking can focus security operations on the threats most likely to affect an organization negatively. Assigning alerts and malware to probable campaigns allows teams to rank investigations by relevance and potential impact rather than processing information mainly according to its quantity.
  • Operational change is necessary after new insight is produced. The Athletics changed recruiting, personnel choices, starting lineups, and pitching decisions, showing that better analysis matters only when people, processes, tools, and operating practices are redesigned to apply it.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: How can cybersecurity teams prioritize attack campaigns?

Cybersecurity teams can prioritize attack campaigns by mapping alerts, malware samples, and shared threat intelligence to campaigns that are relevant to their particular organization, business, and industry. They can then rank operations according to the probability that each signal belongs to a meaningful campaign and the likelihood that the campaign could affect the organization negatively. This directs attention toward probable attack paths instead of every isolated alert.

Q: Why is collecting more cybersecurity data not enough?

Collecting more data is not enough because additional alerts, threat intelligence, indicators of compromise, malware samples, and behavioral anomalies do not automatically reveal which activity matters. Teams may spend substantial effort chasing information without a clear purpose. Value comes from interpreting the data in context, distinguishing suspicious signals from malicious activity, and connecting individual observations to relevant attack campaigns that can guide operational priorities.

Q: What can cybersecurity leaders learn from Moneyball?

Cybersecurity leaders can learn to challenge conventional measures, search for undervalued indicators, and connect analysis to operational decisions. The Oakland Athletics did not gain their advantage merely by using analytics. They examined familiar information differently, identified abilities that better predicted success, acquired talent suited to those findings, and changed how the team operated. Security organizations likewise need new measures and the courage to apply them throughout their practices.

Q: How should security alerts be evaluated differently?

Security alerts should be evaluated according to their relationship to relevant attack campaigns, their probability of representing genuinely malicious activity, and their potential effect on the organization. Instead of treating each alert as an independent task, analysts can place it within a probable attack path and compare it with other evidence. This approach supports informed ranking and reduces the emphasis on processing a large quantity of disconnected signals.

Q: What is the difference between suspicious and malicious security activity?

Suspicious activity is an indicator that may deserve examination, while truly malicious activity is connected to a threat that is actually operating against the environment. The transcript argues that security teams should explicitly ask which category their findings belong to. Placing alerts, malware, and anomalous behavior within the context of relevant campaigns can help analysts make that distinction and concentrate on threats with meaningful organizational consequences.

Q: Why should threat intelligence be organized by campaign?

Threat intelligence should be organized by campaign because campaign context connects otherwise separate alerts, malware samples, and indicators to an attack that the organization understands and cares about. This structure can reveal the probable path of an attack and support prioritization based on relevance. It also shifts the goal from accumulating information to producing insight that people, processes, and tools can use in security operations.

Q: How can cybersecurity teams move from defense to offense?

Cybersecurity teams can move toward offense by using prioritized insight to search proactively for meaningful threats instead of reacting uniformly to every alert. Understanding relevant attackers and probable attack paths allows teams to focus their attention where harm is more likely. The operational model must also change, with explicit adjustments to tools, processes, and people so that improved analysis produces different actions rather than merely greater knowledge.

Q: What security metrics provide more operational value?

Security metrics provide more value when they indicate the probability, relevance, and organizational impact of an attack rather than simply counting alerts, malware samples, or other information. Useful measures can show whether a signal belongs to a campaign the organization cares about and where it fits along a probable attack path. These measures enable teams to rank work according to expected security value and focus on information quality.

Summary & Key Takeaways

  • Cybersecurity has moved from a back-office function into boardroom and government discussions, while investment, innovation, spending, and threat detection have all increased. Yet greater effort and more information have not produced sufficient results. Security organizations must therefore stop equating activity with progress and reconsider how they define, measure, and pursue defensive value.

  • The Oakland Athletics provide a model for changing entrenched practices. They questioned traditional measures of player value, emphasized measurable abilities that better predicted success, acquired undervalued talent, and changed how the team operated. Their example suggests that cybersecurity teams should reinterpret familiar data, identify overlooked signals, and follow new insights through operational implementation.

  • Security teams can gain better insight by mapping alerts, malware samples, and shared intelligence to relevant attack campaigns. Probabilistic ranking can help distinguish suspicious indicators from genuinely malicious activity and opportunistic attacks from focused campaigns. This approach directs limited attention toward probable attack paths and threats most likely to harm a particular organization.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚