How Does CERT-EU Make Threat Intelligence Useful?

351 views
•
April 28, 2015
by
RSAC Cybersecurity
YouTube video player
How Does CERT-EU Make Threat Intelligence Useful?

TL;DR

Threat intelligence becomes actionable only when technical indicators include context about relevance, timing, threat actors, campaigns, techniques, and defensive responses. CERT-EU uses a STIX-based internal platform to correlate and prioritize this information, then helps European organizations translate it into specific actions such as blocking, monitoring, or watching malicious domains during the periods when they are active.

Transcript

Hi, everyone. It's Brian Prince again. I'm a cybersecurity journalist here with a distinguished guest, uh, Freddy De Jord, head of the CERT team in Europe. Uh, how are you? I'm fine. Good. Nice to be here with you. Yeah. Enjoying RSA? Yes, I do. Very good. So. You, um, have a presentation up that, uh, deals with threat intelligence sharing. Uh, can... Read More

Key Insights

  • CERT-EU's mandate is to help protect about 60 European organizations, including major institutions and specialized agencies. These organizations are highly valued targets for targeted attacks, so the team concentrates on defending them against sophisticated attackers.
  • Raw technical indicators are insufficient for effective defense because an IP address or domain name does not explain its relevance, purpose, timing, or associated threat. Intelligence must include enough context for defenders to understand what the indicator means.
  • Cyber threat information includes technical indicators, threat actors, campaigns, techniques, tactics, procedures, and courses of action. Managing these connected elements carefully helps an organization understand threats and convert intelligence into practical defensive measures.
  • The CERT-EU CTI platform is an internal repository that stores potential threat information according to the STIX model. It combines technical data, such as IP addresses, domains, and MD5 identifiers, with contextual details about actors, campaigns, techniques, and defenses.
  • The CTI platform supports correlation, prioritization, and deployment of defensive measures. These functions help CERT-EU evaluate sophisticated threats and communicate useful protection guidance to the European institutions and agencies it serves.
  • A malicious domain's function determines the appropriate response because it may operate as a command-and-control server, watering hole, or redirecting site. Defenders need this classification before deciding whether to block, monitor, or otherwise watch the domain.
  • The active period of a malicious indicator is essential context because a domain may require attention only during a defined interval. Time information prevents constituents from applying a response outside the period when the indicator was associated with malicious activity.
  • Greater automation is a future priority for operational threat intelligence. CERT-EU wants courses of action to move beyond email exchanges and become embedded and communicated directly into the devices that control its constituents' infrastructure.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: What is CERT-EU's role in protecting European organizations?

CERT-EU's mandate is to help protect about 60 organizations described as European federal agencies. Its constituents include the European Commission, Parliament, European Central Bank, Europol, EASA, the Chemicals Agency, and the Food Safety Agency. Because these institutions and agencies are highly valued targets for targeted attacks, CERT-EU helps them protect their infrastructure against sophisticated attackers.

Q: Why is context necessary in cyber threat intelligence?

Context gives technical indicators meaning and makes them actionable. An IP address or domain name alone does not show whether it is relevant to a particular organization, when it was malicious, which actor used it, or how defenders should respond. Adding purpose, timing, actor, campaign, technique, and defensive guidance allows organizations to apply suitable controls to their infrastructure.

Q: What information does the CERT-EU CTI platform store?

The CERT-EU cyber threat information platform stores technical indicators and related contextual information according to the STIX model. Its technical records include IP addresses, domains, and MD5 identifiers. It also records actors, campaigns, techniques, tactics, procedures, and courses of action, including information about how organizations can protect themselves against the threats represented in the repository.

Q: How does CERT-EU make threat intelligence actionable?

CERT-EU adds meaning and timing to technical indicators, then explains the appropriate response to its constituents. For a malicious domain, the guidance may specify that it should be blocked, monitored, or watched during a particular period. This process helps constituent organizations absorb incoming intelligence and convert it into controls that protect their infrastructure from sophisticated attacks.

Q: What are the barriers to operationalizing threat intelligence?

A primary barrier is receiving large volumes of raw indicators without the context needed to interpret them. Organizations may know a domain is suspicious but not whether it served as a command-and-control server, watering hole, or redirecting site. They may also lack its active period and response guidance, making it difficult to choose an effective defensive action.

Q: How does timing affect the handling of malicious domains?

Timing identifies the period during which a domain was active as a malicious resource. That detail helps defenders decide when monitoring, blocking, or watching is justified. Without it, an organization may apply a control outside the relevant period. CERT-EU therefore treats the active interval as part of the context required to turn a domain indicator into actionable intelligence.

Q: What benefits does CERT-EU gain from using a CTI repository?

The internal CTI repository helps CERT-EU correlate information, prioritize threats, and roll out defensive measures. By keeping technical indicators together with actors, campaigns, techniques, tactics, procedures, and courses of action, the platform supports a more sophisticated method of managing potential threats and preparing useful guidance for the organizations that CERT-EU is responsible for helping protect.

Q: How could threat intelligence sharing become more automated?

CERT-EU's proposed direction is to combine richer context on the incoming side with greater automation on the actionability side. Courses of action should move beyond email exchanges and be embedded, communicated, and applied through the devices controlling constituent infrastructure. This would help defensive guidance reach operational systems more directly instead of depending entirely on manual communication and implementation.

Summary & Key Takeaways

  • CERT-EU helps protect about 60 European organizations, including the European Commission, Parliament, European Central Bank, Europol, EASA, the Chemicals Agency, and the Food Safety Agency. Because these organizations are highly valued targets for targeted attacks, CERT-EU focuses on helping them defend against sophisticated attackers through relevant cyber threat information.

  • Effective threat intelligence contains more than IP addresses, domain names, and MD5 identifiers. It also explains relevance, timing, threat actors, campaigns, techniques, tactics, procedures, and courses of action. This context allows defenders to determine whether an indicator should be blocked, monitored, or watched only during a specific period of malicious activity.

  • CERT-EU stores technical and contextual threat information in an internal platform structured according to the STIX model. The repository supports correlation, prioritization, and deployment of defensive measures. Future improvements should bring richer context into incoming intelligence and increase automation for communicating courses of action directly to infrastructure control devices used by constituent organizations.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚