How to Improve Security Response With Context

609 views
β€’
May 22, 2014
by
RSAC Cybersecurity
YouTube video player
How to Improve Security Response With Context

TL;DR

Effective security response requires combining validated threat indicators with internal context about risky behavior, known vulnerabilities, and the organization’s changing attack surface. Traditional products, compliance checklists, and large data collections remain useful but are insufficient because they often depend on prior knowledge, lack lateral visibility, and cannot consistently measure security effectiveness against current threats.

Transcript

Anyway, thanks everybody for coming. Good morning to you. Uh, we-we've got some esteemed, uh, members of the panel that I think are gonna generate a conversation not only amongst us, but also engaging the, uh, the audience here. It's, it's interesting, when we talk about threat indicators, particularly in the, uh, world we live in today, oftentimes... Read More

Key Insights

  • Traditional security products are valuable but insufficient because antivirus, intrusion detection systems, and next-generation firewalls typically need prior knowledge of malicious activity, while the products deployed by organizations may reflect technology developed twelve to eighteen months earlier.
  • Security effectiveness is difficult to measure through compliance alone because different practitioners may implement the same regulatory requirement differently. A checklist can confirm that controls exist without demonstrating how effectively those controls resist the threats currently targeting an organization.
  • Threat intelligence is most useful when it supplies information that existing security products do not already possess. Feeding validated indicators into defensive controls can reduce gaps across an infrastructure, although the panel emphasizes that no technology provides a complete solution.
  • Attack-surface awareness is a core defensive requirement because organizations must understand their operating systems, applications, and infrastructure before they can evaluate variable risk. Threat intelligence should be connected with this internal knowledge and supported by consistently good security hygiene.
  • Internal staging and lateral movement expand the security problem beyond the visible attack surface. Attackers can exploit limited lateral visibility and gaps between isolated IT silos, especially when business workflows connect employees, contractors, supply-chain partners, devices, and applications.
  • Smart data is more valuable than data volume because collecting and mining additional information can aggravate an existing big-data problem. The central challenge is extracting relevant, actionable information that supports timely security decisions rather than accumulating more unvalidated observations.
  • Threat intelligence requires validation because organizations may receive indicators from many sources without knowing whether those indicators are reliable. Decisions about the trustworthiness of a user, application, or device should begin with intelligence whose quality can be assessed.
  • Security architecture must evolve with the network because fixed perimeter assumptions no longer describe environments containing virtual machines, rapidly created internal networks, and personal devices. Policies and enforcement approaches must be reconsidered as the number and type of connected systems change.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: Why are traditional security best practices insufficient?

Traditional best practices are insufficient because organizations have repeatedly deployed antivirus, intrusion detection systems, and next-generation firewalls while continuing to face security gaps. These technologies remain useful, but they often need prior knowledge of malicious activity. They should be combined with breach detection, validated threat intelligence, security hygiene, and current knowledge of the organization’s attack surface.

Q: How can threat intelligence improve security response?

Threat intelligence can improve response by providing indicators and other information that existing security controls may not already know. Organizations can feed that information into defensive products and combine it with internal context about risky behavior and known vulnerabilities. This approach helps reduce gaps across the infrastructure, although it cannot create a complete defense or guarantee that every attack will be stopped.

Q: How should organizations validate threat intelligence?

Organizations should assess the quality and trustworthiness of threat intelligence before using it to make security judgments. The panel notes that indicators can arrive from many sources, but their availability does not prove their reliability. A useful framework or industry standard should help determine whether the data can support decisions about the trust of users, applications, devices, and observed behavior.

Q: Why is smart data better than more security data?

Smart data is better because a larger collection does not automatically produce better security decisions. The panel argues that the big-data problem was created for reasons other than the attacker’s needs, and adding more mined information can aggravate it. Defenders need relevant, validated information that turns observations into useful context, rather than an expanding volume of data with uncertain quality.

Q: What is the difference between an attack surface and a staging surface?

The attack surface includes exposed operating systems, applications, devices, and other components that an adversary may target. The staging surface extends the problem to internal activity used to prepare or advance an attack. It includes lateral visibility gaps and disconnected business or IT silos that attackers can exploit while moving through workflows involving partners, contractors, people, applications, and devices.

Q: Why does regulatory compliance lag behind cyber threats?

Regulatory compliance lags because it generally addresses threats and practices that are already known. Checklist-based requirements and hardening guides can establish a baseline, but different people may implement the same requirement differently, and the resulting security effectiveness may not be measurable. Regulation therefore has a role, but it must be connected to better data quality, changing risks, and operational context.

Q: How does a changing network affect security architecture?

A changing network weakens assumptions built around a stable perimeter and a known topology. Virtual machines can create large internal networks quickly, while employees may add personal phones and other devices throughout the day. Because the number, type, and location of systems can shift rapidly, organizations must repeatedly reconsider access policies, enforcement points, visibility, and the architecture used to protect communications.

Q: Can organizations stop targeted attacks before they happen?

Organizations cannot reliably identify and thwart every targeted attack before it happens, according to the description. However, progress has been made by combining indicators that suggest an industry sector is being targeted with real-time internal context about risky behavior and known vulnerabilities. This combination can improve preparation and response, but the panel does not present it as a guaranteed preventive capability.

Summary & Key Takeaways

  • Traditional antivirus, intrusion detection systems, and next-generation firewalls provide useful protection, but they generally depend on knowledge of existing threats. Because no product eliminates every gap, organizations should supplement established controls with breach detection, validated threat intelligence, sound security hygiene, and a detailed understanding of operating systems, applications, and other elements of the attack surface.

  • Checklist-based compliance and hardening guidance are trailing indicators because regulations primarily address what is already known. Inside an organization, defenders must manage unknown risks, staging activity, lateral movement, isolated business silos, and fluid relationships involving partners, contractors, people, and devices. Attackers can exploit the visibility and communication gaps created by these conditions.

  • Security teams need smart, trustworthy data rather than simply larger collections of information. Threat intelligence from multiple sources must be validated before it informs judgments about users, applications, or devices. Because networks continually change through virtual machines, rapidly expanding infrastructure, and personal devices, security architectures and enforcement policies must also be reconsidered continuously.


Read in Other Languages (beta)

Share This Summary πŸ“š

Explore More Summaries from RSAC Cybersecurity πŸ“š