How Can Threat Analytics Strengthen Cyber Defense?

601 views
•
February 14, 2017
by
RSAC Cybersecurity
YouTube video player
How Can Threat Analytics Strengthen Cyber Defense?

TL;DR

Cyber defenders can regain an advantage by rapidly sharing threat intelligence and automatically analyzing it within security control systems. Combining indicators of compromise, indicators of attacks, global activity, and local environment data helps teams reduce alert noise, expose adversary behavior, prioritize meaningful events, and implement protective measures before attackers can remain hidden for extended periods.

Transcript

Hi, my name is Jeannette Jarvis. I'm Director of Product Management at McAfee Labs for Intel Security. My talk today is on threat intelligence and data analytics jujitsu. Like a samurai warrior heading into battle, today's cybersecurity professional faces formidable challenges in protecting the ecosystem, but these can be overcome with the right th... Read More

Key Insights

  • Cyber defenders face an asymmetric contest because attackers need only one entry point, while defenders require extensive monitoring, detection, and technical capabilities. Adversaries can adapt quickly, conceal their actions, persist inside environments, and use lateral movement, making broad and timely defensive visibility essential.
  • McAfee Labs sees approximately thirty to forty million new malware samples every quarter. This volume compounds the challenge created by overwhelming alerts, limited skilled personnel, and insufficient capacity, making it difficult for security teams to determine which events deserve immediate attention and effort.
  • Threat intelligence is most useful when it is shared rapidly and combined across sources. Fragmented or delayed sharing prevents defenders from connecting the dots, understanding the full course of an attack, and recognizing how the same adversary may target related organizations or industries.
  • Automated data consumption is necessary in a dynamic threat landscape because manual processes delay protective countermeasures. Ingesting relevant intelligence directly into security control systems allows organizations to react faster and helps solve the last-mile problem between receiving data and putting it into operational use.
  • Data analytics works by exposing adversary footprints, outlier activity, targets, impacts, motivations, and behavioral markers. This greater transparency helps defenders distinguish meaningful signals from noise, develop threat and adversarial playbooks, and place appropriate control measures across their environments.
  • Indicators of compromise and indicators of attacks help organizations connect external intelligence with evidence inside their own environments. These indicators can guide preventive measures while also helping defenders determine whether an attacker has already entered and generated activity that previously went unnoticed.
  • Global visibility strengthens local protection because attacks against organizations with similar characteristics can warn others that they may face the same adversary. The car manufacturer example shows how intelligence about an overseas competitor’s attack can guide both prevention and internal investigation in the same industry.
  • Threat-sharing programs serve different purposes: CERTs commonly share incident-response information after attacks, ISACs focus on particular industry sectors, and ISAOs support sharing among government agencies and between public and private organizations. The Cyber Threat Alliance emphasizes timely, cross-industry, actionable, and automated intelligence sharing.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: How can threat intelligence improve cyber defense?

Threat intelligence improves cyber defense by giving teams evidence about attacker activity beyond what they can observe locally. Shared indicators of compromise and indicators of attacks help organizations recognize relevant threats, investigate whether an intruder is already present, and choose preventive measures. When intelligence connects multiple observations, defenders can understand the attack’s broader story and prioritize their limited time and capacity.

Q: Why do cyber attackers have an advantage over defenders?

Attackers have an advantage because they need only one entry point to cause harm, while defenders must maintain extensive monitoring, detection, and technical controls throughout an environment. Attackers can innovate quickly, adapt to security measures, hide their activity, persist over time, and move laterally. Meanwhile, defenders must sort through overwhelming alert noise to identify and prioritize the events that represent genuine threats.

Q: How does data analytics expose cyber threats?

Data analytics exposes threats by examining large volumes of information for adversary footprints, outlier activity, targets, impacts, motivations, and behavioral markers. Query, aggregation, management, and visualization systems can help transform scattered data into a coherent account of an attack. This analysis makes bad-actor behavior more transparent and helps defenders find the meaningful needle within a large and noisy haystack of alerts.

Q: Why is automated threat intelligence consumption important?

Automated consumption is important because manually processing intelligence slows the implementation of protective countermeasures. The threat landscape changes quickly, so relevant data must reach security control systems in real time or near real time. Automation helps close the last-mile gap between receiving intelligence and using it, allowing defenders to recognize activity, update protections, and respond without waiting for prolonged manual review.

Q: Why should organizations share cyber threat intelligence?

Organizations should share threat intelligence because no single organization can see the complete activity of an adversary. Collaboration adds connection points, improves accuracy, and helps participants identify who is targeted, how attacks unfold, and what impacts they cause. Rapid sharing also warns similar organizations about relevant threats and provides indicators they can use to search their own environments for previously unnoticed attacker activity.

Q: How does global threat visibility protect a local network?

Global visibility reveals attacks that may also be relevant to a local organization. If a car manufacturer in Germany is attacked, a competing manufacturer in Michigan may be monitored by the same actor because both operate in the same industry. Shared intelligence can tell the Michigan organization which preventive measures to consider and which indicators to search for when determining whether the attacker has already entered its environment.

Q: What are the differences among CERTs, ISACs, and ISAOs?

The traditional CERT model provides valuable incident-response information, generally after an attack has occurred, and its information is not usually shared beyond organizations involved in that incident, although data can cross borders and boundaries. ISACs share valuable intelligence within specific industry sectors. ISAOs were created to improve information sharing among government agencies and between public and private sector organizations.

Q: What role does the Cyber Threat Alliance play in intelligence sharing?

The Cyber Threat Alliance addresses timely, cross-industry sharing of threat intelligence. It aims to provide an end-to-end account of threats and deliver relevant, actionable playbook information that security teams can consume through their data control systems. Its approach focuses on orchestrating data consumption in real time or near real time, helping defenders move from collected intelligence to operational protection more quickly.

Summary & Key Takeaways

  • Cybersecurity teams face thirty to forty million new malware samples every quarter, fragmented intelligence sharing, overwhelming alert volumes, and insufficient personnel. Attackers need only one successful entry point, while defenders must monitor broadly. Threat intelligence and data analytics can shift this imbalance by making suspicious activity easier to discover and prioritize.

  • The jujitsu analogy describes using an opponent’s own force to neutralize their advantage. Defenders can study attacker tactics, expertise, persistence, targets, lateral movement, and footprints. Sharing indicators and applying query, aggregation, management, and visualization systems turns raw data into an actionable account of the threat and its actors.

  • Effective collaboration connects intelligence across organizations, industries, borders, and public and private sectors. CERTs, ISACs, ISAOs, and the Cyber Threat Alliance provide different sharing models. The Cyber Threat Alliance emphasizes timely cross-industry intelligence and automated, real-time or near-real-time consumption that can support relevant defensive playbooks and faster countermeasures.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚