Automation, Orchestration, and Actionable Threat Intelligence II
Facebook Twitter LinkedIn

Making Threat Intelligence a Shared Resource for Network Defense

Combined Session
Wednesday, October 09, 2019 16:00—17:00
Location: Holeman Lounge

Can small to medium organizations use what the larger organizations learn about threats to take action in a prioritized, appropriate, and automated manner? Is there an incentive for an organization to share opinions and sightings about Indicators of Compromise (IOCs)? How can a service provider share the insight gained by all these contributors so organizations can directly use that insight? Bandura Cyber has partnered with the IACD team to demonstrate the potential value of: community sharing of opinions/sightings, confidence scores to provide updated context, and dynamic prioritization to drive local response actions. This talk will describe the joint experiment, results, and lessons learned.

How can small to medium organizations use what the larger organizations learn about threats to take action in a prioritized, appropriate, and automated manner? Is there an incentive for an organization to share opinions and sightings about Indicators of Compromise (IOCs)? How can a service provider share the insight gained by all these contributors so organizations can directly use that insight, even if they do not have the staff to analyze all the associated information? Bandura Cyber has partnered with the IACD team to demonstrate the potential value of: community sharing of opinions/sightings, confidence scores to provide updated context, and dynamic prioritization to drive local response actions. This talk will describe the joint experiment, results, and lessons learned.

The experiment uses a simulated AIS feed, a threat intelligence gateway, a SOAR platform, and traditional security products to address an IOC associated with a watering hole attack. The demonstration uses the opinions and sightings from organizations to update the AIS confidence score which is used by the gateway to create a dynamic score. This score is used to block/allow or pass the IOC and context on to an orchestrator for processing. The scenario moves from IOC is good, to IOC is questionable, to IOC is bad, back to IOC is questionable, back to IOC is good. The contributions from the community build a perspective on the changing nature of the IOC, and the gateway can block or allow when appropriate threshold is met. It can also send to the orchestrator when the IOC is questionable.

The intent of the experiment was to: demonstrate a value to community members for sharing sightings/opinions, etc; attempt to use insight from other organizations to deal with a temporal aspect of an IOC; show a way to combine multiple insights into a single value to provide updated context to organizations; and identify the type of information that is needed to define the different actions to invoke under the different conditions based on local policy.

Key take-aways:
Participants who attend this session will leave with an understanding of how they can obtain value from providing local insight into community shared threat intelligence. They will also see a way to use dynamic prioritization to drive different actions in their environment, which may make it more appropriate to process IOCs and associated response actions in an automated manner.

 

Making Threat Intelligence a Shared Resource for Network Defense
Presentation deck
Making Threat Intelligence a Shared Resource for Network Defense
Click here to download the slide deck. Please note that downloads are only available for event participants and subscribers. You'll need to log in to download it.
Jason Mok
Jason Mok
IACD, Johns Hopkins Applied Physics Laboratory
Todd Weller
Todd Weller
Bandura Cyber
Todd brings to the team over 20 years of cybersecurity industry experience with a unique blend of operational and Wall Street experience.Todd is responsible for driving corporate, product, and...

Tickets

CyberNext Summit & Borderless Cyber
€700
€1000
 
All days: Oct
Two day ticket
€550
€750
 
Day 1 + Day 2
€550
€750
 
Day 2 + Day 3
€550
€750
 
Day 1 + Day 3
€550
€750
 
One day ticket
€300
€500
 
Day 1
€300
€500
 
Oct
Day 2
€300
€500
 
Oct
Day 3
€300
€500
 
Oct
CyberNext Summit & Borderless Cyber - Gov. rate
€360
 
Government rate, All days: Oct
Two day ticket - Gov. rate
€295
 
Day 1 + Day 2
€295
 
Day 2 + Day 3
€295
 
Day 1 + Day 3
€295
 
One day ticket - Gov. rate
€230
 
Day 1
€230
 
Oct
Day 2
€230
 
Oct
Day 3
€230
 
Oct
Have you participated in our events?
Contact us to get a special discount
Subscribe for updates
Please provide your email address