Welcome!

Agile Computing Authors: Elizabeth White, Yeshim Deniz, Liz McMillan, Pat Romanski, Larry Alton

Blog Feed Post

RSA 2013 – The Year of Threat Intelligence

The RSA conference this year was abuzz with talk of threat intelligence and its usage in detecting and protecting against more advanced threats. There was re-branding of existing products and the entrance of new products, all of which claimed to support some type of “intelligence” capability.  As I walked around it struck me that usage of the term was not consistent. We need to have a detailed understanding of what it means to use intelligence to secure our enterprise from cyber attacks, and maintain business operations in the face of sophisticated threats.

Recolored

Defining Threat Intelligence

In April of 2011, Cyber Squared defined Threat Intelligence as “an emerging information security discipline that seeks to recognize and understand sophisticated cyber adversaries, specifically why and how they threaten data, networks, and business processes.  With enhanced knowledge of the threat develop better protective measures against them.”  Not many companies would use the word “emerging” as it relates to their primary business, but we did, because at the time most clients were not yet worried about sophisticated threats, nor did they know how they would use threat intelligence to protect themselves from them.  Almost two years later and Threat Intelligence has now become a market within the broader security space.  For you skeptics that think it is yet another marketing term, don’t take my word for it.    SANS has sponsored a Summit on this single topic.

The Cyber Threat Intelligence Summit will be held in March.  I’ll be presenting a lightning round presentation on the topic of crowdsourcing threat intelligence, and Rich Barger, Cyber Squared’s Chief Intelligence Officer, will be participating on a panel.  This is such an important topic for the industry that SANS is putting on this event, and in doing so have started the process for an industry wide definition of Threat Intelligence.

Why is it needed

The Advanced Persistent Threat (APT) facing many modern networked organizations has rendered intrusion detection systems, anti-virus and traditional incident response approaches insufficient. The APT represents well-resourced and trained adversary’s who use advanced tools and techniques designed to circumvent most conventional computer network defense mechanisms. Their multi-year intrusion campaigns target highly sensitive and valuable data for competitive edge.

What is it

Network defense techniques that leverage knowledge about these adversaries – known as cyber threat intelligence – can enable defenders to establish a state of information superiority which decreases the adversary’s likelihood of success with each subsequent intrusion attempt. Threat intelligence can be a force multiplier and provide security managers accurate, timely and detailed information to continuously monitor new and evolving attacks. Earlier detection can minimize losses or disruption within the network, and lessen the cost of cleanup efforts.  With Threat Intelligence you can provide a more effective defensive posture then would be otherwise be possible.

Threat Intelligence Triangle

A Threat Intelligence Ecosystem can be broken down into the following basic functional areas: information collection and analysis, decision support, and mitigations.  All three must work in concert in order to keep pace with the threat.  So to make Threat Intelligence possible, we must connect the efforts of our decision makers with security personal, and provide them with a robust ability to leverage more comprehensive knowledge of their particular cyber threats. Taking the concept of a Threat Intelligence one step further. We must unite the efforts of the community around the threat, and crowdsource our need for threat intelligence. The Threat Intelligence Ecosystem is so much more knowledgeable and powerful than a single individual or organization.

How crowdsourcing can help

We know that responding quickly to cyber threats is of critical importance, and the only way to really change the game is to understand how the adversary works and predict where they might go next.  We realize that we can’t win this battle by fighting alone. While progress is being made to create and use Threat Intelligence within organizations, unfortunately today this is only possible with the more mature and resourced organizations.  It takes a significant investment to collect, create, enrich, and leverage Threat Intelligence, leaving less resourced businesses from protecting themselves in the same manner.  The adversary doesn’t discriminate between those organizations with and without resources.  The adversary  is targeting those who have sensitive and valuable data.

What if we applied the crowdsourcing model?   Applying a crowdsourcing approach to Threat Intelligence would involve being able to assemble an impromptu, virtual army of trusted cyber defenders to more quickly and comprehensively understand the threat and predict where they will go next.  It would require the ability to create dynamic relationships with trusted sharing partners who have common threat interests, and being able to register and receive notifications when threats change.  By transitioning today’s more static “sharing” model to a more dynamic “crowdsourcing” approach for Threat Intelligence, we could actually improve response times and predict attacks.  Furthermore, it is possible that an established, successful crowdsourcing Threat Intelligence solution could serve as a deterrent for cyber adversaries.  Benefits of crowdsourcing include:

  • Less time commitment to understand the threat
  • Lower costs to obtain a larger understanding of the threat
  • Obtain insights that would not be otherwise obvious
  • Connect with other stake holders who are also experiencing the same problem
  • Ability to track / measure the threat, effectively explaining and articulating the problem to decision makers

Based on established current day environmental factors, we should have at our disposal the necessary ingredients to create a successful crowdsourcing environment for threat intelligence.  For instance, the enormous popularity of social media has turned strangers into virtual friends.  Facebook’s “like” feature virtually binds people into a community via a common interest.  There is a growing awareness and acceptance of using crowdsourcing to solve problems.  We can bind these concepts into a crowdsourcing, internet-based solution for Threat Intelligence that includes rankings, statistics, and metrics to facilitate “co-ompetition”.

Conclusions

Unfortunately, there is going to be a great deal of confusion around Threat Intelligence for the foreseeable future.  Just remember that Threat Intelligence is not something you buy, it’s something you create.   You can streamline the process of building Threat Intelligence using security analysis products that support data feeds and crowdsourcing .  Please come out on March 22nd and see what I have to say about Crowdsourcing Threat Intelligence – the BIG (data) idea behind ThreatConnect.com.

Read the original blog entry...

More Stories By Adam Vincent

Adam is an internationally renowned information security expert and is currently the CEO and a founder at Cyber Squared Inc. He possesses over a decade of experience in programming, network security, penetration testing, cryptography design & cryptanalysis, identity and access control, and a detailed expertise in information security. The culmination of this knowledge has led to the company’s creation of ThreatConnect™, the first-of-its-kind threat intelligence platform. He currently serves as an advisor to multiple security-focused organizations and has provided consultation to numerous businesses ranging from start-ups to governments, Fortune 500 organizations, and top financial institutions. Adam holds an MS in computer science with graduate certifications in computer security and information assurance from George Washington University. Vincent lives in Arlington, VA with his wife, two children, and dog.

@ThingsExpo Stories
Organizations do not need a Big Data strategy; they need a business strategy that incorporates Big Data. Most organizations lack a road map for using Big Data to optimize key business processes, deliver a differentiated customer experience, or uncover new business opportunities. They do not understand what’s possible with respect to integrating Big Data into the business model.
Enterprises have taken advantage of IoT to achieve important revenue and cost advantages. What is less apparent is how incumbent enterprises operating at scale have, following success with IoT, built analytic, operations management and software development capabilities – ranging from autonomous vehicles to manageable robotics installations. They have embraced these capabilities as if they were Silicon Valley startups. As a result, many firms employ new business models that place enormous impor...
SYS-CON Events announced today that Taica will exhibit at the Japan External Trade Organization (JETRO) Pavilion at SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. Taica manufacturers Alpha-GEL brand silicone components and materials, which maintain outstanding performance over a wide temperature range -40C to +200C. For more information, visit http://www.taica.co.jp/english/.
SYS-CON Events announced today that Dasher Technologies will exhibit at SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 - Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. Dasher Technologies, Inc. ® is a premier IT solution provider that delivers expert technical resources along with trusted account executives to architect and deliver complete IT solutions and services to help our clients execute their goals, plans and objectives. Since 1999, we'v...
Recently, REAN Cloud built a digital concierge for a North Carolina hospital that had observed that most patient call button questions were repetitive. In addition, the paper-based process used to measure patient health metrics was laborious, not in real-time and sometimes error-prone. In their session at 21st Cloud Expo, Sean Finnerty, Executive Director, Practice Lead, Health Care & Life Science at REAN Cloud, and Dr. S.P.T. Krishnan, Principal Architect at REAN Cloud, will discuss how they b...
SYS-CON Events announced today that TidalScale, a leading provider of systems and services, will exhibit at SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 - Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. TidalScale has been involved in shaping the computing landscape. They've designed, developed and deployed some of the most important and successful systems and services in the history of the computing industry - internet, Ethernet, operating s...
SYS-CON Events announced today that MIRAI Inc. will exhibit at the Japan External Trade Organization (JETRO) Pavilion at SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. MIRAI Inc. are IT consultants from the public sector whose mission is to solve social issues by technology and innovation and to create a meaningful future for people.
SYS-CON Events announced today that IBM has been named “Diamond Sponsor” of SYS-CON's 21st Cloud Expo, which will take place on October 31 through November 2nd 2017 at the Santa Clara Convention Center in Santa Clara, California.
Join IBM November 1 at 21st Cloud Expo at the Santa Clara Convention Center in Santa Clara, CA, and learn how IBM Watson can bring cognitive services and AI to intelligent, unmanned systems. Cognitive analysis impacts today’s systems with unparalleled ability that were previously available only to manned, back-end operations. Thanks to cloud processing, IBM Watson can bring cognitive services and AI to intelligent, unmanned systems. Imagine a robot vacuum that becomes your personal assistant tha...
SYS-CON Events announced today that TidalScale will exhibit at SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. TidalScale is the leading provider of Software-Defined Servers that bring flexibility to modern data centers by right-sizing servers on the fly to fit any data set or workload. TidalScale’s award-winning inverse hypervisor technology combines multiple commodity servers (including their ass...
As hybrid cloud becomes the de-facto standard mode of operation for most enterprises, new challenges arise on how to efficiently and economically share data across environments. In his session at 21st Cloud Expo, Dr. Allon Cohen, VP of Product at Elastifile, will explore new techniques and best practices that help enterprise IT benefit from the advantages of hybrid cloud environments by enabling data availability for both legacy enterprise and cloud-native mission critical applications. By rev...
Infoblox delivers Actionable Network Intelligence to enterprise, government, and service provider customers around the world. They are the industry leader in DNS, DHCP, and IP address management, the category known as DDI. We empower thousands of organizations to control and secure their networks from the core-enabling them to increase efficiency and visibility, improve customer service, and meet compliance requirements.
With major technology companies and startups seriously embracing Cloud strategies, now is the perfect time to attend 21st Cloud Expo October 31 - November 2, 2017, at the Santa Clara Convention Center, CA, and June 12-14, 2018, at the Javits Center in New York City, NY, and learn what is going on, contribute to the discussions, and ensure that your enterprise is on the right path to Digital Transformation.
Amazon is pursuing new markets and disrupting industries at an incredible pace. Almost every industry seems to be in its crosshairs. Companies and industries that once thought they were safe are now worried about being “Amazoned.”. The new watch word should be “Be afraid. Be very afraid.” In his session 21st Cloud Expo, Chris Kocher, a co-founder of Grey Heron, will address questions such as: What new areas is Amazon disrupting? How are they doing this? Where are they likely to go? What are th...
SYS-CON Events announced today that N3N will exhibit at SYS-CON's @ThingsExpo, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. N3N’s solutions increase the effectiveness of operations and control centers, increase the value of IoT investments, and facilitate real-time operational decision making. N3N enables operations teams with a four dimensional digital “big board” that consolidates real-time live video feeds alongside IoT sensor data a...
In his Opening Keynote at 21st Cloud Expo, John Considine, General Manager of IBM Cloud Infrastructure, will lead you through the exciting evolution of the cloud. He'll look at this major disruption from the perspective of technology, business models, and what this means for enterprises of all sizes. John Considine is General Manager of Cloud Infrastructure Services at IBM. In that role he is responsible for leading IBM’s public cloud infrastructure including strategy, development, and offering ...
Digital transformation is changing the face of business. The IDC predicts that enterprises will commit to a massive new scale of digital transformation, to stake out leadership positions in the "digital transformation economy." Accordingly, attendees at the upcoming Cloud Expo | @ThingsExpo at the Santa Clara Convention Center in Santa Clara, CA, Oct 31-Nov 2, will find fresh new content in a new track called Enterprise Cloud & Digital Transformation.
Most technology leaders, contemporary and from the hardware era, are reshaping their businesses to do software. They hope to capture value from emerging technologies such as IoT, SDN, and AI. Ultimately, irrespective of the vertical, it is about deriving value from independent software applications participating in an ecosystem as one comprehensive solution. In his session at @ThingsExpo, Kausik Sridhar, founder and CTO of Pulzze Systems, will discuss how given the magnitude of today's applicati...
SYS-CON Events announced today that NetApp has been named “Bronze Sponsor” of SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. NetApp is the data authority for hybrid cloud. NetApp provides a full range of hybrid cloud data services that simplify management of applications and data across cloud and on-premises environments to accelerate digital transformation. Together with their partners, NetApp emp...
Smart cities have the potential to change our lives at so many levels for citizens: less pollution, reduced parking obstacles, better health, education and more energy savings. Real-time data streaming and the Internet of Things (IoT) possess the power to turn this vision into a reality. However, most organizations today are building their data infrastructure to focus solely on addressing immediate business needs vs. a platform capable of quickly adapting emerging technologies to address future ...