1
1

00:00:00,300  -->  00:00:02,760
<v Instructor>Security and threat intelligence.</v>
2

2

00:00:02,760  -->  00:00:04,530
These days, we have to use
3

3

00:00:04,530  -->  00:00:06,180
our intelligence-driven defense
4

4

00:00:06,180  -->  00:00:08,460
to create a solid defensive posture.
5

5

00:00:08,460  -->  00:00:11,310
We can't rely on the way we've done things historically.
6

6

00:00:11,310  -->  00:00:14,190
Now, historically, our focus was on configurations.
7

7

00:00:14,190  -->  00:00:15,750
We would set up the right firewalls,
8

8

00:00:15,750  -->  00:00:18,420
the right ACLs, install the right antivirus,
9

9

00:00:18,420  -->  00:00:20,670
and then we would say, "Hey, we're protected."
10

10

00:00:20,670  -->  00:00:23,190
But these days, that simply isn't enough.
11

11

00:00:23,190  -->  00:00:25,440
While all these technologies are very important,
12

12

00:00:25,440  -->  00:00:28,590
they don't by themself give you enough defense
13

13

00:00:28,590  -->  00:00:32,820
against a thinking adversary that uses modern cyber attacks.
14

14

00:00:32,820  -->  00:00:34,470
So instead, it's really important
15

15

00:00:34,470  -->  00:00:35,820
for us to think about the idea
16

16

00:00:35,820  -->  00:00:38,820
of security intelligence and cyber threat intelligence.
17

17

00:00:38,820  -->  00:00:41,130
And that's what we're going to focus on in this lesson.
18

18

00:00:41,130  -->  00:00:43,230
Now, security intelligence is the process
19

19

00:00:43,230  -->  00:00:44,670
through which data is generated
20

20

00:00:44,670  -->  00:00:47,220
in the ongoing use of the information system.
21

21

00:00:47,220  -->  00:00:50,520
And that data is going to be collected, processed, analyzed
22

22

00:00:50,520  -->  00:00:52,050
and disseminated to provide us
23

23

00:00:52,050  -->  00:00:55,410
with insights into the security status of those systems.
24

24

00:00:55,410  -->  00:00:57,870
So if you think of a standard system administrator,
25

25

00:00:57,870  -->  00:01:00,960
they log things on their system and they review those logs.
26

26

00:01:00,960  -->  00:01:03,330
That is a form of security intelligence.
27

27

00:01:03,330  -->  00:01:04,770
It's for them to be able to understand
28

28

00:01:04,770  -->  00:01:06,630
what is their system doing.
29

29

00:01:06,630  -->  00:01:08,400
As they go through their firewall logs,
30

30

00:01:08,400  -->  00:01:11,310
their intrusion detection alerts and other things like that,
31

31

00:01:11,310  -->  00:01:14,340
you're understanding what your posture is internally
32

32

00:01:14,340  -->  00:01:15,660
inside your network
33

33

00:01:15,660  -->  00:01:19,380
and what your organization's security posture is now set at.
34

34

00:01:19,380  -->  00:01:20,580
Now, on the other hand,
35

35

00:01:20,580  -->  00:01:23,760
we have to consider our cyber threat intelligence as well.
36

36

00:01:23,760  -->  00:01:25,950
Now, cyber threat intelligence is the process
37

37

00:01:25,950  -->  00:01:28,470
of investigating, collecting, analyzing
38

38

00:01:28,470  -->  00:01:31,440
and disseminating information about the emerging threats
39

39

00:01:31,440  -->  00:01:33,570
and threat sources to provide data
40

40

00:01:33,570  -->  00:01:36,000
about the external threat landscape.
41

41

00:01:36,000  -->  00:01:37,860
So when we're talking about security intelligence,
42

42

00:01:37,860  -->  00:01:40,830
we're thinking inward, how are our systems looking?
43

43

00:01:40,830  -->  00:01:41,663
But when we think
44

44

00:01:41,663  -->  00:01:44,190
about cyber threat intelligence, we're looking outward.
45

45

00:01:44,190  -->  00:01:45,840
We're thinking about the attacker groups,
46

46

00:01:45,840  -->  00:01:47,670
we're thinking about malware outbreaks.
47

47

00:01:47,670  -->  00:01:50,610
We're thinking about zero-day exploits and things like that.
48

48

00:01:50,610  -->  00:01:53,010
All those bad things that are out there that can attack us
49

49

00:01:53,010  -->  00:01:55,200
and hurt us, that is what we're focused on
50

50

00:01:55,200  -->  00:01:57,270
when we're doing cyber threat intelligence.
51

51

00:01:57,270  -->  00:01:58,320
And we need both of these.
52

52

00:01:58,320  -->  00:01:59,640
We need to know our posture
53

53

00:01:59,640  -->  00:02:01,920
with security intelligence, but we also have to know
54

54

00:02:01,920  -->  00:02:05,160
what can attack us using cyber threat intelligence.
55

55

00:02:05,160  -->  00:02:07,110
Now, when we look at cyber threat intelligence,
56

56

00:02:07,110  -->  00:02:09,480
it really does come to us in two forms.
57

57

00:02:09,480  -->  00:02:10,380
It can come in the form
58

58

00:02:10,380  -->  00:02:12,780
of a narrative report or a data feed.
59

59

00:02:12,780  -->  00:02:14,910
Now, when we're dealing with a narrative report,
60

60

00:02:14,910  -->  00:02:16,830
this is going to give us the analysis
61

61

00:02:16,830  -->  00:02:20,130
of a certain adversary group or a certain type of malware,
62

62

00:02:20,130  -->  00:02:22,590
and we're going to get a written report based on that.
63

63

00:02:22,590  -->  00:02:24,583
There are a lot of places you can buy these from,
64

64

00:02:24,583  -->  00:02:27,810
and these come in a format that is really manually created
65

65

00:02:27,810  -->  00:02:29,700
by some threat analyst.
66

66

00:02:29,700  -->  00:02:31,890
And so if you get a job as an intelligence analyst
67

67

00:02:31,890  -->  00:02:34,950
or a threat analyst, you may spend all day going
68

68

00:02:34,950  -->  00:02:36,420
through different packet captures,
69

69

00:02:36,420  -->  00:02:37,890
and going through honeypots,
70

70

00:02:37,890  -->  00:02:39,810
and learning about some kind of adversary
71

71

00:02:39,810  -->  00:02:42,090
or malware, and then writing a report on it.
72

72

00:02:42,090  -->  00:02:44,640
And these reports are then sold to all the different SOCs
73

73

00:02:44,640  -->  00:02:46,830
around the world who use that in their defense
74

74

00:02:46,830  -->  00:02:47,910
of their networks.
75

75

00:02:47,910  -->  00:02:50,880
Now, this is very useful at a strategic level.
76

76

00:02:50,880  -->  00:02:53,100
This gives you intelligence about what the bad guys
77

77

00:02:53,100  -->  00:02:55,380
are doing, and that can help us decide
78

78

00:02:55,380  -->  00:02:56,700
where we want to put money
79

79

00:02:56,700  -->  00:02:58,650
and which security controls we want to have
80

80

00:02:58,650  -->  00:02:59,910
to be able able to defend ourself
81

81

00:02:59,910  -->  00:03:02,730
from these bad guys and their types of attacks.
82

82

00:03:02,730  -->  00:03:05,160
Now, on the other hand, we also have data feeds.
83

83

00:03:05,160  -->  00:03:08,310
And data feeds can be a list of known bad indicators,
84

84

00:03:08,310  -->  00:03:11,580
things like indicators of compromises, domain names,
85

85

00:03:11,580  -->  00:03:13,560
IP addresses, it might be something
86

86

00:03:13,560  -->  00:03:16,170
like hashes of exploit malware code.
87

87

00:03:16,170  -->  00:03:19,800
All of these type of things are tactical level information.
88

88

00:03:19,800  -->  00:03:21,720
This gives us something that is very operational.
89

89

00:03:21,720  -->  00:03:23,640
It's something we can do something with.
90

90

00:03:23,640  -->  00:03:26,970
If you tell me that this IP address is a known bad IP,
91

91

00:03:26,970  -->  00:03:28,470
I can block it in my firewall
92

92

00:03:28,470  -->  00:03:30,690
so no connections can go to it, right?
93

93

00:03:30,690  -->  00:03:32,460
That's the idea with a data feed.
94

94

00:03:32,460  -->  00:03:34,260
Now, which one is better?
95

95

00:03:34,260  -->  00:03:36,690
Do we want data feeds or narrative reports?
96

96

00:03:36,690  -->  00:03:38,340
Well, we want both.
97

97

00:03:38,340  -->  00:03:40,260
We don't want to use just one or the other.
98

98

00:03:40,260  -->  00:03:42,600
We have to use both to get the best security
99

99

00:03:42,600  -->  00:03:43,740
for our networks.
100

100

00:03:43,740  -->  00:03:45,180
We're going to use those narrative reports
101

101

00:03:45,180  -->  00:03:48,300
to get the big picture of what the landscape looks like
102

102

00:03:48,300  -->  00:03:49,860
and then we're going to use the data feeds
103

103

00:03:49,860  -->  00:03:51,930
to get those specific tactical things
104

104

00:03:51,930  -->  00:03:53,430
that we can program our sensors
105

105

00:03:53,430  -->  00:03:56,130
and our defenses against to be able to protect ourselves.
106

106

00:03:56,130  -->  00:03:59,490
Now, the combination of both of these is very useful to us
107

107

00:03:59,490  -->  00:04:01,620
and it allows us to have a better security posture
108

108

00:04:01,620  -->  00:04:02,970
for our organization.
109

109

00:04:02,970  -->  00:04:04,290
Now, if you want to be able to sign up
110

110

00:04:04,290  -->  00:04:06,840
for some of these data feeds or these narrative reports,
111

111

00:04:06,840  -->  00:04:08,280
your organization can do that.
112

112

00:04:08,280  -->  00:04:09,270
And most of this is done
113

113

00:04:09,270  -->  00:04:11,850
as a monthly subscription or a yearly subscription.
114

114

00:04:11,850  -->  00:04:13,740
There are a lot of companies out there that do this,
115

115

00:04:13,740  -->  00:04:18,720
like McAfee, FireEye, Red Canary, and many, many other ones.
116

116

00:04:18,720  -->  00:04:20,280
For example, if you want to learn more
117

117

00:04:20,280  -->  00:04:23,190
about a specific adversary or a certain tactic,
118

118

00:04:23,190  -->  00:04:24,600
you could search for that on Google
119

119

00:04:24,600  -->  00:04:27,780
or use your subscription to one of these services.
120

120

00:04:27,780  -->  00:04:29,400
In one of my previous organizations,
121

121

00:04:29,400  -->  00:04:31,710
we had a subscription to FireEye service.
122

122

00:04:31,710  -->  00:04:34,260
And so if I wanted to learn more about APT28,
123

123

00:04:34,260  -->  00:04:36,750
which happens to be a group of Russian hackers,
124

124

00:04:36,750  -->  00:04:39,420
I could learn more about them and the techniques they use.
125

125

00:04:39,420  -->  00:04:40,650
And in that report,
126

126

00:04:40,650  -->  00:04:42,900
it tells me what type of targets they're going after.
127

127

00:04:42,900  -->  00:04:45,420
Are they going after military or commercial targets?
128

128

00:04:45,420  -->  00:04:47,040
Are they going after the banking sector
129

129

00:04:47,040  -->  00:04:48,300
or the film industry?
130

130

00:04:48,300  -->  00:04:49,770
And then we can see how that affects me
131

131

00:04:49,770  -->  00:04:52,560
and my industry and how we can better defend against it.
132

132

00:04:52,560  -->  00:04:54,780
If you want to see an example of one of these reports,
133

133

00:04:54,780  -->  00:04:59,370
if you go to Google and type in APT28 FireEye PDF,
134

134

00:04:59,370  -->  00:05:00,630
this report will come up
135

135

00:05:00,630  -->  00:05:01,950
and you can see what these look like.
136

136

00:05:01,950  -->  00:05:03,900
They're generally around 20 to 30 pages
137

137

00:05:03,900  -->  00:05:04,740
and they give you a lot
138

138

00:05:04,740  -->  00:05:07,260
of great information about a particular adversary group
139

139

00:05:07,260  -->  00:05:08,943
or a specific malware type.
