1
1

00:00:00,450  -->  00:00:03,240
<v Instructor>The security intelligence cycle.</v>
2

2

00:00:03,240  -->  00:00:05,730
Now, intelligence is a process.
3

3

00:00:05,730  -->  00:00:07,590
It's not just about collecting data
4

4

00:00:07,590  -->  00:00:08,910
but you have to collect that data,
5

5

00:00:08,910  -->  00:00:10,740
you have to plan to collect that data
6

6

00:00:10,740  -->  00:00:12,600
and you have to go through and process that data
7

7

00:00:12,600  -->  00:00:13,800
and get it through.
8

8

00:00:13,800  -->  00:00:15,900
So, when you look at the process, it's going to start out
9

9

00:00:15,900  -->  00:00:18,360
with requirements, planning and direction.
10

10

00:00:18,360  -->  00:00:19,560
This is where we're going to be focused
11

11

00:00:19,560  -->  00:00:21,330
on what do we want to collect
12

12

00:00:21,330  -->  00:00:23,250
and figure out how we can best do that.
13

13

00:00:23,250  -->  00:00:25,140
Then we move into our second phase
14

14

00:00:25,140  -->  00:00:27,210
which is collection and processing.
15

15

00:00:27,210  -->  00:00:28,650
Now that we know what we want to collect,
16

16

00:00:28,650  -->  00:00:30,990
we have to go about actually collecting it.
17

17

00:00:30,990  -->  00:00:32,670
Third, we need to move into analysis
18

18

00:00:32,670  -->  00:00:34,770
where we start taking all that data we got
19

19

00:00:34,770  -->  00:00:36,450
and we start looking through it to try to make
20

20

00:00:36,450  -->  00:00:38,100
some decisions based on it.
21

21

00:00:38,100  -->  00:00:39,540
And then we move into our fourth phase,
22

22

00:00:39,540  -->  00:00:40,980
which is dissemination.
23

23

00:00:40,980  -->  00:00:43,650
This is how we take that information that we've analyzed
24

24

00:00:43,650  -->  00:00:45,420
and present it to other people.
25

25

00:00:45,420  -->  00:00:48,360
And then we move into our fifth phase, which is feedback.
26

26

00:00:48,360  -->  00:00:50,280
This is how we look back through the cycle,
27

27

00:00:50,280  -->  00:00:51,990
see what went right, what went wrong
28

28

00:00:51,990  -->  00:00:53,220
and what we could do better
29

29

00:00:53,220  -->  00:00:55,680
and then we started all over again.
30

30

00:00:55,680  -->  00:00:57,330
Let's take a little bit more in-depth look
31

31

00:00:57,330  -->  00:00:59,010
at each of these five phases
32

32

00:00:59,010  -->  00:01:01,860
as we move through the security intelligence cycle.
33

33

00:01:01,860  -->  00:01:04,680
First, we want to talk about the requirements phase.
34

34

00:01:04,680  -->  00:01:07,200
Now requirements is also planning and direction.
35

35

00:01:07,200  -->  00:01:09,540
The requirements phase is going to set out the goals
36

36

00:01:09,540  -->  00:01:11,850
for the intelligence gathering effort.
37

37

00:01:11,850  -->  00:01:14,580
At this point, we need to figure out what is it
38

38

00:01:14,580  -->  00:01:15,900
that we want to collect.
39

39

00:01:15,900  -->  00:01:17,700
That way we can figure out what are the things
40

40

00:01:17,700  -->  00:01:18,960
we care about?
41

41

00:01:18,960  -->  00:01:20,910
What do we want to spend the time, money
42

42

00:01:20,910  -->  00:01:22,680
and resources to gather?
43

43

00:01:22,680  -->  00:01:24,630
This is really important to have your goals set
44

44

00:01:24,630  -->  00:01:26,820
because if you don't understand what your goals are
45

45

00:01:26,820  -->  00:01:28,500
and you don't understand what your use case is
46

46

00:01:28,500  -->  00:01:30,240
for this data, you're going to be spending
47

47

00:01:30,240  -->  00:01:33,300
a lot of time and a lot of money collecting a lot of data
48

48

00:01:33,300  -->  00:01:35,130
for no reason at all.
49

49

00:01:35,130  -->  00:01:38,310
For example, if I worked for an auto manufacturer like Tesla
50

50

00:01:38,310  -->  00:01:41,490
or Honda or Ford, I would probably want to make sure
51

51

00:01:41,490  -->  00:01:42,840
that we are gathering intelligence
52

52

00:01:42,840  -->  00:01:45,270
on any threats to automobile systems.
53

53

00:01:45,270  -->  00:01:47,040
Especially if you're somebody like Tesla
54

54

00:01:47,040  -->  00:01:49,020
that is trying to work towards self-driving cars,
55

55

00:01:49,020  -->  00:01:51,330
there's a big cyber threat component to that.
56

56

00:01:51,330  -->  00:01:53,100
And so we'd want to be looking out there
57

57

00:01:53,100  -->  00:01:56,130
at the entire landscape to figure out what adversaries
58

58

00:01:56,130  -->  00:01:58,290
are out there, what APTs are out there
59

59

00:01:58,290  -->  00:02:00,600
and what type of malware and vulnerabilities are out there
60

60

00:02:00,600  -->  00:02:03,000
for our type of systems that could affect the safety
61

61

00:02:03,000  -->  00:02:04,410
of our systems.
62

62

00:02:04,410  -->  00:02:06,750
Consequently, we might also look at any kind of things
63

63

00:02:06,750  -->  00:02:08,640
that would affect our supply chain.
64

64

00:02:08,640  -->  00:02:10,920
We have to buy those computers from somewhere, right?
65

65

00:02:10,920  -->  00:02:12,630
And so we need to make sure we understand what
66

66

00:02:12,630  -->  00:02:15,840
threats exist there and how we can mitigate those risks.
67

67

00:02:15,840  -->  00:02:17,910
There's a lot of information out there
68

68

00:02:17,910  -->  00:02:20,160
and what the idea here in requirements gathering
69

69

00:02:20,160  -->  00:02:22,650
the planning and direction is figuring out what are
70

70

00:02:22,650  -->  00:02:24,420
the things we want to measure?
71

71

00:02:24,420  -->  00:02:26,070
That's what we have to deal with here.
72

72

00:02:26,070  -->  00:02:27,270
Now, another thing we have to think
73

73

00:02:27,270  -->  00:02:30,000
about here is thinking about any kind of special factors
74

74

00:02:30,000  -->  00:02:31,440
or constraints we might have.
75

75

00:02:31,440  -->  00:02:33,900
For example, if you work for the government,
76

76

00:02:33,900  -->  00:02:36,510
there are certain things you can and cannot collect
77

77

00:02:36,510  -->  00:02:38,460
on your citizens depending on what government
78

78

00:02:38,460  -->  00:02:39,750
you are in the world.
79

79

00:02:39,750  -->  00:02:41,970
For example, I'm in the United States.
80

80

00:02:41,970  -->  00:02:44,400
The US has a policy that they cannot collect
81

81

00:02:44,400  -->  00:02:46,290
information on US citizens.
82

82

00:02:46,290  -->  00:02:49,260
So if you work for the NSA or the CIA,
83

83

00:02:49,260  -->  00:02:51,210
they are not allowed to collect information on me
84

84

00:02:51,210  -->  00:02:52,290
as a US citizen.
85

85

00:02:52,290  -->  00:02:54,000
No matter if I'm sitting in the United States
86

86

00:02:54,000  -->  00:02:56,580
or if I'm sitting abroad, if I'm a US citizen,
87

87

00:02:56,580  -->  00:02:57,870
they can't collect on me.
88

88

00:02:57,870  -->  00:02:59,280
That's part of the rules.
89

89

00:02:59,280  -->  00:03:01,260
And so there are legal restrictions on what they can
90

90

00:03:01,260  -->  00:03:02,340
and cannot do.
91

91

00:03:02,340  -->  00:03:04,410
For instance, if they wanted to collect information on me,
92

92

00:03:04,410  -->  00:03:06,719
they would have to go and get a warrant to do
93

93

00:03:06,719  -->  00:03:08,640
that because as a US citizen, I am protected by
94

94

00:03:08,640  -->  00:03:12,060
the fourth amendment against unlawful search and seizure.
95

95

00:03:12,060  -->  00:03:13,560
Every country has different rules,
96

96

00:03:13,560  -->  00:03:15,120
every location has different rules.
97

97

00:03:15,120  -->  00:03:17,550
So your organization is going to have to consider that
98

98

00:03:17,550  -->  00:03:20,730
as you're planning what your collection process is going to be.
99

99

00:03:20,730  -->  00:03:22,230
So now that we've considered all of that
100

100

00:03:22,230  -->  00:03:23,940
and we've figured out what we want a plan to do,
101

101

00:03:23,940  -->  00:03:26,040
we now need to actually move into collection.
102

102

00:03:26,040  -->  00:03:28,860
And the second phase is collection and processing.
103

103

00:03:28,860  -->  00:03:31,500
The collection process is implemented by software tools
104

104

00:03:31,500  -->  00:03:35,220
such as SIEMS and then it's processed for later analysis.
105

105

00:03:35,220  -->  00:03:36,540
Now, when we collect things,
106

106

00:03:36,540  -->  00:03:38,370
this is where we're gathering all the data.
107

107

00:03:38,370  -->  00:03:40,350
So if I put a network sensor out there
108

108

00:03:40,350  -->  00:03:43,170
that's collecting PCAP data, packet capture data,
109

109

00:03:43,170  -->  00:03:44,580
it can collect all that information
110

110

00:03:44,580  -->  00:03:46,680
and send it back to a centralized server.
111

111

00:03:46,680  -->  00:03:48,510
I may collect logs from a router
112

112

00:03:48,510  -->  00:03:50,040
from an intrusion detection system,
113

113

00:03:50,040  -->  00:03:52,890
from a firewall, from servers, from endpoints.
114

114

00:03:52,890  -->  00:03:55,890
All that data has to be collected and then sent someplace.
115

115

00:03:55,890  -->  00:03:57,990
Generally, we'll put this into a SIEM
116

116

00:03:57,990  -->  00:04:00,930
which is a security information and event management system
117

117

00:04:00,930  -->  00:04:02,670
and then we can use that as our center point
118

118

00:04:02,670  -->  00:04:04,140
of all the collection.
119

119

00:04:04,140  -->  00:04:06,660
Now, the one challenge we have though is that all this data
120

120

00:04:06,660  -->  00:04:08,610
is coming from different systems, right?
121

121

00:04:08,610  -->  00:04:10,830
Well, when all this stuff is coming from different systems,
122

122

00:04:10,830  -->  00:04:12,990
it might come in a different format.
123

123

00:04:12,990  -->  00:04:15,330
So we need to normalize that data
124

124

00:04:15,330  -->  00:04:17,190
and that is the processing part.
125

125

00:04:17,190  -->  00:04:18,750
This is where we'll convert all the data
126

126

00:04:18,750  -->  00:04:21,510
into a standard format that a single solution
127

127

00:04:21,510  -->  00:04:23,640
like a single SIEM can actually use.
128

128

00:04:23,640  -->  00:04:25,530
This means all the source IP addresses will be
129

129

00:04:25,530  -->  00:04:26,520
in a certain column
130

130

00:04:26,520  -->  00:04:28,560
all the destinations will be in another column,
131

131

00:04:28,560  -->  00:04:30,540
all the timestamps will be in a third column.
132

132

00:04:30,540  -->  00:04:33,510
And this way we can search and index all this information
133

133

00:04:33,510  -->  00:04:35,910
and use it as we search for those things later on
134

134

00:04:35,910  -->  00:04:37,830
in our analysis cycle.
135

135

00:04:37,830  -->  00:04:39,600
Now, another consideration you have to think about is
136

136

00:04:39,600  -->  00:04:41,730
how are you going to keep all this data secure?
137

137

00:04:41,730  -->  00:04:44,070
So we just took all this data from across our network
138

138

00:04:44,070  -->  00:04:46,470
and all of our sensors and put it in the SIEM.
139

139

00:04:46,470  -->  00:04:49,050
Well, we need to make sure we protect that SIEM too.
140

140

00:04:49,050  -->  00:04:51,720
And so we might be using things like encryption on the SIEM,
141

141

00:04:51,720  -->  00:04:54,210
we might be using things like access control in the SIEM
142

142

00:04:54,210  -->  00:04:56,610
and we might be using things for integrity like hashing
143

143

00:04:56,610  -->  00:04:57,600
on the SIEM.
144

144

00:04:57,600  -->  00:05:00,030
All that data needs to be protected as well, because
145

145

00:05:00,030  -->  00:05:03,273
if it's useful to us, it could also be useful to an attack.
146

146

00:05:03,273  -->  00:05:05,550
The third step we're going to have is going into
147

147

00:05:05,550  -->  00:05:07,350
the analysis process.
148

148

00:05:07,350  -->  00:05:09,330
Now, the analysis phase is performed
149

149

00:05:09,330  -->  00:05:11,340
against the giving use cases that we had
150

150

00:05:11,340  -->  00:05:12,630
from our planning phase
151

151

00:05:12,630  -->  00:05:15,720
and we can utilize things like automated analysis,
152

152

00:05:15,720  -->  00:05:18,090
artificial intelligence, and machine learning.
153

153

00:05:18,090  -->  00:05:19,470
Now, this is really important
154

154

00:05:19,470  -->  00:05:21,810
because there is so much data that we are collecting
155

155

00:05:21,810  -->  00:05:24,540
at this point that a single person cannot read it
156

156

00:05:24,540  -->  00:05:26,280
and analyze it fast enough.
157

157

00:05:26,280  -->  00:05:29,610
So we have to use some sort of way to automate this.
158

158

00:05:29,610  -->  00:05:32,010
So these days one of the most common ways of attacking this
159

159

00:05:32,010  -->  00:05:35,370
problem is by separating our data first into three buckets.
160

160

00:05:35,370  -->  00:05:36,900
First, what do we know is good?
161

161

00:05:36,900  -->  00:05:38,580
Second, what do we know is bad?
162

162

00:05:38,580  -->  00:05:40,410
And third, what we're really concerned with
163

163

00:05:40,410  -->  00:05:42,690
is what we're not sure of because again,
164

164

00:05:42,690  -->  00:05:44,490
if it's known good, we're going to allow it,
165

165

00:05:44,490  -->  00:05:46,560
if it's known bad, we're going to block it,
166

166

00:05:46,560  -->  00:05:48,930
if we're not sure, that's where further analysis
167

167

00:05:48,930  -->  00:05:49,950
needs to be done.
168

168

00:05:49,950  -->  00:05:52,410
Now, because of there's so much data at this point,
169

169

00:05:52,410  -->  00:05:54,240
we have to use things like machine learning
170

170

00:05:54,240  -->  00:05:56,400
and artificial intelligence to help our humans
171

171

00:05:56,400  -->  00:05:57,990
go through this data data because there is just
172

172

00:05:57,990  -->  00:06:00,780
so much stuff going over our networks.
173

173

00:06:00,780  -->  00:06:03,240
This allows us, again, because of our processing,
174

174

00:06:03,240  -->  00:06:04,500
we've normalized it,
175

175

00:06:04,500  -->  00:06:06,750
and now in our analysis, we can filter it,
176

176

00:06:06,750  -->  00:06:08,700
we can organize it into a useful form
177

177

00:06:08,700  -->  00:06:10,740
and we can start doing our analysis on it.
178

178

00:06:10,740  -->  00:06:12,990
Now, all of the analysis we do should be done
179

179

00:06:12,990  -->  00:06:14,910
in the context of a use case.
180

180

00:06:14,910  -->  00:06:16,950
And these use cases are something that we developed
181

181

00:06:16,950  -->  00:06:19,080
all the way back in our planning phase.
182

182

00:06:19,080  -->  00:06:21,690
This says, I'm interested in this type of information
183

183

00:06:21,690  -->  00:06:23,250
for this reason
184

184

00:06:23,250  -->  00:06:25,260
because there might be some interesting information
185

185

00:06:25,260  -->  00:06:27,060
but if it doesn't impact business decisions
186

186

00:06:27,060  -->  00:06:29,910
for you and your organization, why do you even care?
187

187

00:06:29,910  -->  00:06:31,440
And that's the idea here.
188

188

00:06:31,440  -->  00:06:33,930
Our job here is to go through these large data sets
189

189

00:06:33,930  -->  00:06:36,870
and we want to start figuring out what doesn't look right,
190

190

00:06:36,870  -->  00:06:39,600
what looks funky, what is not going to be good
191

191

00:06:39,600  -->  00:06:40,890
for our organization
192

192

00:06:40,890  -->  00:06:43,410
and we want to start building our models against that.
193

193

00:06:43,410  -->  00:06:45,570
For example, if I start looking through the domain
194

194

00:06:45,570  -->  00:06:48,210
authentications that are occurring in your organization,
195

195

00:06:48,210  -->  00:06:49,560
and I know what good looks like
196

196

00:06:49,560  -->  00:06:50,850
and I know what bad looks like,
197

197

00:06:50,850  -->  00:06:52,950
there may be some things there that are suspect
198

198

00:06:52,950  -->  00:06:55,350
and it may be the indication of an insider threat.
199

199

00:06:55,350  -->  00:06:56,670
And so if I'm looking at that
200

200

00:06:56,670  -->  00:06:59,160
through the lens of an insider threat use case,
201

201

00:06:59,160  -->  00:07:01,410
that will help me do my analysis better
202

202

00:07:01,410  -->  00:07:03,180
and use the right filters and query strings
203

203

00:07:03,180  -->  00:07:05,490
to extract the relevant data that I need.
204

204

00:07:05,490  -->  00:07:07,920
Now, the fourth phase is dissemination.
205

205

00:07:07,920  -->  00:07:10,110
And the dissemination phase refers to publishing
206

206

00:07:10,110  -->  00:07:12,900
the information produced by an analyst to a consumer
207

207

00:07:12,900  -->  00:07:15,420
who needs to act on the insights developed.
208

208

00:07:15,420  -->  00:07:18,000
Now, this can take a lot of different forms, and it depends
209

209

00:07:18,000  -->  00:07:21,390
on your organization and what the intended audience is.
210

210

00:07:21,390  -->  00:07:24,000
You may have oral reports, you may have written reports,
211

211

00:07:24,000  -->  00:07:25,770
you may have a PowerPoint presentation,
212

212

00:07:25,770  -->  00:07:26,880
you may have an email.
213

213

00:07:26,880  -->  00:07:29,340
It really does depend on your organization.
214

214

00:07:29,340  -->  00:07:31,350
Now, three of the most common ways we'd like to break
215

215

00:07:31,350  -->  00:07:34,320
up this dissemination is into the level of intelligence.
216

216

00:07:34,320  -->  00:07:37,770
It can be strategic, operational, or tactical.
217

217

00:07:37,770  -->  00:07:39,210
When strategic intelligence,
218

218

00:07:39,210  -->  00:07:41,730
this is going to address broad themes and objectives
219

219

00:07:41,730  -->  00:07:43,350
and these usually affect projects
220

220

00:07:43,350  -->  00:07:47,130
and business priorities over weeks, months, and years.
221

221

00:07:47,130  -->  00:07:50,730
Most often I see this done as a report to an executive
222

222

00:07:50,730  -->  00:07:53,760
or a PowerPoint presentation in a large group.
223

223

00:07:53,760  -->  00:07:56,370
The second one we have is operational intelligence.
224

224

00:07:56,370  -->  00:07:58,290
Now, operational intelligence is going to address
225

225

00:07:58,290  -->  00:08:01,200
the day-to-day priorities of managers and specialists.
226

226

00:08:01,200  -->  00:08:04,080
Oftentimes, I'll see this put out as a checklist of
227

227

00:08:04,080  -->  00:08:06,180
these are the things you should be worried about today
228

228

00:08:06,180  -->  00:08:08,730
and these are the things we need to focus on today.
229

229

00:08:08,730  -->  00:08:11,160
The third type we have is tactical intelligence.
230

230

00:08:11,160  -->  00:08:13,890
And tactical intelligence informs real-time decisions
231

231

00:08:13,890  -->  00:08:16,500
made by staff as they encounter different alerts
232

232

00:08:16,500  -->  00:08:18,000
and system indications.
233

233

00:08:18,000  -->  00:08:20,220
So if you're sitting there on the SOC watch floor
234

234

00:08:20,220  -->  00:08:22,200
and you see an alert pop up on your screen
235

235

00:08:22,200  -->  00:08:24,480
that is considered tactical intelligence.
236

236

00:08:24,480  -->  00:08:27,780
It needs to be dealt with right now, and it is real time.
237

237

00:08:27,780  -->  00:08:30,660
Our fifth and final phase of the cycle is feedback
238

238

00:08:30,660  -->  00:08:31,710
and review.
239

239

00:08:31,710  -->  00:08:34,590
Now, this phase is going to aim to clarify the requirements
240

240

00:08:34,590  -->  00:08:37,320
and improve the collection, analysis, and dissemination
241

241

00:08:37,320  -->  00:08:40,620
of information by reviewing the current inputs and outputs.
242

242

00:08:40,620  -->  00:08:42,900
Basically, how can we do things better?
243

243

00:08:42,900  -->  00:08:44,040
That's our goal.
244

244

00:08:44,040  -->  00:08:45,930
We always want to improve the implementation
245

245

00:08:45,930  -->  00:08:48,210
of our requirements, our collection, our analysis
246

246

00:08:48,210  -->  00:08:51,030
and dissemination, and how we can improve over time
247

247

00:08:51,030  -->  00:08:53,040
and get better at what we do.
248

248

00:08:53,040  -->  00:08:54,900
For example, you might be doing things
249

249

00:08:54,900  -->  00:08:57,900
like lessons learned by figuring out what incidents occurred
250

250

00:08:57,900  -->  00:09:00,060
during the intelligence gathering this cycle
251

251

00:09:00,060  -->  00:09:02,220
so we can avoid those problems next cycle.
252

252

00:09:02,220  -->  00:09:04,740
We might want to figure out how we're going to measure success,
253

253

00:09:04,740  -->  00:09:07,200
what metrics are going to show us success or failure
254

254

00:09:07,200  -->  00:09:09,210
of the intelligence gathering.
255

255

00:09:09,210  -->  00:09:11,670
We also want to think about evolving threat issues.
256

256

00:09:11,670  -->  00:09:13,440
Maybe we've been looking a lot for phishing
257

257

00:09:13,440  -->  00:09:15,780
but now we're seeing that phishing isn't popular.
258

258

00:09:15,780  -->  00:09:18,360
Instead, people are going against bring your own devices
259

259

00:09:18,360  -->  00:09:20,400
and so we want to start shifting our intelligence collection
260

260

00:09:20,400  -->  00:09:21,840
towards that threat vector.
261

261

00:09:21,840  -->  00:09:23,820
These are the kind of things you want to think about as
262

262

00:09:23,820  -->  00:09:25,770
you move through the intelligence lifecycle.
263

263

00:09:25,770  -->  00:09:28,560
So one more time, as a quick review, the five phases
264

264

00:09:28,560  -->  00:09:30,420
of the intelligence lifecycle are:
265

265

00:09:30,420  -->  00:09:33,090
one, requirements planning and direction,
266

266

00:09:33,090  -->  00:09:35,190
two, collection and processing
267

267

00:09:35,190  -->  00:09:40,083
three, analysis, four, dissemination, and five, feedback.
