1
1

00:00:00,300  -->  00:00:02,340
<v Lecturer>Intelligence Sources.</v>
2

2

00:00:02,340  -->  00:00:05,700
Now, in addition to having our five phases of the lifecycle,
3

3

00:00:05,700  -->  00:00:07,320
we have to dive a little bit deeper
4

4

00:00:07,320  -->  00:00:08,970
into one particular phase:
5

5

00:00:08,970  -->  00:00:11,280
The collection and processing phase.
6

6

00:00:11,280  -->  00:00:13,170
This is important because we have to consider
7

7

00:00:13,170  -->  00:00:15,420
the sources of our intelligence.
8

8

00:00:15,420  -->  00:00:17,040
Now, there are lots of different sources
9

9

00:00:17,040  -->  00:00:18,900
to our intelligence that we can get out there,
10

10

00:00:18,900  -->  00:00:20,880
but not all are created equal.
11

11

00:00:20,880  -->  00:00:23,430
And so we have to be able to identify some factors
12

12

00:00:23,430  -->  00:00:26,700
to weigh the value of the intelligence that we're getting.
13

13

00:00:26,700  -->  00:00:29,010
Now, there are several factors that we can use.
14

14

00:00:29,010  -->  00:00:32,460
There is timeliness, relevancy, accuracy,
15

15

00:00:32,460  -->  00:00:34,020
and confidence level.
16

16

00:00:34,020  -->  00:00:35,610
When we talk about timeliness,
17

17

00:00:35,610  -->  00:00:37,890
this is the property of an intelligence source
18

18

00:00:37,890  -->  00:00:40,980
that ensures that it is up-to-date, because over time,
19

19

00:00:40,980  -->  00:00:43,590
the information is not nearly as valuable.
20

20

00:00:43,590  -->  00:00:45,270
If I know that somebody has been attacking
21

21

00:00:45,270  -->  00:00:47,370
your network today and I don't tell you about it
22

22

00:00:47,370  -->  00:00:50,400
for three years, it's not going to be very useful to you.
23

23

00:00:50,400  -->  00:00:52,980
It'd be a lot more useful if I told you today.
24

24

00:00:52,980  -->  00:00:54,930
And so that's the idea with timeliness,
25

25

00:00:54,930  -->  00:00:56,910
because once an adversary understands
26

26

00:00:56,910  -->  00:00:59,460
they've been identified, they're going to change tactics
27

27

00:00:59,460  -->  00:01:01,440
and they're going to change the way they do things.
28

28

00:01:01,440  -->  00:01:03,720
And that means your report that you wrote today
29

29

00:01:03,720  -->  00:01:07,410
may not be valid in a week, three weeks, three months,
30

30

00:01:07,410  -->  00:01:09,930
or three years from now because things change,
31

31

00:01:09,930  -->  00:01:11,910
and so timeliness is important.
32

32

00:01:11,910  -->  00:01:14,160
Our second factor is relevancy.
33

33

00:01:14,160  -->  00:01:16,260
Now, this is the property of an intelligence source
34

34

00:01:16,260  -->  00:01:19,560
that ensures it matches the use case it was intended for.
35

35

00:01:19,560  -->  00:01:21,150
Let's go back to my example of working
36

36

00:01:21,150  -->  00:01:23,100
for a large auto manufacturer.
37

37

00:01:23,100  -->  00:01:25,260
If I start seeing that there's a lot of attacks
38

38

00:01:25,260  -->  00:01:27,990
going against the Mac OS X operating system,
39

39

00:01:27,990  -->  00:01:30,150
does that really apply to me as somebody
40

40

00:01:30,150  -->  00:01:34,050
who is running a car company and is using Windows machines
41

41

00:01:34,050  -->  00:01:37,320
or is using Linux in my embedded systems?
42

42

00:01:37,320  -->  00:01:38,310
Probably not.
43

43

00:01:38,310  -->  00:01:40,020
And so it's not nearly relevant to me
44

44

00:01:40,020  -->  00:01:41,220
for the use case I have.
45

45

00:01:41,220  -->  00:01:42,600
And so you need to consider that as you're looking
46

46

00:01:42,600  -->  00:01:44,010
at all the different information out there
47

47

00:01:44,010  -->  00:01:45,780
because it can be overwhelming.
48

48

00:01:45,780  -->  00:01:49,200
And you have to think what affects me and my organization
49

49

00:01:49,200  -->  00:01:50,880
so I can defend against it.
50

50

00:01:50,880  -->  00:01:52,980
The third area is accuracy.
51

51

00:01:52,980  -->  00:01:55,500
Now accuracy is the property of an intelligence source
52

52

00:01:55,500  -->  00:01:58,350
that ensures that it produces effective results.
53

53

00:01:58,350  -->  00:02:00,510
Now, this means that the information needs
54

54

00:02:00,510  -->  00:02:02,070
to be valid and true.
55

55

00:02:02,070  -->  00:02:03,690
If you tell me that I've been attacked
56

56

00:02:03,690  -->  00:02:05,490
and I look and I can't find anything,
57

57

00:02:05,490  -->  00:02:09,000
well, was I really attacked, or was your information bad?
58

58

00:02:09,000  -->  00:02:10,260
We really don't know.
59

59

00:02:10,260  -->  00:02:11,550
And so it's really important to make sure
60

60

00:02:11,550  -->  00:02:13,770
the information we're getting is accurate.
61

61

00:02:13,770  -->  00:02:15,120
This means we want to try to eliminate
62

62

00:02:15,120  -->  00:02:17,070
as many false positives as possible,
63

63

00:02:17,070  -->  00:02:19,110
especially when using automated software
64

64

00:02:19,110  -->  00:02:21,540
and machine learning and artificial intelligence,
65

65

00:02:21,540  -->  00:02:23,910
and make sure that we're getting the right information
66

66

00:02:23,910  -->  00:02:25,830
so that we can do our analysis properly
67

67

00:02:25,830  -->  00:02:28,590
on good information and create good decisions.
68

68

00:02:28,590  -->  00:02:30,540
The fourth and final factor we have to consider
69

69

00:02:30,540  -->  00:02:32,040
is confidence levels.
70

70

00:02:32,040  -->  00:02:34,260
Now, this is the property of an intelligence source
71

71

00:02:34,260  -->  00:02:36,330
that ensures it produces qualified statements
72

72

00:02:36,330  -->  00:02:38,130
about reliability.
73

73

00:02:38,130  -->  00:02:39,690
When an analyst publishes report,
74

74

00:02:39,690  -->  00:02:41,730
they don't have a hundred percent of the facts.
75

75

00:02:41,730  -->  00:02:43,200
It's just the way this works.
76

76

00:02:43,200  -->  00:02:45,480
We're trying to guess our way through this
77

77

00:02:45,480  -->  00:02:47,010
and we're getting lots of different pieces
78

78

00:02:47,010  -->  00:02:49,230
of information and lots of different indicators
79

79

00:02:49,230  -->  00:02:52,290
and we try to put together the best report we can.
80

80

00:02:52,290  -->  00:02:53,520
Well, when we deal with this
81

81

00:02:53,520  -->  00:02:55,230
and we start taking all these sources,
82

82

00:02:55,230  -->  00:02:58,020
we have to look at these sources and figure out:
83

83

00:02:58,020  -->  00:02:59,430
Are they reliable?
84

84

00:02:59,430  -->  00:03:00,263
Are they accurate?
85

85

00:03:00,263  -->  00:03:01,950
Are they relevant and are they timely?
86

86

00:03:01,950  -->  00:03:03,750
And we start talking about confidence level.
87

87

00:03:03,750  -->  00:03:05,880
We're going to actually put a grade on it
88

88

00:03:05,880  -->  00:03:08,610
of how good we think that information is.
89

89

00:03:08,610  -->  00:03:11,250
For example, the MISP Project codifies the use
90

90

00:03:11,250  -->  00:03:12,270
of the admiralty scale
91

91

00:03:12,270  -->  00:03:14,850
for grading data and estimative language.
92

92

00:03:14,850  -->  00:03:16,740
Now, you can choose any scale you want,
93

93

00:03:16,740  -->  00:03:19,620
but the admiralty scale is one of the more common ones.
94

94

00:03:19,620  -->  00:03:22,770
The way this works is that it breaks it down into two areas.
95

95

00:03:22,770  -->  00:03:25,050
It evaluates you based on source reliability
96

96

00:03:25,050  -->  00:03:26,670
and information content.
97

97

00:03:26,670  -->  00:03:28,590
If I look at the source reliability,
98

98

00:03:28,590  -->  00:03:31,590
this is going to get a letter grade from A through F.
99

99

00:03:31,590  -->  00:03:33,570
It tells you if it's reliable all the way down
100

100

00:03:33,570  -->  00:03:35,790
to I can't judge the reliability.
101

101

00:03:35,790  -->  00:03:37,710
For example, if I got this piece of data
102

102

00:03:37,710  -->  00:03:40,020
from my own sensors and I trust them
103

103

00:03:40,020  -->  00:03:41,760
and there's no doubt this is reliable,
104

104

00:03:41,760  -->  00:03:43,500
give it a grade of A.
105

105

00:03:43,500  -->  00:03:45,990
Next we have the information content,
106

106

00:03:45,990  -->  00:03:49,320
and when we grade this, we do it on a scale of 1 to 6.
107

107

00:03:49,320  -->  00:03:50,790
Now, when we grade this from 1 to 6,
108

108

00:03:50,790  -->  00:03:52,770
we're going to say that this could be confirmed
109

109

00:03:52,770  -->  00:03:54,540
or it cannot be judged.
110

110

00:03:54,540  -->  00:03:55,373
When I confirmed it,
111

111

00:03:55,373  -->  00:03:57,960
this means that I had multiple independent sources
112

112

00:03:57,960  -->  00:03:59,610
that told me this information.
113

113

00:03:59,610  -->  00:04:02,040
It's not just hearsay from one person.
114

114

00:04:02,040  -->  00:04:03,630
Now, as I go down the scale,
115

115

00:04:03,630  -->  00:04:05,670
I get less and less stringent
116

116

00:04:05,670  -->  00:04:07,500
on how well I can confirm that information
117

117

00:04:07,500  -->  00:04:09,540
all the way down to cannot be judged,
118

118

00:04:09,540  -->  00:04:12,180
which means it's basically just a best guess.
119

119

00:04:12,180  -->  00:04:14,040
Now, this is useful, especially when reporting
120

120

00:04:14,040  -->  00:04:16,710
up to higher authorities or up to your bosses.
121

121

00:04:16,710  -->  00:04:19,290
Because you can say, "Hey, I have this information.
122

122

00:04:19,290  -->  00:04:20,520
I heard there's this threat,
123

123

00:04:20,520  -->  00:04:22,440
but I'm not real confident about it.
124

124

00:04:22,440  -->  00:04:24,660
It only has a grade letter of C."
125

125

00:04:24,660  -->  00:04:26,280
And you going to take less actions against that
126

126

00:04:26,280  -->  00:04:28,560
maybe than something that has a strength of A,
127

127

00:04:28,560  -->  00:04:30,180
because A is much more certain.
128

128

00:04:30,180  -->  00:04:31,260
And this is the idea when you deal
129

129

00:04:31,260  -->  00:04:32,550
with the admiralty scale.
130

130

00:04:32,550  -->  00:04:35,010
For the exam, you do not need to know the admiralty scale
131

131

00:04:35,010  -->  00:04:37,590
in depth, but it is something I wanted to make you aware of
132

132

00:04:37,590  -->  00:04:39,810
because you may see it out in the workplace.
133

133

00:04:39,810  -->  00:04:41,130
Now, the next thing we need to talk about
134

134

00:04:41,130  -->  00:04:43,380
is the three places you can get information from.
135

135

00:04:43,380  -->  00:04:46,440
You can find information that's proprietary, closed-source,
136

136

00:04:46,440  -->  00:04:47,760
or open-source.
137

137

00:04:47,760  -->  00:04:50,790
The first source we have is what's known as proprietary.
138

138

00:04:50,790  -->  00:04:52,620
Proprietary is threat intelligence
139

139

00:04:52,620  -->  00:04:55,080
that comes as a commercial service offering,
140

140

00:04:55,080  -->  00:04:57,240
where you're going to pay for access to these updates
141

141

00:04:57,240  -->  00:04:59,670
and research based on a subscription fee.
142

142

00:04:59,670  -->  00:05:01,800
Now, some of these commercial services are really
143

143

00:05:01,800  -->  00:05:03,900
just repackaging information that's available
144

144

00:05:03,900  -->  00:05:05,970
in free public registries without providing
145

145

00:05:05,970  -->  00:05:08,070
of any of their own data inside of it,
146

146

00:05:08,070  -->  00:05:09,870
and these aren't nearly as useful.
147

147

00:05:09,870  -->  00:05:11,250
This brings us to the second type
148

148

00:05:11,250  -->  00:05:13,050
which is closed-source data.
149

149

00:05:13,050  -->  00:05:15,660
Now, closed-source data is data that's derived
150

150

00:05:15,660  -->  00:05:18,240
from the provider's own research and analysis efforts,
151

151

00:05:18,240  -->  00:05:20,670
such as data from honeynets as they operate,
152

152

00:05:20,670  -->  00:05:22,080
plus information that's mined
153

153

00:05:22,080  -->  00:05:25,290
from their other customer systems and suitably anonymized.
154

154

00:05:25,290  -->  00:05:28,410
So for example, if you and a hundred thousand other people
155

155

00:05:28,410  -->  00:05:30,390
all subscribe to a certain service
156

156

00:05:30,390  -->  00:05:32,010
and they're monitoring your networks,
157

157

00:05:32,010  -->  00:05:33,270
they can collect all that data
158

158

00:05:33,270  -->  00:05:34,860
from the 100,000 users
159

159

00:05:34,860  -->  00:05:36,570
and then be able to make analysis
160

160

00:05:36,570  -->  00:05:39,720
and reports based off of that in an anonymized fashion
161

161

00:05:39,720  -->  00:05:41,370
back to those 100,000 users
162

162

00:05:41,370  -->  00:05:43,620
so you all can share the information.
163

163

00:05:43,620  -->  00:05:45,510
Now, a good example of this is Mandiant.
164

164

00:05:45,510  -->  00:05:47,820
Mandiant is a proprietary information source
165

165

00:05:47,820  -->  00:05:49,080
that is closed-source.
166

166

00:05:49,080  -->  00:05:51,870
They provide their own data, and you can subscribe using
167

167

00:05:51,870  -->  00:05:53,820
their threat intelligence subscription service
168

168

00:05:53,820  -->  00:05:55,653
to get data and updates from them.
169

169

00:05:56,520  -->  00:05:59,730
Now, the third type we have is what's known as open-source.
170

170

00:05:59,730  -->  00:06:01,800
Open sources data that's available for use
171

171

00:06:01,800  -->  00:06:03,030
without a subscription,
172

172

00:06:03,030  -->  00:06:04,860
and this may include threat feeds similar
173

173

00:06:04,860  -->  00:06:07,950
to commercial providers, and it can contain reputation list
174

174

00:06:07,950  -->  00:06:10,230
and malware signature databases too.
175

175

00:06:10,230  -->  00:06:11,670
There are a lot of great sources
176

176

00:06:11,670  -->  00:06:13,560
of open-source intelligence out there.
177

177

00:06:13,560  -->  00:06:15,600
And so if your organization is a little weary
178

178

00:06:15,600  -->  00:06:17,040
about spending a lot of money
179

179

00:06:17,040  -->  00:06:18,990
on commercial source information,
180

180

00:06:18,990  -->  00:06:20,970
they can start out with open-source information
181

181

00:06:20,970  -->  00:06:23,130
and then upgrade from there later on.
182

182

00:06:23,130  -->  00:06:25,020
Now, when you talk about open-source intelligence,
183

183

00:06:25,020  -->  00:06:27,060
there are lots of different sources.
184

184

00:06:27,060  -->  00:06:29,610
First, we have the US-CERT, which is the United States
185

185

00:06:29,610  -->  00:06:31,770
Computer Emergency Readiness Team.
186

186

00:06:31,770  -->  00:06:33,630
This provides you with feeds of current activity
187

187

00:06:33,630  -->  00:06:37,020
and alert news, plus regular bulletins and analysis reports.
188

188

00:06:37,020  -->  00:06:38,910
They also have a bidirectional threat feed
189

189

00:06:38,910  -->  00:06:41,910
called the Automated Indicator Service that you can use.
190

190

00:06:41,910  -->  00:06:42,743
The next one we have
191

191

00:06:42,743  -->  00:06:45,510
is the UK's National Cyber Security Centre,
192

192

00:06:45,510  -->  00:06:48,990
which provides similar services to the US-CERT.
193

193

00:06:48,990  -->  00:06:50,640
There are some other ones out there as well, though.
194

194

00:06:50,640  -->  00:06:53,040
We have AT&amp;T Security, which was actually
195

195

00:06:53,040  -->  00:06:55,620
AlienVault Open Threat Exchange previously,
196

196

00:06:55,620  -->  00:06:57,570
but was bought out by AT&amp;T.
197

197

00:06:57,570  -->  00:07:00,390
After that, we have MISP, which we talked about before.
198

198

00:07:00,390  -->  00:07:02,670
This is the Malware Information Sharing Project.
199

199

00:07:02,670  -->  00:07:04,830
And again, it's an open-source intelligence feed
200

200

00:07:04,830  -->  00:07:06,150
that you can use.
201

201

00:07:06,150  -->  00:07:08,580
We also have VirusTotal, which is a great place
202

202

00:07:08,580  -->  00:07:10,770
to upload any file you're not sure of.
203

203

00:07:10,770  -->  00:07:11,820
If you upload this file,
204

204

00:07:11,820  -->  00:07:14,910
it will check across 40 to 50 different antivirus products
205

205

00:07:14,910  -->  00:07:17,310
to see if any of them know if it's a virus or not,
206

206

00:07:17,310  -->  00:07:20,160
and it's a public repository for malware.
207

207

00:07:20,160  -->  00:07:21,840
Another one we have is Spamhaus,
208

208

00:07:21,840  -->  00:07:24,360
which is very focused on spam and email.
209

209

00:07:24,360  -->  00:07:27,480
And finally, we have SANS ISC Suspicious Domains,
210

210

00:07:27,480  -->  00:07:30,510
which, as the name implies, is focused on providing a feed
211

211

00:07:30,510  -->  00:07:33,720
of suspicious domains that they think might be malicious.
212

212

00:07:33,720  -->  00:07:36,000
Now, all of these feeds are really great
213

213

00:07:36,000  -->  00:07:37,320
and they provide you with what's known
214

214

00:07:37,320  -->  00:07:38,850
as explicit knowledge,
215

215

00:07:38,850  -->  00:07:42,600
which is knowledge you can write down, see, feel, and touch.
216

216

00:07:42,600  -->  00:07:45,090
But, there's another great source of knowledge out there too
217

217

00:07:45,090  -->  00:07:47,280
and it's known as implicit knowledge.
218

218

00:07:47,280  -->  00:07:50,490
Implicit knowledge is really useful, but you can only get it
219

219

00:07:50,490  -->  00:07:52,770
from experienced practitioners in the field.
220

220

00:07:52,770  -->  00:07:54,930
This is kind of that sense that they have,
221

221

00:07:54,930  -->  00:07:57,300
that they just go, "Ah, I know something is wrong here
222

222

00:07:57,300  -->  00:07:59,520
because of my 20 years of experience."
223

223

00:07:59,520  -->  00:08:01,230
Now, they may not always have the latest trends
224

224

00:08:01,230  -->  00:08:04,110
in cybersecurity, although most of the time they do,
225

225

00:08:04,110  -->  00:08:06,660
but they also have the ability to give you that attitude
226

226

00:08:06,660  -->  00:08:08,550
and instinct because of their career
227

227

00:08:08,550  -->  00:08:10,260
as a cybersecurity professional.
228

228

00:08:10,260  -->  00:08:12,120
Overtime, you're going to develop this
229

229

00:08:12,120  -->  00:08:14,190
as you become a senior cybersecurity analyst,
230

230

00:08:14,190  -->  00:08:16,260
where you just know this is wrong
231

231

00:08:16,260  -->  00:08:18,450
because you've seen it a hundred times before
232

232

00:08:18,450  -->  00:08:19,650
and you start getting this feeling
233

233

00:08:19,650  -->  00:08:22,530
of what is going to come next based on your experience.
234

234

00:08:22,530  -->  00:08:24,600
And that is something that we call implicit knowledge,
235

235

00:08:24,600  -->  00:08:25,680
because you can't write it down,
236

236

00:08:25,680  -->  00:08:27,750
you can't codify it in a procedure.
237

237

00:08:27,750  -->  00:08:29,040
It's just something you know
238

238

00:08:29,040  -->  00:08:31,200
based on your years of experience.
239

239

00:08:31,200  -->  00:08:32,640
Now, the last thing I want to mention here
240

240

00:08:32,640  -->  00:08:34,290
is what's known as OSINT.
241

241

00:08:34,290  -->  00:08:36,390
Now, open-source intelligence or OSINT
242

242

00:08:36,390  -->  00:08:38,520
is a very popular thing these days.
243

243

00:08:38,520  -->  00:08:40,410
This is a method of obtaining information
244

244

00:08:40,410  -->  00:08:41,940
about a person or organization
245

245

00:08:41,940  -->  00:08:45,150
through public records, websites, and social media.
246

246

00:08:45,150  -->  00:08:46,380
We're going to talk about this later on
247

247

00:08:46,380  -->  00:08:48,990
as we talk about pen testing and other parts of the course.
248

248

00:08:48,990  -->  00:08:51,420
But as you go out and you look at your organization
249

249

00:08:51,420  -->  00:08:53,190
from the outside looking in,
250

250

00:08:53,190  -->  00:08:55,800
anything people can find out about you on Google,
251

251

00:08:55,800  -->  00:08:58,620
on Facebook, by doing enumeration scans,
252

252

00:08:58,620  -->  00:09:00,540
that is all considered OSINT.
253

253

00:09:00,540  -->  00:09:03,330
It's ways for you to get information from public records,
254

254

00:09:03,330  -->  00:09:05,010
websites, and social media.
255

255

00:09:05,010  -->  00:09:06,570
So we'll talk more about that later on,
256

256

00:09:06,570  -->  00:09:08,010
but I just wanted to introduce that concept now
257

257

00:09:08,010  -->  00:09:10,590
because it is a form of open-source intelligence
258

258

00:09:10,590  -->  00:09:12,090
that a lot of people consider.
