1
1

00:00:00,300  -->  00:00:02,400
<v Instructor>Threat intelligence sharing.</v>
2

2

00:00:02,400  -->  00:00:04,560
Now, in addition to being part of an ISAC,
3

3

00:00:04,560  -->  00:00:06,630
if that's part of one of your industries,
4

4

00:00:06,630  -->  00:00:08,760
you also need to think about threat intelligence sharing
5

5

00:00:08,760  -->  00:00:10,890
within your organization.
6

6

00:00:10,890  -->  00:00:12,900
As we start identifying this timely,
7

7

00:00:12,900  -->  00:00:15,510
relevant and accurate sources of threat intelligence
8

8

00:00:15,510  -->  00:00:18,900
we need to think about how do we make that data actionable?
9

9

00:00:18,900  -->  00:00:20,100
And one of the ways we do that
10

10

00:00:20,100  -->  00:00:21,780
is by disseminating this information
11

11

00:00:21,780  -->  00:00:23,640
to different people within our organization,
12

12

00:00:23,640  -->  00:00:25,740
or even outside our organization.
13

13

00:00:25,740  -->  00:00:28,380
That's the idea that we're going to talk about in this lesson.
14

14

00:00:28,380  -->  00:00:29,250
We're going to talk about
15

15

00:00:29,250  -->  00:00:31,020
how we can use this through risk management
16

16

00:00:31,020  -->  00:00:33,840
and security engineering, incident response,
17

17

00:00:33,840  -->  00:00:36,570
vulnerability management and detection and monitoring.
18

18

00:00:36,570  -->  00:00:38,310
First, risk management.
19

19

00:00:38,310  -->  00:00:39,990
What is risk management?
20

20

00:00:39,990  -->  00:00:42,570
Well, risk management is the process of identifying,
21

21

00:00:42,570  -->  00:00:45,090
evaluating and prioritizing different threats
22

22

00:00:45,090  -->  00:00:46,200
and vulnerabilities
23

23

00:00:46,200  -->  00:00:49,050
in order for us to reduce their negative impact.
24

24

00:00:49,050  -->  00:00:50,640
Now, the reason that threat intelligence
25

25

00:00:50,640  -->  00:00:51,990
is important to risk management
26

26

00:00:51,990  -->  00:00:55,080
is it tells us how risky a certain thing is
27

27

00:00:55,080  -->  00:00:56,970
based on outside threats,
28

28

00:00:56,970  -->  00:00:58,890
because we know our own vulnerabilities
29

29

00:00:58,890  -->  00:01:01,170
through our vulnerability management and our scanning,
30

30

00:01:01,170  -->  00:01:04,170
but if we don't know what attackers are coming after us
31

31

00:01:04,170  -->  00:01:06,180
we can't really think about the threat.
32

32

00:01:06,180  -->  00:01:08,940
And so putting those two together is really important.
33

33

00:01:08,940  -->  00:01:10,770
Now, the reason why we put risk management
34

34

00:01:10,770  -->  00:01:12,510
and security engineering together
35

35

00:01:12,510  -->  00:01:14,310
is because by putting them together
36

36

00:01:14,310  -->  00:01:16,770
we can start designing the architecture of the hardware,
37

37

00:01:16,770  -->  00:01:18,840
the software, and the network platforms
38

38

00:01:18,840  -->  00:01:20,910
to respond to these different threats
39

39

00:01:20,910  -->  00:01:23,010
and reduce our attack surface.
40

40

00:01:23,010  -->  00:01:24,900
This way we can start figuring out
41

41

00:01:24,900  -->  00:01:26,520
what attacks we're vulnerable to
42

42

00:01:26,520  -->  00:01:28,860
and what controls we can put in place.
43

43

00:01:28,860  -->  00:01:29,693
For instance,
44

44

00:01:29,693  -->  00:01:31,380
if we're looking at strategic threat intelligence
45

45

00:01:31,380  -->  00:01:32,213
and we start seeing
46

46

00:01:32,213  -->  00:01:34,380
that people are going after Linux systems
47

47

00:01:34,380  -->  00:01:37,500
more than Mac or Windows systems for instance
48

48

00:01:37,500  -->  00:01:40,320
that may mean that if we're running a lot of Linux servers
49

49

00:01:40,320  -->  00:01:41,790
we need to make sure we're prepared
50

50

00:01:41,790  -->  00:01:43,380
for those additional attacks.
51

51

00:01:43,380  -->  00:01:45,120
This is the idea of thinking strategically
52

52

00:01:45,120  -->  00:01:47,460
of what changes we can make inside our organization
53

53

00:01:47,460  -->  00:01:49,830
for the long term to try to outsmart
54

54

00:01:49,830  -->  00:01:53,100
or out-maneuver the different bad actors that are out there.
55

55

00:01:53,100  -->  00:01:55,590
Now, the second area we have to use threat intelligence for
56

56

00:01:55,590  -->  00:01:57,300
is incident response.
57

57

00:01:57,300  -->  00:01:59,340
Incident response is an organized approach
58

58

00:01:59,340  -->  00:02:00,630
to addressing and managing
59

59

00:02:00,630  -->  00:02:03,600
the aftermath of a cybersecurity breach or attack.
60

60

00:02:03,600  -->  00:02:05,190
So if somebody has been successful
61

61

00:02:05,190  -->  00:02:06,990
in penetrating our network,
62

62

00:02:06,990  -->  00:02:09,840
we need intelligence to help keep them out.
63

63

00:02:09,840  -->  00:02:11,700
Now, the best type of intelligence here
64

64

00:02:11,700  -->  00:02:14,550
is going to be tactical-level intelligence though,
65

65

00:02:14,550  -->  00:02:17,490
because we need to know where they are in our networks,
66

66

00:02:17,490  -->  00:02:19,680
what IP address are they coming from,
67

67

00:02:19,680  -->  00:02:21,570
what are they doing once they're in our network,
68

68

00:02:21,570  -->  00:02:24,180
and all those tactical pieces of threat intelligence
69

69

00:02:24,180  -->  00:02:25,890
will help us identify where they are
70

70

00:02:25,890  -->  00:02:27,570
and how we can get them out of our network
71

71

00:02:27,570  -->  00:02:29,670
and prevent them from coming back.
72

72

00:02:29,670  -->  00:02:31,830
Then we can start using those strategic insights
73

73

00:02:31,830  -->  00:02:33,690
to prevent them from coming back over and over again
74

74

00:02:33,690  -->  00:02:34,523
in the future.
75

75

00:02:34,523  -->  00:02:36,000
But right now, we're really focused
76

76

00:02:36,000  -->  00:02:37,530
on the tactical threat intelligence
77

77

00:02:37,530  -->  00:02:40,110
to get this incident response resolved.
78

78

00:02:40,110  -->  00:02:42,960
The third one we have is vulnerability management.
79

79

00:02:42,960  -->  00:02:44,400
Now, when we deal with vulnerability management
80

80

00:02:44,400  -->  00:02:47,070
this is the practice of identifying, classifying,
81

81

00:02:47,070  -->  00:02:48,870
prioritizing, remediating,
82

82

00:02:48,870  -->  00:02:51,450
and mitigating software vulnerabilities.
83

83

00:02:51,450  -->  00:02:53,610
Now, as we start thinking about vulnerability management
84

84

00:02:53,610  -->  00:02:55,050
at a strategic level
85

85

00:02:55,050  -->  00:02:56,640
we're going to use our threat intelligence
86

86

00:02:56,640  -->  00:02:59,400
to identify unrecognized sources of vulnerabilities
87

87

00:02:59,400  -->  00:03:00,840
that we may not have thought of.
88

88

00:03:00,840  -->  00:03:04,440
For instance, do we have a WiFi enabled thermostat?
89

89

00:03:04,440  -->  00:03:07,050
That's an IoT device, an internet of things
90

90

00:03:07,050  -->  00:03:08,460
and that's something we have to consider.
91

91

00:03:08,460  -->  00:03:10,590
And many people don't think about that
92

92

00:03:10,590  -->  00:03:12,300
inside their organizations.
93

93

00:03:12,300  -->  00:03:14,280
What about the concept of deepfakes?
94

94

00:03:14,280  -->  00:03:16,380
That is a big issue these days.
95

95

00:03:16,380  -->  00:03:18,360
What about AI facilitated fuzzing
96

96

00:03:18,360  -->  00:03:20,520
to discover zero day vulnerabilities?
97

97

00:03:20,520  -->  00:03:22,380
There are lots of different things out there
98

98

00:03:22,380  -->  00:03:24,840
and if we think about them from a strategic level
99

99

00:03:24,840  -->  00:03:25,673
we can make sure
100

100

00:03:25,673  -->  00:03:27,570
that we're doing a good vulnerability management program
101

101

00:03:27,570  -->  00:03:29,580
that addresses those concerns.
102

102

00:03:29,580  -->  00:03:31,680
Also, we can be thinking about things
103

103

00:03:31,680  -->  00:03:33,300
at a more tactical level,
104

104

00:03:33,300  -->  00:03:35,670
like we know that a certain piece of malware
105

105

00:03:35,670  -->  00:03:36,870
is now in the market.
106

106

00:03:36,870  -->  00:03:38,370
Are we vulnerable to it?
107

107

00:03:38,370  -->  00:03:39,390
And so we can do a scan,
108

108

00:03:39,390  -->  00:03:41,880
specifically looking for that one thing.
109

109

00:03:41,880  -->  00:03:42,840
This is very popular
110

110

00:03:42,840  -->  00:03:45,060
once there's a big well-known malware attack
111

111

00:03:45,060  -->  00:03:46,170
that goes out there.
112

112

00:03:46,170  -->  00:03:47,820
For instance, when WannaCry came out
113

113

00:03:47,820  -->  00:03:50,010
that was something you'd want to do a vulnerability management
114

114

00:03:50,010  -->  00:03:50,940
of your own network
115

115

00:03:50,940  -->  00:03:52,620
and see if you were vulnerable to it
116

116

00:03:52,620  -->  00:03:54,300
and what mitigations you could put in place
117

117

00:03:54,300  -->  00:03:55,770
before you were attacked.
118

118

00:03:55,770  -->  00:03:58,350
And using threat intelligence allows you to do that.
119

119

00:03:58,350  -->  00:04:00,690
Finally, we have detection and monitoring.
120

120

00:04:00,690  -->  00:04:02,910
This is the practice of observing activity
121

121

00:04:02,910  -->  00:04:06,360
to identify anomalous patterns for further analysis.
122

122

00:04:06,360  -->  00:04:08,550
Now, as we think about detection and monitoring
123

123

00:04:08,550  -->  00:04:11,220
we need to also use threat intelligence here too,
124

124

00:04:11,220  -->  00:04:14,010
because as we know what threats are out there
125

125

00:04:14,010  -->  00:04:16,080
we can then tune our sensors better.
126

126

00:04:16,080  -->  00:04:18,480
This will allow us to add more rules and definitions
127

127

00:04:18,480  -->  00:04:20,820
based on different observed incidences
128

128

00:04:20,820  -->  00:04:22,740
that have happened either to our organization
129

129

00:04:22,740  -->  00:04:24,150
or partner organizations,
130

130

00:04:24,150  -->  00:04:25,920
or one of those commercial data feeds
131

131

00:04:25,920  -->  00:04:27,360
that we're subscribed to.
132

132

00:04:27,360  -->  00:04:30,210
By getting that information, we can tune our sensors better
133

133

00:04:30,210  -->  00:04:32,280
and we can have a lot more true positives
134

134

00:04:32,280  -->  00:04:34,380
and a lot less false positives.
135

135

00:04:34,380  -->  00:04:35,970
So this is why it's a good idea to make sure
136

136

00:04:35,970  -->  00:04:38,550
you're on the dissemination chain for threat intelligence
137

137

00:04:38,550  -->  00:04:40,770
if you work in detection and monitoring.
138

138

00:04:40,770  -->  00:04:43,950
Overall, our goal here is to share our threat intelligence
139

139

00:04:43,950  -->  00:04:45,450
within our organization
140

140

00:04:45,450  -->  00:04:47,940
so we can improve our organizational capabilities
141

141

00:04:47,940  -->  00:04:50,240
and protect ourselves from additional threats.
