1
00:00:00,000 --> 00:00:01,740
In this lesson, we're going to discuss

2
00:00:01,740 --> 00:00:03,420
Threat Intelligence Feeds.

3
00:00:03,420 --> 00:00:04,830
Now, as we move through this lesson,

4
00:00:04,830 --> 00:00:06,810
we're going to cover some basic concepts in the world

5
00:00:06,810 --> 00:00:08,880
of Threat Intelligence and where we can gather

6
00:00:08,880 --> 00:00:10,020
Threat Intelligence from

7
00:00:10,020 --> 00:00:12,630
by using Open-Source Intelligence Feeds, Proprietary

8
00:00:12,630 --> 00:00:13,890
or Third-Party Feeds,

9
00:00:13,890 --> 00:00:15,930
Feeds from information sharing organizations

10
00:00:15,930 --> 00:00:18,420
and information that we gather from the dark web.

11
00:00:18,420 --> 00:00:21,000
Now, before we do that though, let's take a moment to define

12
00:00:21,000 --> 00:00:23,250
what Threat Intelligence actually is.

13
00:00:23,250 --> 00:00:25,560
Threat intelligence is a continual process used

14
00:00:25,560 --> 00:00:28,200
to understand the threats faced by an organization.

15
00:00:28,200 --> 00:00:29,820
Depending on your organization's business

16
00:00:29,820 --> 00:00:31,560
and its missions, you're going to be facing

17
00:00:31,560 --> 00:00:32,850
different kinds of threats.

18
00:00:32,850 --> 00:00:34,860
So it's important to understand your own business

19
00:00:34,860 --> 00:00:37,230
and the threat environment that it's going to be focused on.

20
00:00:37,230 --> 00:00:39,750
For example, if you work in a nuclear power plant,

21
00:00:39,750 --> 00:00:41,040
you're facing different threats

22
00:00:41,040 --> 00:00:43,500
and attacks than somebody who works at a high school might.

23
00:00:43,500 --> 00:00:45,150
By understanding your own organization

24
00:00:45,150 --> 00:00:46,410
and then looking at the different threats

25
00:00:46,410 --> 00:00:48,870
that are out there, you can better identify which threats

26
00:00:48,870 --> 00:00:51,750
are more likely to affect you and therefore prepare yourself

27
00:00:51,750 --> 00:00:53,790
to defend against those threats.

28
00:00:53,790 --> 00:00:56,070
Now, Threat Intelligence is focused on analyzing

29
00:00:56,070 --> 00:00:58,050
evidence-based knowledge about an existing

30
00:00:58,050 --> 00:01:00,210
or emerging hazard to our asset.

31
00:01:00,210 --> 00:01:02,550
Threat intelligence is going to combine data from a large

32
00:01:02,550 --> 00:01:04,769
number of sources to provide us with the context,

33
00:01:04,769 --> 00:01:06,900
mechanisms, indicators, implications,

34
00:01:06,900 --> 00:01:09,750
and actionable information about a given threat.

35
00:01:09,750 --> 00:01:12,450
Threat intelligence has become a big business as well

36
00:01:12,450 --> 00:01:15,180
with companies like FireEye, providing subscription services

37
00:01:15,180 --> 00:01:17,220
to help keep cybersecurity professionals up to date

38
00:01:17,220 --> 00:01:19,680
on the latest attacks, vulnerabilities, threats,

39
00:01:19,680 --> 00:01:22,830
mitigations against zero day attacks and much more.

40
00:01:22,830 --> 00:01:24,780
Now, information technology changes quickly,

41
00:01:24,780 --> 00:01:26,520
and so it's important that we understand that the types

42
00:01:26,520 --> 00:01:27,960
of attacks that we're going to observe

43
00:01:27,960 --> 00:01:29,940
are also going to change quickly too.

44
00:01:29,940 --> 00:01:32,340
Back in the old days, threat actors focused their attacks

45
00:01:32,340 --> 00:01:33,540
on server side attacks

46
00:01:33,540 --> 00:01:36,180
because servers always had at least some ports and protocols

47
00:01:36,180 --> 00:01:37,410
open by default.

48
00:01:37,410 --> 00:01:40,440
After all, their job as a server is to have open services

49
00:01:40,440 --> 00:01:42,600
that can be utilized by authorized clients,

50
00:01:42,600 --> 00:01:44,250
but as administrators have done a better job

51
00:01:44,250 --> 00:01:46,860
of protecting those servers, threat actors have moved on

52
00:01:46,860 --> 00:01:49,950
to easier targets, which in this case is the clients.

53
00:01:49,950 --> 00:01:52,680
Now client side attacks focus on targeting vulnerabilities

54
00:01:52,680 --> 00:01:54,330
in the client applications.

55
00:01:54,330 --> 00:01:55,800
Threat actors have found that many clients

56
00:01:55,800 --> 00:01:56,970
are not well secured

57
00:01:56,970 --> 00:01:58,770
because users don't maintain a hardened device

58
00:01:58,770 --> 00:02:01,050
configuration, or they simply don't perform the proper

59
00:02:01,050 --> 00:02:02,850
patching and updates when needed.

60
00:02:02,850 --> 00:02:05,250
Also, users often install additional software

61
00:02:05,250 --> 00:02:06,810
in their clients, which also opens up

62
00:02:06,810 --> 00:02:07,800
additional vulnerabilities

63
00:02:07,800 --> 00:02:09,930
that could be exploited by a threat actor.

64
00:02:09,930 --> 00:02:11,430
Now on our enterprise networks,

65
00:02:11,430 --> 00:02:13,650
we can implement things like network access control

66
00:02:13,650 --> 00:02:15,720
or NAC to help scan client computers

67
00:02:15,720 --> 00:02:17,880
before we allow them to connect to our network.

68
00:02:17,880 --> 00:02:19,260
This can help minimize our risk

69
00:02:19,260 --> 00:02:21,270
of spreading infections across our other clients

70
00:02:21,270 --> 00:02:22,740
that are also connected to our network

71
00:02:22,740 --> 00:02:24,210
because we're keeping those clients out

72
00:02:24,210 --> 00:02:26,400
that haven't already passed our security test.

73
00:02:26,400 --> 00:02:27,960
Because of this, a lot of clients

74
00:02:27,960 --> 00:02:29,310
are becoming much more secure

75
00:02:29,310 --> 00:02:31,290
because NAC can place them into isolation

76
00:02:31,290 --> 00:02:33,120
until they're updated and properly configured,

77
00:02:33,120 --> 00:02:35,130
and then give them access to the network.

78
00:02:35,130 --> 00:02:37,380
But again, threat actors have been pivoting their attack

79
00:02:37,380 --> 00:02:39,690
methods as our clients have become more secure.

80
00:02:39,690 --> 00:02:41,730
Now, as users have begun moving more and more

81
00:02:41,730 --> 00:02:44,040
into a mobile environment simultaneously,

82
00:02:44,040 --> 00:02:46,590
the amount of malware for those devices like iOS

83
00:02:46,590 --> 00:02:49,500
and Android devices have also risen in turn.

84
00:02:49,500 --> 00:02:51,240
To help mitigate this new threat,

85
00:02:51,240 --> 00:02:53,190
enterprises are using mobile device management

86
00:02:53,190 --> 00:02:55,170
and mobile application management software

87
00:02:55,170 --> 00:02:56,610
to better control the configurations

88
00:02:56,610 --> 00:02:59,310
and use of their organization's mobile devices.

89
00:02:59,310 --> 00:03:01,470
Also, threat actors have noticed a large move

90
00:03:01,470 --> 00:03:03,120
by organizations into the cloud

91
00:03:03,120 --> 00:03:05,490
and the widespread adoption of virtualization.

92
00:03:05,490 --> 00:03:07,500
Because of this, many of the newest attacks

93
00:03:07,500 --> 00:03:08,670
are being developed around exploiting

94
00:03:08,670 --> 00:03:10,350
these technologies too.

95
00:03:10,350 --> 00:03:12,270
So now that we have a better understanding

96
00:03:12,270 --> 00:03:14,040
of Threat Intelligence, let's talk about

97
00:03:14,040 --> 00:03:15,630
Threat Intelligence Feed.

98
00:03:15,630 --> 00:03:16,800
Now, a Threat Intelligence Feed

99
00:03:16,800 --> 00:03:19,320
is a continuous stream of data related to the potential

100
00:03:19,320 --> 00:03:21,510
or current threats that an organization's security

101
00:03:21,510 --> 00:03:22,770
might be facing.

102
00:03:22,770 --> 00:03:25,440
Threat intelligence data is collected, analyzed,

103
00:03:25,440 --> 00:03:28,080
and disseminated by security researchers, organizations,

104
00:03:28,080 --> 00:03:30,900
or automated tools, and it's then used to provide realtime

105
00:03:30,900 --> 00:03:33,600
or near realtime updates on various aspects

106
00:03:33,600 --> 00:03:35,400
such as new malware signatures,

107
00:03:35,400 --> 00:03:38,100
indicators of compromise, malicious IP addresses,

108
00:03:38,100 --> 00:03:40,020
URLs, and much more.

109
00:03:40,020 --> 00:03:41,910
There are many different kinds of feeds that can be used

110
00:03:41,910 --> 00:03:43,950
by an organization, so they can stay abreast

111
00:03:43,950 --> 00:03:45,300
of the latest security threats,

112
00:03:45,300 --> 00:03:46,500
and that way they can proactively

113
00:03:46,500 --> 00:03:48,330
enhance their security posture.

114
00:03:48,330 --> 00:03:50,520
This Threat Intelligence can be received from various

115
00:03:50,520 --> 00:03:52,650
sources, including Open-source Intelligence,

116
00:03:52,650 --> 00:03:54,660
Proprietary or Third-Party Feeds,

117
00:03:54,660 --> 00:03:57,660
Information-sharing Organizations, and the Dark Web.

118
00:03:57,660 --> 00:04:00,150
So let's take a quick look at each of these four sources

119
00:04:00,150 --> 00:04:02,010
of Threat Intelligence that we can be using

120
00:04:02,010 --> 00:04:03,630
inside of our organization.

121
00:04:03,630 --> 00:04:05,730
First, we have Open-Source Intelligence.

122
00:04:05,730 --> 00:04:08,400
Now, Open-Source Intelligence, also known as OSINT,

123
00:04:08,400 --> 00:04:10,350
is the intelligence that's being collected from publicly

124
00:04:10,350 --> 00:04:14,010
available sources, including reports, forums, news articles,

125
00:04:14,010 --> 00:04:16,140
blogs and social media posts.

126
00:04:16,140 --> 00:04:18,510
Open-Source Intelligence feed can be a great source

127
00:04:18,510 --> 00:04:20,220
of information, and they're usually available

128
00:04:20,220 --> 00:04:21,720
at no cost to you.

129
00:04:21,720 --> 00:04:24,150
Some popular Open-Source Intelligence feeds include

130
00:04:24,150 --> 00:04:26,700
those provided by AlienVault Open Threat Exchange,

131
00:04:26,700 --> 00:04:29,070
the SANS Internet Storm Center, and various forms

132
00:04:29,070 --> 00:04:31,890
and blogs where security researchers share any new findings

133
00:04:31,890 --> 00:04:33,900
that they've identified out in the wild.

134
00:04:33,900 --> 00:04:35,820
By utilizing Open-Source Intelligence,

135
00:04:35,820 --> 00:04:38,220
organizations can gain insights into the emerging threats

136
00:04:38,220 --> 00:04:40,290
and vulnerabilities without having to invest heavily

137
00:04:40,290 --> 00:04:42,030
in proprietary solutions.

138
00:04:42,030 --> 00:04:43,800
Now, this brings us to our second option,

139
00:04:43,800 --> 00:04:46,380
which is a Proprietary or Third-Party Feed.

140
00:04:46,380 --> 00:04:48,300
Now Proprietary or Third-Party Feeds

141
00:04:48,300 --> 00:04:50,310
are Threat Intelligence feeds that are being provided

142
00:04:50,310 --> 00:04:51,450
by commercial vendors,

143
00:04:51,450 --> 00:04:54,360
usually under a subscription service type of business model.

144
00:04:54,360 --> 00:04:57,450
These proprietary feeds often offer more refined, analyzed,

145
00:04:57,450 --> 00:04:59,640
and timely information than what you might find

146
00:04:59,640 --> 00:05:01,710
in an Open-Source Intelligence Feed.

147
00:05:01,710 --> 00:05:02,970
Some of the best known companies

148
00:05:02,970 --> 00:05:05,220
that provide proprietary Threat Intelligence Feeds

149
00:05:05,220 --> 00:05:07,740
are FireEye, McAfee, and Symantec.

150
00:05:07,740 --> 00:05:09,450
Each of these companies allows their feeds

151
00:05:09,450 --> 00:05:11,220
to be integrated into security information

152
00:05:11,220 --> 00:05:13,650
and event management tools and other security tools

153
00:05:13,650 --> 00:05:15,450
to provide our cybersecurity analysts

154
00:05:15,450 --> 00:05:16,500
with actionable insights

155
00:05:16,500 --> 00:05:18,930
and an automated threat response capability.

156
00:05:18,930 --> 00:05:21,690
Third, we have information sharing organizations.

157
00:05:21,690 --> 00:05:23,400
There are information sharing organizations

158
00:05:23,400 --> 00:05:24,720
and alliances that have been formed

159
00:05:24,720 --> 00:05:27,180
to share Threat Intelligence among their members.

160
00:05:27,180 --> 00:05:29,970
For example, the information sharing and analysis centers

161
00:05:29,970 --> 00:05:32,280
and the information sharing and analysis organizations

162
00:05:32,280 --> 00:05:33,840
were created to foster collaboration

163
00:05:33,840 --> 00:05:35,700
among businesses in similar industries

164
00:05:35,700 --> 00:05:38,550
and sectors like all the companies working in finance

165
00:05:38,550 --> 00:05:41,070
or healthcare or energy, to allow them to share

166
00:05:41,070 --> 00:05:42,660
and receive information about the threats

167
00:05:42,660 --> 00:05:44,250
and vulnerabilities that are specific

168
00:05:44,250 --> 00:05:46,080
to their particular industries.

169
00:05:46,080 --> 00:05:48,270
By joining an information sharing organization,

170
00:05:48,270 --> 00:05:50,190
your business will learn from the collective experience

171
00:05:50,190 --> 00:05:51,570
and insights of a community

172
00:05:51,570 --> 00:05:53,880
that understands their unique challenges and threats,

173
00:05:53,880 --> 00:05:56,280
and you'll also give your data into that collective

174
00:05:56,280 --> 00:05:57,990
so they can learn from you too.

175
00:05:57,990 --> 00:06:00,420
Fourth and finally, we have the dark web.

176
00:06:00,420 --> 00:06:02,100
Now, the dark web is a part of the Internet

177
00:06:02,100 --> 00:06:03,180
that is intentionally hidden

178
00:06:03,180 --> 00:06:05,670
and inaccessible through standard web browsers.

179
00:06:05,670 --> 00:06:07,350
While the dark web is most often associated

180
00:06:07,350 --> 00:06:09,840
with illegal activities, it can also be a great source

181
00:06:09,840 --> 00:06:12,420
of Threat Intelligence for security researchers.

182
00:06:12,420 --> 00:06:13,560
Now, security researchers

183
00:06:13,560 --> 00:06:16,320
and organizations will sometimes explore the dark web forums

184
00:06:16,320 --> 00:06:17,610
and marketplaces to try

185
00:06:17,610 --> 00:06:19,980
and uncover the information about new hacking techniques

186
00:06:19,980 --> 00:06:22,290
and tools, stolen data and emerging threats

187
00:06:22,290 --> 00:06:24,180
that are existing there on the dark web.

188
00:06:24,180 --> 00:06:26,280
By understanding what is happening in the dark web,

189
00:06:26,280 --> 00:06:28,860
your organization's security researchers will have a better

190
00:06:28,860 --> 00:06:30,360
heads up on potential threats

191
00:06:30,360 --> 00:06:32,280
before they become public knowledge too.

192
00:06:32,280 --> 00:06:33,570
So as you can see,

193
00:06:33,570 --> 00:06:35,520
Threat Intelligence Feeds are an essential tool

194
00:06:35,520 --> 00:06:37,650
in a cybersecurity professionals toolkit.

195
00:06:37,650 --> 00:06:39,750
By gathering information from various sources,

196
00:06:39,750 --> 00:06:41,100
you can ensure that you remain up to date

197
00:06:41,100 --> 00:06:42,840
on the latest threats and are well prepared

198
00:06:42,840 --> 00:06:45,360
to defend your organization against those threats.

199
00:06:45,360 --> 00:06:47,790
Regardless of whether you're relying on open source feeds,

200
00:06:47,790 --> 00:06:50,370
subscribing to third party proprietary intelligence feeds,

201
00:06:50,370 --> 00:06:52,530
participating in information sharing organizations

202
00:06:52,530 --> 00:06:54,210
or exploring the dark web,

203
00:06:54,210 --> 00:06:55,950
staying informed is going to be the key

204
00:06:55,950 --> 00:06:58,890
to maintaining a stronger organizational security posture.

205
00:06:58,890 --> 00:06:59,910
Since the threat landscape

206
00:06:59,910 --> 00:07:01,290
and cybersecurity is always evolving

207
00:07:01,290 --> 00:07:03,450
and changing, we have to remain up to date

208
00:07:03,450 --> 00:07:06,150
and proactive by leveraging Threat Intelligence Feeds

209
00:07:06,150 --> 00:07:07,860
so that we can stay ahead of the new threats

210
00:07:07,860 --> 00:07:10,433
and we can avoid falling victim to them in the future.

