1
00:00:06,540 --> 00:00:08,190
- In this lesson 5.2,

2
00:00:08,190 --> 00:00:10,140
we're gonna be talking
about threat modeling

3
00:00:10,140 --> 00:00:11,823
and threat intelligence.

4
00:00:12,960 --> 00:00:15,960
The threat modeling is a
very structured process

5
00:00:15,960 --> 00:00:18,600
by which we identify potential threats

6
00:00:18,600 --> 00:00:20,760
as well as threat actors.

7
00:00:20,760 --> 00:00:23,700
So we identify them, we enumerate them,

8
00:00:23,700 --> 00:00:25,683
and we can prioritize them.

9
00:00:27,960 --> 00:00:30,120
So what makes for a successful attack?

10
00:00:30,120 --> 00:00:34,170
Well, motivation, talent, work factor,

11
00:00:34,170 --> 00:00:39,170
meaning time and resources,
patience, evasion, capability,

12
00:00:39,540 --> 00:00:41,190
and sometimes just luck

13
00:00:41,190 --> 00:00:44,520
really all contribute
to a successful attack.

14
00:00:44,520 --> 00:00:46,770
Work factor being the time, the effort,

15
00:00:46,770 --> 00:00:49,290
and the resources
necessary for the attacker

16
00:00:49,290 --> 00:00:52,470
to successfully achieve their objective.

17
00:00:52,470 --> 00:00:54,210
But it's really important
that we understand

18
00:00:54,210 --> 00:00:56,220
all of the components that go into

19
00:00:56,220 --> 00:00:58,170
making an attacker successful.

20
00:00:58,170 --> 00:01:01,380
It's not just that we have a
vulnerability or a weakness

21
00:01:01,380 --> 00:01:04,200
they also have to have
a whole list of things.

22
00:01:04,200 --> 00:01:06,240
Again, motivation, talent, work factor,

23
00:01:06,240 --> 00:01:10,350
patience, ovation, capabilities,
and sometimes luck.

24
00:01:10,350 --> 00:01:11,760
But by doing threat modeling,

25
00:01:11,760 --> 00:01:15,660
we can get some insight
right into what they need

26
00:01:15,660 --> 00:01:18,213
to really complete a successful attack.

27
00:01:19,740 --> 00:01:22,740
Now, there are three
approaches to threat modeling,

28
00:01:22,740 --> 00:01:26,460
asset centric, architecture
centric, and attacker centric.

29
00:01:26,460 --> 00:01:29,640
And what I find is that most organizations

30
00:01:29,640 --> 00:01:32,490
intuitively take all
three of these approaches

31
00:01:32,490 --> 00:01:35,700
and could mesh it into a hybrid approach.

32
00:01:35,700 --> 00:01:38,760
So here we are thinking about,
right, who might attack us?

33
00:01:38,760 --> 00:01:41,310
What attacks? What threats do we have?

34
00:01:41,310 --> 00:01:44,820
What potential dangers
in our organization?

35
00:01:44,820 --> 00:01:48,390
Asset centric threat
modeling really approaches on

36
00:01:48,390 --> 00:01:50,520
kind of what do we have

37
00:01:50,520 --> 00:01:53,790
that someone would want
and why would they want it?

38
00:01:53,790 --> 00:01:55,950
So we're really looking to identify

39
00:01:55,950 --> 00:01:59,580
our valued assets and
the motivation of someone

40
00:01:59,580 --> 00:02:01,443
who might come after those assets.

41
00:02:02,460 --> 00:02:05,700
In architecture centric, we're
looking at the how, right?

42
00:02:05,700 --> 00:02:07,830
How they might be able to attack us.

43
00:02:07,830 --> 00:02:09,390
And what we're really doing here,

44
00:02:09,390 --> 00:02:12,450
is identifying system design components,

45
00:02:12,450 --> 00:02:14,370
strengths and weaknesses.

46
00:02:14,370 --> 00:02:18,930
So for example, if I
have a web server, right?

47
00:02:18,930 --> 00:02:22,050
And I'm running Apache and WordPress,

48
00:02:22,050 --> 00:02:25,320
I wanna know what were
the weaknesses in Apache,

49
00:02:25,320 --> 00:02:27,540
what were the weaknesses
in WordPress, right?

50
00:02:27,540 --> 00:02:31,083
That my attacker may attempt to exploit?

51
00:02:32,190 --> 00:02:34,140
And third is attacker centric,

52
00:02:34,140 --> 00:02:35,760
which is, who am I wanna come after me?

53
00:02:35,760 --> 00:02:38,130
So we're identifying the adversaries.

54
00:02:38,130 --> 00:02:40,890
So by doing asset centric,
architecture centric,

55
00:02:40,890 --> 00:02:42,600
and attacker centric, right?

56
00:02:42,600 --> 00:02:44,400
We're answering the question

57
00:02:44,400 --> 00:02:46,920
what might they wanna come after and why?

58
00:02:46,920 --> 00:02:49,983
How might they do it and who are they?

59
00:02:52,980 --> 00:02:56,940
So how do we learn about
our potential attackers?

60
00:02:56,940 --> 00:02:59,520
That's where threat intelligence comes in.

61
00:02:59,520 --> 00:03:02,400
Threat intelligence is
evidence-based knowledge

62
00:03:02,400 --> 00:03:05,640
about emerging threats
that can be used to inform

63
00:03:05,640 --> 00:03:07,233
our control decisions.

64
00:03:08,250 --> 00:03:10,350
But it's not just raw data, right?

65
00:03:10,350 --> 00:03:13,620
We really wanna make sure
that our threat intelligence

66
00:03:13,620 --> 00:03:15,120
is usable.

67
00:03:15,120 --> 00:03:18,510
So useful threat
intelligence is aggregated,

68
00:03:18,510 --> 00:03:22,500
analyzed, assessed, and actionable.

69
00:03:22,500 --> 00:03:24,270
Aggregated from reliable sources

70
00:03:24,270 --> 00:03:26,700
and cross correlated for accuracy,

71
00:03:26,700 --> 00:03:28,860
analyzed by trained specialist,

72
00:03:28,860 --> 00:03:31,770
assessed for relevancy
to our organization,

73
00:03:31,770 --> 00:03:32,910
and actionable

74
00:03:32,910 --> 00:03:35,580
meaning can I do something
with this information?

75
00:03:35,580 --> 00:03:37,200
Now, actionable threat intelligence

76
00:03:37,200 --> 00:03:39,870
will often include contacts, mechanisms,

77
00:03:39,870 --> 00:03:41,820
indicators, implications,

78
00:03:41,820 --> 00:03:44,703
and response and remediation advice.

79
00:03:46,080 --> 00:03:47,970
So what are some sources
of threat intelligence?

80
00:03:47,970 --> 00:03:49,110
Well, we can get threat intelligence

81
00:03:49,110 --> 00:03:52,560
from technology vendors from
cyber security companies

82
00:03:52,560 --> 00:03:55,650
from journalists, researchers,
and thought leaders

83
00:03:55,650 --> 00:03:59,490
as well as a whole pantheon
of of government agencies.

84
00:03:59,490 --> 00:04:00,960
So with our technology vendors,

85
00:04:00,960 --> 00:04:03,630
many of them will have
subscription or public feeds

86
00:04:03,630 --> 00:04:07,173
provided by vendors such as
Microsoft or Cisco or Apple.

87
00:04:08,220 --> 00:04:10,500
Cybersecurity companies have subscriptions

88
00:04:10,500 --> 00:04:12,270
and or public feeds

89
00:04:12,270 --> 00:04:15,031
provided by the vendors
such as TylerDetect

90
00:04:15,031 --> 00:04:19,560
or AlienVault, FireEye,
RSA, and SecureWorks.

91
00:04:19,560 --> 00:04:22,050
And then there's some awesome journalists,

92
00:04:22,050 --> 00:04:24,390
researchers, and thought leaders.

93
00:04:24,390 --> 00:04:27,300
Bruce Schneider, Jeremiah
Grossman, Brian Krebs

94
00:04:27,300 --> 00:04:30,150
who has a fabulous blog
called Krebs on Security,

95
00:04:30,150 --> 00:04:33,660
Mark Russinovich, Kim
Zetter, Nicole Periroth,

96
00:04:33,660 --> 00:04:37,140
Andy Greenberg, and Ellen Nakashima.

97
00:04:37,140 --> 00:04:40,080
All excellent journalists,
researchers, thought leaders.

98
00:04:40,080 --> 00:04:41,490
They're almost all on Twitter.

99
00:04:41,490 --> 00:04:43,170
You can follow them on Twitter.

100
00:04:43,170 --> 00:04:46,740
Again, some of them have
blogs like Krebs on Security,

101
00:04:46,740 --> 00:04:49,440
definitely, definitely
worth following them.

102
00:04:49,440 --> 00:04:50,940
And then government agencies.

103
00:04:50,940 --> 00:04:53,700
And this is data provided
by agencies such as NIST,

104
00:04:53,700 --> 00:04:56,130
the National Institute of
Standards and Technology,

105
00:04:56,130 --> 00:04:58,830
the FBI, US-CERT, NVD

106
00:04:58,830 --> 00:05:01,410
which is the National
Vulnerability Database,

107
00:05:01,410 --> 00:05:04,027
MITRE and my new personal favorite,

108
00:05:04,027 --> 00:05:08,100
which is a Cybersecurity
and Infrastructure Agency

109
00:05:08,100 --> 00:05:09,630
known as CISA.

110
00:05:09,630 --> 00:05:11,930
And I'll talk about that
one in just a moment.

111
00:05:13,680 --> 00:05:16,380
Now, another place to
get threat intelligence

112
00:05:16,380 --> 00:05:18,990
is through open source sources.

113
00:05:18,990 --> 00:05:22,320
Now, open source
intelligence known as OSINT,

114
00:05:22,320 --> 00:05:24,600
is a term used to refer to data collected

115
00:05:24,600 --> 00:05:26,340
from publicly available sources

116
00:05:26,340 --> 00:05:28,893
to be used in an intelligence context.

117
00:05:29,850 --> 00:05:31,380
Now, there's an excellent framework

118
00:05:31,380 --> 00:05:32,730
that you wanna become familiar with

119
00:05:32,730 --> 00:05:34,620
called the OSINT framework,

120
00:05:34,620 --> 00:05:38,430
which is a structured
collection of OSINT tools.

121
00:05:38,430 --> 00:05:43,320
And the OSINT framework is
organized by topic and goals.

122
00:05:43,320 --> 00:05:46,530
And it presents itself in
a really cool tree form

123
00:05:46,530 --> 00:05:49,860
that allows you to browse
different OSINT tools

124
00:05:49,860 --> 00:05:51,300
filtered by category.

125
00:05:51,300 --> 00:05:52,500
So how do you get to it?

126
00:05:52,500 --> 00:05:54,550
If you go out to osintframework.com

127
00:05:56,160 --> 00:05:57,630
definitely put that on your list.

128
00:05:57,630 --> 00:05:59,730
You wanna really become
familiar there are lots

129
00:05:59,730 --> 00:06:00,960
of great information

130
00:06:00,960 --> 00:06:03,720
and some really fantastic
open source tools

131
00:06:03,720 --> 00:06:04,683
that you can use.

132
00:06:06,930 --> 00:06:09,060
So let's circle back to CISA.

133
00:06:09,060 --> 00:06:10,830
You haven't been out to the CISA website.

134
00:06:10,830 --> 00:06:15,503
You definitely wanna get out
there www.cisa, C-I-S-A.gov.

135
00:06:16,383 --> 00:06:19,263
CISA is America's Cyber Defense Agency.

136
00:06:19,263 --> 00:06:23,160
It's a cybersecurity and
infrastructure security agency

137
00:06:23,160 --> 00:06:27,120
and they have just an incredible
wealth of information.

138
00:06:27,120 --> 00:06:31,410
There are advisories,
there are news and events,

139
00:06:31,410 --> 00:06:34,140
there are resources, there are actions

140
00:06:34,140 --> 00:06:36,270
that are being spotlighted.

141
00:06:36,270 --> 00:06:38,160
CISA interacts with a
lot of other agencies

142
00:06:38,160 --> 00:06:41,760
and so they pull in information
from other agencies as well.

143
00:06:41,760 --> 00:06:44,100
So this should be a bookmark for you.

144
00:06:44,100 --> 00:06:46,740
This should be a place that
you visit on a regular basis

145
00:06:46,740 --> 00:06:49,230
to get some really excellent information

146
00:06:49,230 --> 00:06:52,470
about what's going on,
not just in in America

147
00:06:52,470 --> 00:06:54,510
but really what's going on worldwide.

148
00:06:54,510 --> 00:06:58,473
So definitely bookmark that, www.cisa.gov.

149
00:06:59,460 --> 00:07:02,130
And that my friends, brings us
to a three second challenge.

150
00:07:02,130 --> 00:07:03,960
Five challenge questions,
three seconds each.

151
00:07:03,960 --> 00:07:05,060
You know how to do it.

152
00:07:06,270 --> 00:07:08,913
Threat model that
focuses on system design.

153
00:07:10,350 --> 00:07:12,030
Remember we talked about
three different approaches.

154
00:07:12,030 --> 00:07:14,280
This one focuses on system design.

155
00:07:14,280 --> 00:07:15,903
One, two, three.

156
00:07:16,830 --> 00:07:18,580
It's gonna be architecture centric.

157
00:07:19,740 --> 00:07:22,623
Number two, the threat
model that focuses on who?

158
00:07:23,460 --> 00:07:27,573
One, two, three. That's attacker centric.

159
00:07:29,370 --> 00:07:31,890
Number three, the US government agency

160
00:07:31,890 --> 00:07:34,305
charged with working with government

161
00:07:34,305 --> 00:07:37,710
and industry to identify,
analyze, prioritize and manage

162
00:07:37,710 --> 00:07:40,860
the most significant
cybersecurity strategic risks

163
00:07:40,860 --> 00:07:43,830
to the nation's critical infrastructure.

164
00:07:43,830 --> 00:07:45,600
Now, I didn't give you all
that when we looked at it

165
00:07:45,600 --> 00:07:49,200
but I said this is the one
you really wanna get to know.

166
00:07:49,200 --> 00:07:50,913
Who is it? One, two, three.

167
00:07:52,110 --> 00:07:54,300
That's gonna be the Cybersecurity

168
00:07:54,300 --> 00:07:57,183
and Infrastructure Security
Agency known as CISA.

169
00:07:59,070 --> 00:08:01,620
Question four, evidence-based knowledge

170
00:08:01,620 --> 00:08:03,063
about an emerging threat.

171
00:08:04,440 --> 00:08:06,423
One, two, three.

172
00:08:07,530 --> 00:08:09,690
There's threat intelligence. Fantastic.

173
00:08:09,690 --> 00:08:12,000
And number five, data collected

174
00:08:12,000 --> 00:08:13,620
from publicly available sources

175
00:08:13,620 --> 00:08:16,023
to be used in an intelligence context.

176
00:08:16,950 --> 00:08:18,723
One, two, three.

177
00:08:19,860 --> 00:08:22,623
That's open source
intelligence known as OSINT.

178
00:08:25,513 --> 00:08:26,346
So let's do a security

179
00:08:26,346 --> 00:08:28,590
and action together about threat modeling.

180
00:08:28,590 --> 00:08:30,600
You've been asked to guide your department

181
00:08:30,600 --> 00:08:32,700
through a threat modeling exercise.

182
00:08:32,700 --> 00:08:35,430
Now, this is the first time
the department has done this

183
00:08:35,430 --> 00:08:38,223
and you are recommending
a hybrid approach.

184
00:08:39,090 --> 00:08:41,460
So I want you to describe
your approach to me

185
00:08:41,460 --> 00:08:43,920
and resources that you might use.

186
00:08:43,920 --> 00:08:46,740
Go ahead, put me on pause,
jot down some notes,

187
00:08:46,740 --> 00:08:49,190
then come back and we'll
talk about the approach.

188
00:08:52,470 --> 00:08:54,450
Well, a hybrid approach to threat modeling

189
00:08:54,450 --> 00:08:58,740
focuses on assets, architecture,
and attackers, right?

190
00:08:58,740 --> 00:09:01,290
And it asks the following questions

191
00:09:01,290 --> 00:09:02,970
what do we have of value?

192
00:09:02,970 --> 00:09:05,250
That's our asset centric.

193
00:09:05,250 --> 00:09:09,570
How would we be attacked?
That's our architecture centric.

194
00:09:09,570 --> 00:09:11,820
And who are our likely attackers?

195
00:09:11,820 --> 00:09:13,503
That's our attacker centric.

196
00:09:15,090 --> 00:09:18,750
Now, our resources could
include a variety of OSINT,

197
00:09:18,750 --> 00:09:22,170
government sources,
researchers, journalists,

198
00:09:22,170 --> 00:09:24,510
thought leaders, and vendors.

199
00:09:24,510 --> 00:09:27,420
So there's a lot of places
for us to get information

200
00:09:27,420 --> 00:09:31,080
to feed into our threat modeling process.

201
00:09:31,080 --> 00:09:32,640
But I really like the idea of starting

202
00:09:32,640 --> 00:09:34,110
with a hybrid approach,

203
00:09:34,110 --> 00:09:37,680
because then you can sort of
pull from all areas, right?

204
00:09:37,680 --> 00:09:39,000
What do we have of value?

205
00:09:39,000 --> 00:09:40,080
Who might be attacked?

206
00:09:40,080 --> 00:09:41,640
What are our likely attackers?

207
00:09:41,640 --> 00:09:42,994
And I guarantee it will result

208
00:09:42,994 --> 00:09:46,050
in a very robust conversation.

209
00:09:46,050 --> 00:09:48,180
So being able to lead this exercise,

210
00:09:48,180 --> 00:09:51,153
that my friends for sure
is security in action.

211
00:09:52,170 --> 00:09:53,400
So that brings us to our word club.

212
00:09:53,400 --> 00:09:54,270
You know what to do.

213
00:09:54,270 --> 00:09:55,590
You wanna go through all of these terms,

214
00:09:55,590 --> 00:09:57,240
make sure that you're
comfortable and confident

215
00:09:57,240 --> 00:09:58,440
before moving on.

216
00:09:58,440 --> 00:10:00,810
And speaking of moving on,
what are we gonna do next?

217
00:10:00,810 --> 00:10:02,970
Well, let's do a quiz together.

218
00:10:02,970 --> 00:10:03,803
See you there.
