Add the rest of university notes
This commit is contained in:
366 files changed
+9844
-110
No files matched your search
@@ -0,0 +1,96 @@
|
||||
## Cyber Threat Intelligence
|
||||
|
||||
- Broad Definition
|
||||
- Any information about threats that can assist decisions for preventing and mitigating an attack
|
||||
- Examples
|
||||
- Reading new papers
|
||||
- Read incident reports
|
||||
|
||||
> “Cyber Threat intelligence is information about threats and threat actors that helps mitigate harmful events in cyberspace.” [Wikipedia, 2021; Pierluigi Paganini, 2020].
|
||||
|
||||
#### Threat Inelligence Type
|
||||
|
||||

|
||||
|
||||
#### Threat Intelligence Sharing
|
||||
|
||||
- Standardised language
|
||||
- **S**tructured **T**hread **I**nformation e**X**pression (STIX)
|
||||
- Standardised Exchange Mechanism
|
||||
- Trusted automated Exchange of Indicator Information (TAXII)
|
||||
- STIX and TAXII are to enable automated cyber threat information exchange across organisation and product boundaries
|
||||
|
||||
##### Structured Threat Information Expression
|
||||
|
||||
- Designed for sharing and analysing threat intelligence
|
||||
- Can be understood by humans
|
||||
- Structured language for automation.
|
||||
- Can be understood by security technology
|
||||
- Active community of developer and analyst
|
||||
- International standard in OASIS
|
||||
|
||||

|
||||
|
||||

|
||||
|
||||
###### Flexible Sharing Models
|
||||
|
||||
- Most sharing models are variants of these three basic models
|
||||
|
||||

|
||||
|
||||

|
||||
|
||||

|
||||
|
||||
#### Cyber Kill Chain
|
||||
|
||||
- Kill chain is a term used bu the US military
|
||||
- Lockheed Martin’s process to explain and defensively mitigate future threat
|
||||
- Deconstructs a threat to individual components
|
||||
|
||||
##### Reconnaissance
|
||||
|
||||
- The attacker research on the target before the actual attack starts
|
||||
- Through Internet Search, and social media
|
||||
|
||||
##### Weaponisation
|
||||
|
||||
- The attacker develops a malicious payload and send to the victim
|
||||
- This setp happens at the attacker side, without contact with the victim
|
||||
- Difficult to interrupt for prevention
|
||||
- No longer requires advanced skills
|
||||
|
||||
##### Delivery
|
||||
|
||||
- The attacker sends the malicious payload to the victim by email or other means
|
||||
|
||||
##### Exploitation
|
||||
|
||||
- Triggers the intruders’ code
|
||||
- Targets can be
|
||||
- Application or host system
|
||||
- An operating system feature that auto-executes code
|
||||
- User’s themselves
|
||||
|
||||
##### Installation
|
||||
|
||||
- Installs malware, remote access Trojan or backdoor on victim system
|
||||
- Allows the adversary to maintain persistence inside the environment
|
||||
- Point in time within a much more elaborate attack process that may take months to operate
|
||||
|
||||
##### Command and Control
|
||||
|
||||
- The attacker creates a C2 channel in order to control the system remotely
|
||||
- This step is relevant throughout the attack life-cycle, not just when malware is installed
|
||||
|
||||
##### Action on Objectives
|
||||
|
||||
- The attacker takes actions to achieve his original objective inside the victim’s network
|
||||
- Elaborate active attack process that may take months
|
||||
- Information Theft
|
||||
- Hacker Fame / Hactivism - Defacement
|
||||
- Extortion - Ransomware
|
||||
- Nation State Leverage
|
||||
- Destructive malware
|
||||
- A point to compromise additional systems
|
||||
Reference in new issue
Block a user