Files
notes/docs/lectures/security/16_cyber_threat_intelligence.md
T
2026-10-04 15:24:17 +01:00

3.0 KiB
Raw Blame History

Cyber Threat Intelligence

  • Broad Definition
    • Any information about threats that can assist decisions for preventing and mitigating an attack
    • Examples
      • Reading new papers
      • Reading incident reports

“Cyber Threat intelligence is information about threats and threat actors that helps mitigate harmful events in cyberspace.” [Wikipedia, 2021; Pierluigi Paganini, 2020].

Threat Intelligence Type

1648755300.png

Threat Intelligence Sharing

  • Standardised language
    • Structured Threat Information eXpression (STIX)
  • Standardised Exchange Mechanism
    • Trusted automated Exchange of Indicator Information (TAXII)
  • STIX and TAXII are to enable automated cyber threat information exchange across organisation and product boundaries
Structured Threat Information Expression
  • Designed for sharing and analysing threat intelligence
  • Can be understood by humans
  • Structured language for automation.
    • Can be understood by security technology
  • Active community of developers and analysts
  • International standard in OASIS

1648755739.png

1648755749.png

Flexible Sharing Models
  • Most sharing models are variants of these three basic models

1648755842.png

1648755851.png

1648755869.png

Cyber Kill Chain

  • Kill chain is a term used by the US military
  • Lockheed Martin’s process to explain and defensively mitigate future threat
  • Deconstructs a threat to individual components
Reconnaissance
  • The attacker researches the target before the actual attack starts
  • Through Internet Search, and social media
Weaponisation
  • The attacker develops a malicious payload and sends it to the victim
  • This step happens on the attacker’s side, without contact with the victim
  • Difficult to interrupt for prevention
  • No longer requires advanced skills
Delivery
  • The attacker sends the malicious payload to the victim by email or other means
Exploitation
  • Triggers the intruders’ code
  • Targets can be
    • Application or host system
    • An operating system feature that auto-executes code
    • Users themselves
Installation
  • Installs malware, remote access Trojan or backdoor on victim system
  • Allows the adversary to maintain persistence inside the environment
  • Point in time within a much more elaborate attack process that may take months to operate
Command and Control
  • The attacker creates a C2 channel in order to control the system remotely
  • This step is relevant throughout the attack life-cycle, not just when malware is installed
Action on Objectives
  • The attacker takes actions to achieve his original objective inside the victim’s network
  • Elaborate active attack process that may take months
    • Information Theft
    • Hacker Fame / Hacktivism - Defacement
    • Extortion - Ransomware
    • Nation State Leverage
    • Destructive malware
  • A point to compromise additional systems