3.0 KiB
3.0 KiB
Cyber Threat Intelligence
- Broad Definition
- Any information about threats that can assist decisions for preventing and mitigating an attack
- Examples
- Reading new papers
- Read incident reports
“Cyber Threat intelligence is information about threats and threat actors that helps mitigate harmful events in cyberspace.” [Wikipedia, 2021; Pierluigi Paganini, 2020].
Threat Inelligence Type
Threat Intelligence Sharing
- Standardised language
- Structured Thread Information eXpression (STIX)
- Standardised Exchange Mechanism
- Trusted automated Exchange of Indicator Information (TAXII)
- STIX and TAXII are to enable automated cyber threat information exchange across organisation and product boundaries
Structured Threat Information Expression
- Designed for sharing and analysing threat intelligence
- Can be understood by humans
- Structured language for automation.
- Can be understood by security technology
- Active community of developer and analyst
- International standard in OASIS
Flexible Sharing Models
- Most sharing models are variants of these three basic models
Cyber Kill Chain
- Kill chain is a term used bu the US military
- Lockheed Martin’s process to explain and defensively mitigate future threat
- Deconstructs a threat to individual components
Reconnaissance
- The attacker research on the target before the actual attack starts
- Through Internet Search, and social media
Weaponisation
- The attacker develops a malicious payload and send to the victim
- This setp happens at the attacker side, without contact with the victim
- Difficult to interrupt for prevention
- No longer requires advanced skills
Delivery
- The attacker sends the malicious payload to the victim by email or other means
Exploitation
- Triggers the intruders’ code
- Targets can be
- Application or host system
- An operating system feature that auto-executes code
- User’s themselves
Installation
- Installs malware, remote access Trojan or backdoor on victim system
- Allows the adversary to maintain persistence inside the environment
- Point in time within a much more elaborate attack process that may take months to operate
Command and Control
- The attacker creates a C2 channel in order to control the system remotely
- This step is relevant throughout the attack life-cycle, not just when malware is installed
Action on Objectives
- The attacker takes actions to achieve his original objective inside the victim’s network
- Elaborate active attack process that may take months
- Information Theft
- Hacker Fame / Hactivism - Defacement
- Extortion - Ransomware
- Nation State Leverage
- Destructive malware
- A point to compromise additional systems





