96 lines
3.0 KiB
Markdown
96 lines
3.0 KiB
Markdown
## Cyber Threat Intelligence
|
||
|
||
- Broad Definition
|
||
- Any information about threats that can assist decisions for preventing and mitigating an attack
|
||
- Examples
|
||
- Reading new papers
|
||
- Read incident reports
|
||
|
||
> “Cyber Threat intelligence is information about threats and threat actors that helps mitigate harmful events in cyberspace.” [Wikipedia, 2021; Pierluigi Paganini, 2020].
|
||
|
||
#### Threat Inelligence Type
|
||
|
||

|
||
|
||
#### Threat Intelligence Sharing
|
||
|
||
- Standardised language
|
||
- **S**tructured **T**hread **I**nformation e**X**pression (STIX)
|
||
- Standardised Exchange Mechanism
|
||
- Trusted automated Exchange of Indicator Information (TAXII)
|
||
- STIX and TAXII are to enable automated cyber threat information exchange across organisation and product boundaries
|
||
|
||
##### Structured Threat Information Expression
|
||
|
||
- Designed for sharing and analysing threat intelligence
|
||
- Can be understood by humans
|
||
- Structured language for automation.
|
||
- Can be understood by security technology
|
||
- Active community of developer and analyst
|
||
- International standard in OASIS
|
||
|
||

|
||
|
||

|
||
|
||
###### Flexible Sharing Models
|
||
|
||
- Most sharing models are variants of these three basic models
|
||
|
||

|
||
|
||

|
||
|
||

|
||
|
||
#### Cyber Kill Chain
|
||
|
||
- Kill chain is a term used bu the US military
|
||
- Lockheed Martin’s process to explain and defensively mitigate future threat
|
||
- Deconstructs a threat to individual components
|
||
|
||
##### Reconnaissance
|
||
|
||
- The attacker research on the target before the actual attack starts
|
||
- Through Internet Search, and social media
|
||
|
||
##### Weaponisation
|
||
|
||
- The attacker develops a malicious payload and send to the victim
|
||
- This setp happens at the attacker side, without contact with the victim
|
||
- Difficult to interrupt for prevention
|
||
- No longer requires advanced skills
|
||
|
||
##### Delivery
|
||
|
||
- The attacker sends the malicious payload to the victim by email or other means
|
||
|
||
##### Exploitation
|
||
|
||
- Triggers the intruders’ code
|
||
- Targets can be
|
||
- Application or host system
|
||
- An operating system feature that auto-executes code
|
||
- User’s themselves
|
||
|
||
##### Installation
|
||
|
||
- Installs malware, remote access Trojan or backdoor on victim system
|
||
- Allows the adversary to maintain persistence inside the environment
|
||
- Point in time within a much more elaborate attack process that may take months to operate
|
||
|
||
##### Command and Control
|
||
|
||
- The attacker creates a C2 channel in order to control the system remotely
|
||
- This step is relevant throughout the attack life-cycle, not just when malware is installed
|
||
|
||
##### Action on Objectives
|
||
|
||
- The attacker takes actions to achieve his original objective inside the victim’s network
|
||
- Elaborate active attack process that may take months
|
||
- Information Theft
|
||
- Hacker Fame / Hactivism - Defacement
|
||
- Extortion - Ransomware
|
||
- Nation State Leverage
|
||
- Destructive malware
|
||
- A point to compromise additional systems |