Files
notes/docs/lectures/security/16_cyber_threat_intelligence.md
T

96 lines
3.0 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
## Cyber Threat Intelligence
- Broad Definition
- Any information about threats that can assist decisions for preventing and mitigating an attack
- Examples
- Reading new papers
- Read incident reports
> “Cyber Threat intelligence is information about threats and threat actors that helps mitigate harmful events in cyberspace.” [Wikipedia, 2021; Pierluigi Paganini, 2020].
#### Threat Inelligence Type
![1648755300.png](img/1648755300.png)
#### Threat Intelligence Sharing
- Standardised language
- **S**tructured **T**hread **I**nformation e**X**pression (STIX)
- Standardised Exchange Mechanism
- Trusted automated Exchange of Indicator Information (TAXII)
- STIX and TAXII are to enable automated cyber threat information exchange across organisation and product boundaries
##### Structured Threat Information Expression
- Designed for sharing and analysing threat intelligence
- Can be understood by humans
- Structured language for automation.
- Can be understood by security technology
- Active community of developer and analyst
- International standard in OASIS
![1648755739.png](img/1648755739.png)
![1648755749.png](img/1648755749.png)
###### Flexible Sharing Models
- Most sharing models are variants of these three basic models
![1648755842.png](img/1648755842.png)
![1648755851.png](img/1648755851.png)
![1648755869.png](img/1648755869.png)
#### Cyber Kill Chain
- Kill chain is a term used bu the US military
- Lockheed Martin’s process to explain and defensively mitigate future threat
- Deconstructs a threat to individual components
##### Reconnaissance
- The attacker research on the target before the actual attack starts
- Through Internet Search, and social media
##### Weaponisation
- The attacker develops a malicious payload and send to the victim
- This setp happens at the attacker side, without contact with the victim
- Difficult to interrupt for prevention
- No longer requires advanced skills
##### Delivery
- The attacker sends the malicious payload to the victim by email or other means
##### Exploitation
- Triggers the intruders’ code
- Targets can be
- Application or host system
- An operating system feature that auto-executes code
- User’s themselves
##### Installation
- Installs malware, remote access Trojan or backdoor on victim system
- Allows the adversary to maintain persistence inside the environment
- Point in time within a much more elaborate attack process that may take months to operate
##### Command and Control
- The attacker creates a C2 channel in order to control the system remotely
- This step is relevant throughout the attack life-cycle, not just when malware is installed
##### Action on Objectives
- The attacker takes actions to achieve his original objective inside the victim’s network
- Elaborate active attack process that may take months
- Information Theft
- Hacker Fame / Hactivism - Defacement
- Extortion - Ransomware
- Nation State Leverage
- Destructive malware
- A point to compromise additional systems