Professional Documents
Culture Documents
- A high-level overview
Christian Doerr
TU Delft, Cyber Threat Intelligence Lab
Delft
University of
Technology
https://www.cyber-threat-intelligence.com 2
The Devices that Gave Away their Masters
Friday, November 16, 18
For effective Cyber Defense you need
Cyber Threat Intelligence
Organized crime
Script Kiddies Hacktivists
Cracker Nation-state
Cyber actors
terrorists
Who is out there (and after me)?
3
The Devices that Gave Away their Masters
Friday, November 16, 18
What is Threat Intelligence?
The purpose of threat intelligence is to understand the enemy,
help anticipate future actions and plan a response.
Knowns Unknowns
Data
Things we are not Things we don't know
Unknowns aware of but would that they exist
understand and don't understand
Understanding
4
The Devices that Gave Away their Masters
Friday, November 16, 18
What is Threat Intelligence?
The purpose of threat intelligence is to understand the enemy,
help anticipate future actions and plan a response. Improving
Data
Improving
Interpretation Knowns Unknowns
Data
Things we are not Things we don't know
Unknowns aware of but would that they exist
understand and don't understand
Understanding
4
The Devices that Gave Away their Masters
Friday, November 16, 18
When is it a threat to me?
Attacker
5
The Devices that Gave Away their Masters
Friday, November 16, 18
When is it a threat to me?
Attacker
5
The Devices that Gave Away their Masters
Friday, November 16, 18
Strategic Cyber Threat Intelligence
6
The Devices that Gave Away their Masters
Friday, November 16, 18
Operational Cyber Threat Intelligence
7
The Devices that Gave Away their Masters
Friday, November 16, 18
Tactical Cyber Threat Intelligence
c ti ca l
Ta
8
The Devices that Gave Away their Masters
Friday, November 16, 18
Intelligence starts with a question
and answers it
9
The Devices that Gave Away their Masters
Friday, November 16, 18
CTI Interaction in the Organization
and Standardization Efforts
commercial feeds
shared intelligence
asset information
10
The Devices that Gave Away their Masters
Friday, November 16, 18
CTI Interaction in the Organization
and Standardization Efforts
shared intelligence
asset information
10
The Devices that Gave Away their Masters
Friday, November 16, 18
CTI Interaction in the Organization
and Standardization Efforts
shared intelligence
asset information
10
The Devices that Gave Away their Masters
Friday, November 16, 18
CTI Interaction in the Organization
and Standardization Efforts
10
The Devices that Gave Away their Masters
Friday, November 16, 18
CTI Interaction in the Organization
and Standardization Efforts
subject to active
research
shared intelligence
asset information
10
The Devices that Gave Away their Masters
Friday, November 16, 18
CTI Interaction in the Organization
and Standardization Efforts
subject to active
research
shared intelligence
asset information
11
The Devices that Gave Away their Masters
Friday, November 16, 18
CTI Interaction in the Organization
and Standardization Efforts
asset information
11
The Devices that Gave Away their Masters
Friday, November 16, 18
CTI Interaction in the Organization
and Standardization Efforts
asset information
11
The Devices that Gave Away their Masters
Friday, November 16, 18
CTI Interaction in the Organization
and Standardization Efforts
asset information
11
The Devices that Gave Away their Masters
Friday, November 16, 18
CTI Interaction in the Organization
and Standardization Efforts
Terminology
Methods and Techniques
asset information
11
The Devices that Gave Away their Masters
Friday, November 16, 18
Processing CTI:
The Intelligence Cycle
Planning and
Direction
Dissemination and
Collection
Integration
12
The Devices that Gave Away their Masters
Friday, November 16, 18
Processing CTI:
The Intelligence Cycle
Start with intelligence gaps
and prioritize them.
Planning and
Direction
Dissemination and
Collection
Integration
12
The Devices that Gave Away their Masters
Friday, November 16, 18
Processing CTI:
The Intelligence Cycle
Planning and
Determine which data sources
Direction you need and how to get
them. Acquire the data.
Dissemination and
Collection
Integration
12
The Devices that Gave Away their Masters
Friday, November 16, 18
Processing CTI:
The Intelligence Cycle
Planning and
Direction
Dissemination and
Correlation and validation of
Integration
Collection data. Evaluate its usefulness to
answer the question.
12
The Devices that Gave Away their Masters
Friday, November 16, 18
Processing CTI:
The Intelligence Cycle
Planning and
Direction
Dissemination and
Collection
Integration
12
The Devices that Gave Away their Masters
Friday, November 16, 18
Processing CTI:
The Intelligence Cycle
Planning and
Direction
Dissemination and
Collection
Integration
Act Orient
You can also use strategy to disrupt the
activities of the adversary.
Decide
13
The Devices that Gave Away their Masters
Friday, November 16, 18
OODA
Act Orient
You can also use strategy to disrupt the
activities of the adversary.
Decide
O O D A O O D A
13
The Devices that Gave Away their Masters
Friday, November 16, 18
Cyber Kill Chain
Reconnaissance
Weaponization
Delivery
Exploitation
Installation
Command
and Control
Actions
Cost to Defender
14
The Devices that Gave Away their Masters
Friday, November 16, 18
Cyber Kill Chain can help you structure
knowledge about adversarial TTPs
Reconnaissance
Weaponization
Infrastructure Capability
IP, DNS, email malware, exploit kits,
stolen TLS certs, tools
Victim
persona, network assets,
email addresses
16
The Devices that Gave Away their Masters
Friday, November 16, 18
Diamond Model
Intention
Infrastructure Capability
IP, DNS, email malware, exploit kits,
stolen TLS certs, tools
Victim
persona, network assets,
email addresses
16
The Devices that Gave Away their Masters
Friday, November 16, 18
Diamond Model
TTP
Infrastructure Capability
IP, DNS, email malware, exploit kits,
stolen TLS certs, tools
Victim
persona, network assets,
email addresses
16
The Devices that Gave Away their Masters
Friday, November 16, 18
CTI Interaction in the Organization
and Standardization Efforts
18
The Devices that Gave Away their Masters
Friday, November 16, 18
CTI Interaction in the Organization
and Standardization Efforts
CTI Education
(Training + Quality Standards)
18
The Devices that Gave Away their Masters
Friday, November 16, 18
Key Takeaways
19
The Devices that Gave Away their Masters
Friday, November 16, 18
Thank you
Christian Doerr
Cyber Threat Intelligence Lab
https://www.cyber-threat-intelligence.com
c.doerr@tudelft.nl
20
The Devices that Gave Away their Masters
Friday, November 16, 18