33 - idnog03 - guy rosefelt (nsfocus) - threat intelligence

23
SESSION ID: #RSAC Guy Rosefelt Threat Intelligence: Is it any good? GPS2-R02 Dir, Threat Intelligence NSFOCUS, INC

Upload: indonesia-network-operators-group

Post on 13-Apr-2017

221 views

Category:

Internet


0 download

TRANSCRIPT

Page 1: 33 - IDNOG03  - Guy Rosefelt (NSFOCUS) - Threat Intelligence

SESSIONID:

#RSAC

GuyRosefelt

ThreatIntelligence:Isitanygood?

GPS2-R02

Dir,ThreatIntelligenceNSFOCUS,INC

Page 2: 33 - IDNOG03  - Guy Rosefelt (NSFOCUS) - Threat Intelligence

#RSAC

Agenda

2

Whythebadrap?

WhatisThreatIntelligencereally?

Whydowecare?

Somecasestudiesthatshowvalue

Somepromisingresearch

HowcanyoubetterapplyThreatIntelligence?

Page 3: 33 - IDNOG03  - Guy Rosefelt (NSFOCUS) - Threat Intelligence

#RSAC

Whythebadrap?

Page 4: 33 - IDNOG03  - Guy Rosefelt (NSFOCUS) - Threat Intelligence

#RSAC

ImplosionofNorseCorp

• Liar,Liar,KPMGCapital'sInvestmentIntoNorseCorp.OnFire• Forbes– Feb01,2016

• FiredNorseCorpCEOBlamestheMedia• TheRegisterUK– Feb04,2016

• Sources:SecurityFirmNorseCorp.Imploding• KrebsonSecurity – Jan30,2016

• NorseCorpdisappearsshortlyafterCEOisaskedtostepdown• CSOOnline.com– Feb01,2016

Page 5: 33 - IDNOG03  - Guy Rosefelt (NSFOCUS) - Threat Intelligence

#RSAC

CascadeEffect

• No,NorseisNotaBellwetheroftheThreatIntelIndustrybutDoesHoldLessonsLearned

• RobertM.Lee – Jan30,2016

• NorseIsInTrouble-Justacompany-specificblow,orraisingbiggerquestionsaboutthreatintel.

• peerlyst – Jan30,2016

• AfterNorse:VCs,proseyecyberinvestments• SCMagazine– Feb3,2016

• Only42%ofinfosecprosusethreatintelligence,surveyshows• ComputerWeekly–Mar22,2016

• ThreatIntelligence- TheAnswer toThreatsorAnotherFad?• Infosecurity–May24,2016

Page 6: 33 - IDNOG03  - Guy Rosefelt (NSFOCUS) - Threat Intelligence

#RSAC

WhatisThreatIntelligencereally?

Page 7: 33 - IDNOG03  - Guy Rosefelt (NSFOCUS) - Threat Intelligence

#RSAC

DifferentThingstoDifferentPeople

Auto NGFW/IPS/WAF Policy Creation

Page 8: 33 - IDNOG03  - Guy Rosefelt (NSFOCUS) - Threat Intelligence

#RSAC

Gartnersays…

8

"Threatintelligenceisevidence-based knowledge, includingcontext,mechanisms, indicators, implicationsandactionable

advice,aboutanexistingoremergingmenaceorhazardtoassetsthatcanbeusedtoinformdecisions regarding thesubject's

response tothatmenaceorhazard."-Definition:ThreatIntelligence,Gartner16May2013(https://www.gartner.com/doc/2487216/definition-threat- inte lligence)

Page 9: 33 - IDNOG03  - Guy Rosefelt (NSFOCUS) - Threat Intelligence

#RSAC

Gartnersays…

9

"Threatintelligenceisevidence-based knowledge, includingcontext,mechanisms, indicators, implicationsandactionable

advice,aboutanexistingoremergingmenaceorhazardtoassetsthatcanbeusedtoinformdecisions regarding thesubject's

response tothatmenaceorhazard.“-Definition:ThreatIntelligence,Gartner16May2013(https://www.gartner.com/doc/2487216/definition-threat- inte lligence)

Page 10: 33 - IDNOG03  - Guy Rosefelt (NSFOCUS) - Threat Intelligence

#RSAC

WhatisaThreatIntelligenceDataFeed?

10

Youmightbesurprised……

LogsareyourfriendWAF,IDS,webserver,firewalls….

YouhaveyourowncuratorSEIM,logaggregator,Splunk…

OpenSourceTons!... HailaTAXII,I-Blocklist,OpenPhish Feeds,CVEdatabase…

CommercialNSFOCUS, FireEye/iSight,Symantec,Cyveillance,…

Page 11: 33 - IDNOG03  - Guy Rosefelt (NSFOCUS) - Threat Intelligence

#RSAC

Whydowecare?

Page 12: 33 - IDNOG03  - Guy Rosefelt (NSFOCUS) - Threat Intelligence

#RSAC

BuyaSubscription/Service Everything isWarmandFuzzy

ThreatIntelligenceiswhatyoudowithit!

Data

Data

Data

Data

Page 13: 33 - IDNOG03  - Guy Rosefelt (NSFOCUS) - Threat Intelligence

#RSAC

Whatdoyouwanttodowithit?

Proactivelyblockpotentialattacks

Proactivelyblockinformationleakage

Detectthreatsfaster

Providemorecontexttosecurityalerts

Providemorecontexttovulnerabilities,exploits,etc.

Providebetterriskassessmentaboutmyinternetpresence,myorganization,myindustry,etc.

Page 14: 33 - IDNOG03  - Guy Rosefelt (NSFOCUS) - Threat Intelligence

#RSAC

ReduceTimetoRespond

Measure(M)

Counter-measure(CM)

EarlyDaysOfSecurity

Time

Currently

M CM

Future

Howdoweclose thisgap

M CM

Page 15: 33 - IDNOG03  - Guy Rosefelt (NSFOCUS) - Threat Intelligence

#RSAC

65%OfOrganizationssay

attacksevadeexistingpreventive

tools

54%OfBreachesremainundiscovered for

months

DetectionTimevs.Impact

Sources:CiscoAMPResearch,TrendMicro,Fortinet

Page 16: 33 - IDNOG03  - Guy Rosefelt (NSFOCUS) - Threat Intelligence

#RSAC

MovetoShareData

Preventive, static, reactive

Current Security Model

Fire

wal

l

IDS/

IPS

A/V

Anti-

DD

oS

Hardware Software

Adaptive, dynamic, proactive

Advanced Network SecurityInternet

ThreatIntelligence

Security Platform

Fire

wal

l

IDS/

IPS

A/V

Anti-

DD

oS

Hardware Software Cloud

From Security Silos to a Security Platform

Page 17: 33 - IDNOG03  - Guy Rosefelt (NSFOCUS) - Threat Intelligence

#RSAC

TI-driven Security Solution

Alert totimelyfix

Analytics

IPS/ Sandbox

WAF

Cloud Service

Device ->Ability

Close ->Open

APIs 3rd-PartySOC

AdjacentTechniquesincludingDAST,Anti-DDoS, etc.

Collaboration

ThreatIntelligenceDataSharing

SOC

Web Reputation

IPReputation

FileReputation

Threat Intelligence Feeds

Services & Expertise

Some types of indicators• IP (GeoIP, Tor, CDN)• File reputation (hash)• Tools (scanners)• Stolen credentials & weak

passwords

Page 18: 33 - IDNOG03  - Guy Rosefelt (NSFOCUS) - Threat Intelligence

#RSAC

ReducedTimetoPrepare&Respond

Measure(M)

Counter-measure(CM)

EarlyDaysOfSecurity

Time

Currently

M CM

Future

Leveraging TIwithNextGenproducts

Crowdsourcing customerswillhavecountermeasures inplace fasterthananyone

else!

M CM

Page 19: 33 - IDNOG03  - Guy Rosefelt (NSFOCUS) - Threat Intelligence

#RSAC

Somecasestudiesthatshowvalue

Page 20: 33 - IDNOG03  - Guy Rosefelt (NSFOCUS) - Threat Intelligence

#RSAC

Somepromisingresearch

Page 21: 33 - IDNOG03  - Guy Rosefelt (NSFOCUS) - Threat Intelligence

#RSAC

HowcanyoubetterapplyThreatIntelligence?

Page 22: 33 - IDNOG03  - Guy Rosefelt (NSFOCUS) - Threat Intelligence

#RSAC

ReducedTimetoPrepare&Respond

Measure(M)

Counter-measure(CM)

EarlyDaysOfSecurity

Time

Currently

M CM

Future

Leveraging TIwithNextGenproducts

Crowdsourcing customerswillhavecountermeasures inplace fasterthananyone

else!

M CM

Page 23: 33 - IDNOG03  - Guy Rosefelt (NSFOCUS) - Threat Intelligence

#RSAC

Thankyou!