Transcript
Page 1: How do you predict the threat landscape?

HOW DO YOU PREDICT THE THREAT LANDSCAPE?

Janne Pirttilahti

Director, New Services, F-Secure Cyber Security Services

Page 2: How do you predict the threat landscape?

2

Holistic cyber security

Definitions

Why predictive capabilities matter

Predictive approach to cyber threats

Threat intelligence

Recommendations

AGENDA

Page 3: How do you predict the threat landscape?

CYBER SECURITY IS A PROCESS

3

Understand your risk, know your attack surface,

uncover weak spots

React to breaches,mitigate the damage,

analyze and learn

Minimize attack surface, prevent incidents

Recognize incidents and threats, isolate and

contain them

Page 4: How do you predict the threat landscape?

CYBER SECURITY IS A PROCESS

4

Understand your risk, know your attack surface,

uncover weak spots

React to breaches,mitigate the damage,

analyze and learn

Minimize attack surface, prevent incidents

Recognize incidents and threats, isolate and

contain them

Page 5: How do you predict the threat landscape?

PREDICT\Pri-`dikt\

To declare or indicate in advance; especially : foretell on the basis of observation, experience, or scientific reason

Source: Merriam Webster

5

Page 6: How do you predict the threat landscape?

6

Top three behaviors that impact us?

What do future attacks look like?

Where to invest next?

How to train our people?

How to prepare oneself and for what?

PREDICTIVE CAPABILITIES ARE NEEDED TO ANSWER MANY QUESTIONS

Page 7: How do you predict the threat landscape?

PRIORITIZE.BE PREPARED.

7

Page 8: How do you predict the threat landscape?

MARSH & MCLENNAN CYBER HANDBOOK:

MOST ORGANIZATIONS NOT ADEQUATELY PREPARED FOR

CYBER ATTACK

8

Page 9: How do you predict the threat landscape?

9

Page 10: How do you predict the threat landscape?

10

Page 11: How do you predict the threat landscape?

11

Page 12: How do you predict the threat landscape?

12 Source: www.databreaches.net

Page 13: How do you predict the threat landscape?

13

October

Page 14: How do you predict the threat landscape?

14

October

November

Page 15: How do you predict the threat landscape?

PREDICTIVE APPROACH TO CYBER THREATS

15

2) ACTIONABLE THREAT INTELLIGENCE

PROACTIVELY ANTICIPATE NEW ATTACKS

1) ASSET & VULNERABILITY MANAGEMENT

UNDERSTAND THE CURRENT STATE OF YOUR SYSTEMS

Page 16: How do you predict the threat landscape?

THE FOUNDATION OF ACTIONABLE INTELLIGENCE IS TO KNOW YOUR OWN

SYSTEMS

16

Page 17: How do you predict the threat landscape?

THREAT INTELLIGENCE:FOREWARNED IS

FOREARMED

17

Page 18: How do you predict the threat landscape?

18

“Threat intelligence is evidence-based knowledge (e.g. context, mechanisms, indicators, implications

and action-oriented advice) about existing or emerging menaces or hazards to assets.

CISOs should plan for current threats, as well as those that could emerge in the long term (e.g. in three

years).”

Gartner, February 2016

Page 19: How do you predict the threat landscape?

19

CDN

STIXTAXII

OSINT

HUMINT

TLP

IOC

CTI

IOA

DGA

MD5 MRTI

ISAC

ISAO CTIIC

NCCIC

TTPTAP

SHA1

OTX

SIEM

CISAIODEF OPENIOC

CYBOX

YARA

Technical Intel

Adversary Intel

Vulnerability Intel

Breach Monitoring

TIP

Strategic Intel

Data Enrichment

Page 20: How do you predict the threat landscape?

20

STRATEGIC / EXECUTIVE LEVEL

THE DIFFERENT LEVELS OF THREAT INTELLIGENCE

– Strategic, high level information of changing risk– Geopolitics, Foreign Markets, Cultural Background– Vision timeframe: years

Page 21: How do you predict the threat landscape?

21

OPERATIONAL / TACTICAL

STRATEGIC / EXECUTIVE LEVEL

THE DIFFERENT LEVELS OF THREAT INTELLIGENCE

– Strategic, high level information of changing risk– Geopolitics, Foreign Markets, Cultural Background– Vision timeframe: years

– Details of specific incoming risk: who, what, when? – Attacker’s methods, tools and tactics, their modus operandi – Early warnings of incoming attacks– Vision timeframe: months, weeks, hours

Page 22: How do you predict the threat landscape?

22

OPERATIONAL / TACTICAL

STRATEGIC / EXECUTIVE LEVEL

TECHNICAL

THE DIFFERENT LEVELS OF THREAT INTELLIGENCE

– Strategic, high level information of changing risk– Geopolitics, Foreign Markets, Cultural Background– Vision timeframe: years

– Details of specific incoming risk: who, what, when? – Attacker’s methods, tools and tactics, their modus operandi – Early warnings of incoming attacks– Vision timeframe: months, weeks, hours

– Specific IOCs (for SIEM, FW, etc. integration)– More data, less intel– Automated processing is paramount – Vision timeframe: hours, minutes (but also long lasting)

Page 23: How do you predict the threat landscape?

MANY ORGANIZATIONS START WITH FREE SOLUTIONS.

23

Page 24: How do you predict the threat landscape?

24

Page 25: How do you predict the threat landscape?

25

Page 26: How do you predict the threat landscape?

NOTHING BEATS AN EXPERT.

26

Page 27: How do you predict the threat landscape?

PROCURING STRATEGICALLY RELEVANT INTELLIGENCE IS

EXTRAVAGANT.

27

Page 28: How do you predict the threat landscape?

STRATEGICALLY RELEVANT DATA IS UNIQUE TO EACH COMPANY

28

All threat data:Vulnerability feeds

Exploit kit feedsMalicious software feeds

Indicators of compromise feedsBad IP address feeds

Botnet activities feedsDNS changes feeds

Reputation feeds (URL & content)Known threat actor behavior data

All ”breadcrumb” data from company personnel

…Global

landscape

Business area landscape

Possibly relevant data

Strategically important data

Page 29: How do you predict the threat landscape?

EVEN ACTIONABLE INTELLIGENCE IS

ONLY WORTH IT WITH PROCESSES IN PLACE TO EFFECTIVELY ACT ON IT.

29

Page 30: How do you predict the threat landscape?

CYBER SECURITY IS A PROCESS

30

Understand your risk, know your attack surface,

uncover weak spots

React to breaches,mitigate the damage,

analyze and learn

Minimize attack surface, prevent incidents

Recognize incidents and threats, isolate and

contain them

Page 31: How do you predict the threat landscape?

Understanding your own environment is the foundation

31

CLOSING WORDS

Page 32: How do you predict the threat landscape?

Understanding your own environment is the foundation

There are both commercial and free options available

32

CLOSING WORDS

Page 33: How do you predict the threat landscape?

Understanding your own environment is the foundation

There are both commercial and free options available

Start from figuring out what benefits you the most

33

CLOSING WORDS

Page 34: How do you predict the threat landscape?

Understanding your own environment is the foundation

There are both commercial and free options available

Start from figuring out what benefits you the most

Threat Intelligence can strengthen your security posture

34

CLOSING WORDS

Page 35: How do you predict the threat landscape?

QUESTIONS & ANSWERS

35

Page 36: How do you predict the threat landscape?

f-secure.com


Top Related