data-driven threat intelligence: metrics on indicator … · 2018-05-11 · data-driven threat...

38
Data - Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (# ddti ) Alex Pinto Chief Data Scientist MLSec Project @alexcpsec @MLSecProject Alexandre Sieira CTO Niddel @AlexandreSieira @NiddelCorp

Upload: others

Post on 31-Jul-2020

4 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Data-Driven Threat Intelligence: Metrics on Indicator … · 2018-05-11 · Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief

Data-DrivenThreatIntelligence:MetricsonIndicatorDisseminationandSharing

(#ddti)

AlexPintoChiefDataScientist

MLSec Project@alexcpsec

@MLSecProject

AlexandreSieiraCTONiddel

@AlexandreSieira@NiddelCorp

Page 2: Data-Driven Threat Intelligence: Metrics on Indicator … · 2018-05-11 · Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief

• Previouslyon#ddti• ChallengesatTISharing• MeasuringTISharing• TheFutureofSharing

Agenda

Page 3: Data-Driven Threat Intelligence: Metrics on Indicator … · 2018-05-11 · Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief

Thisisadata-drivenwebinar!Pleasecheckyouranecdotesatthedoor

Page 4: Data-Driven Threat Intelligence: Metrics on Indicator … · 2018-05-11 · Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief

Previouslyon#ddti• UsefulMethodsandMeasurementsforHandlingIndicators• AnalysisofThreatIntelligenceFeeds• Indirectly,amethodologyforanalyzingTIProviders

• Combine(https://github.com/mlsecproject/combine)• GathersTIdata(ip/host)fromInternetandlocalfiles

• TIQ-Test(https://github.com/mlsecproject/tiq-test)• RunsstatisticalsummariesandtestsonTIfeeds

Page 5: Data-Driven Threat Intelligence: Metrics on Indicator … · 2018-05-11 · Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief

TIQ-TEST- TonsofThreat-yTests

• NOVELTY – Howoftendothefeedsupdatethemselves?• AGING – Howlongdoesanindicatorsitonafeed?• POPULATION – Howdoesthispopulationdistributioncomparetomydata?

• OVERLAP– Howdotheindicatorscomparetotheonesyougot?

• UNIQUENESS – Howmanyindicatorsarefoundonlyononefeed?

Puttingthisthreatinteldatatowork

Page 6: Data-Driven Threat Intelligence: Metrics on Indicator … · 2018-05-11 · Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief

OverlapTestMoredataisfine,butmakesure

itisdifferent

Page 7: Data-Driven Threat Intelligence: Metrics on Indicator … · 2018-05-11 · Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief

OverlapTest- Outbound

Page 8: Data-Driven Threat Intelligence: Metrics on Indicator … · 2018-05-11 · Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief

UniquenessTestCanwetellifweareclosetofinding*all*thethreats?

Page 9: Data-Driven Threat Intelligence: Metrics on Indicator … · 2018-05-11 · Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief
Page 10: Data-Driven Threat Intelligence: Metrics on Indicator … · 2018-05-11 · Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief

Ihatequotingmyself,but…

Page 11: Data-Driven Threat Intelligence: Metrics on Indicator … · 2018-05-11 · Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief

KeyTakeaway#1

MORE!=BETTERThreatIntelligenceIndicatorFeeds

ThreatIntelligenceProgram

Page 12: Data-Driven Threat Intelligence: Metrics on Indicator … · 2018-05-11 · Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief

ConstructiveFeedbackfromtheInternet:

“TISharingisTOTALLYgoingtosolvethis”

Right,folks?Right?

Page 13: Data-Driven Threat Intelligence: Metrics on Indicator … · 2018-05-11 · Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief

TISharingSolutionPlan:

1. ThebestThreatIntelligenceistheonethatyouanalyzefromyourownincidents(homegrown/organicintelligence)

2. Thereisstrengthinnumbers– verticalherdimmunity!

3. ????????

4. PROFIT!!(oratleastSECURITY!!)

Oratleastaroughstrawman

Page 14: Data-Driven Threat Intelligence: Metrics on Indicator … · 2018-05-11 · Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief

IfCONSUMINGisforthe1%,whatisthepercentageoforganizationsabletoPRODUCE?

Issue1- BYOTI

Page 15: Data-Driven Threat Intelligence: Metrics on Indicator … · 2018-05-11 · Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief

Issue2- HerdImmunity

Source:www.vaccines.gov

• Wemaybeabletodetectmore”virusstrains”togetherbutweare*terrible*atinoculation.

• Thethingswedetectthemostmutatetoofast(PyramidofPain)

• Whodidn’tgetimmunized,stillgetssick(FOMO-TI)

Page 16: Data-Driven Threat Intelligence: Metrics on Indicator … · 2018-05-11 · Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief

TheCognitiveDissonancesofTISharing

Everybody shouldshare! TheCIRCLEOFTRUST

Page 17: Data-Driven Threat Intelligence: Metrics on Indicator … · 2018-05-11 · Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief

Doyoutrustthegroupenoughtoconsume?

TheTwoSidesoftheTrustCoin

Doyoutrustthegroupenoughtoshare?

Page 18: Data-Driven Threat Intelligence: Metrics on Indicator … · 2018-05-11 · Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief

Howaboutmeasuringit?WewouldliketothankthekindcontributionofdatafromthefinefolksatFacebookThreatExchange andThreatConnect

…andalsothesharingcommunitiesthatchosetoremainanonymous.Youknowwhoyouare,andwe❤ youtoo.

Page 19: Data-Driven Threat Intelligence: Metrics on Indicator … · 2018-05-11 · Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief

OVERLAPSLIDE

Page 20: Data-Driven Threat Intelligence: Metrics on Indicator … · 2018-05-11 · Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief

OVERLAPSLIDE

Page 21: Data-Driven Threat Intelligence: Metrics on Indicator … · 2018-05-11 · Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief

UNIQUENESSSLIDE

Lookslikewewouldgetsimilarqualityona”good”ThreatIntelligenceSharingPlatformaswewouldon

a”paidfeed"

Page 22: Data-Driven Threat Intelligence: Metrics on Indicator … · 2018-05-11 · Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief

ActivityMetricIsthereanyactualsharinggoing

on?

Page 23: Data-Driven Threat Intelligence: Metrics on Indicator … · 2018-05-11 · Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief

Updatefrequencychart

High10saverage Low100saverage

Large– 10.000smembers Small– High10smembers

LargeCommunityisroughly36x

biggerthanSmallCommunity

Page 24: Data-Driven Threat Intelligence: Metrics on Indicator … · 2018-05-11 · Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief

DiversityMetricCheckyoursharingprivilege

Page 25: Data-Driven Threat Intelligence: Metrics on Indicator … · 2018-05-11 · Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief

Roughly10%oftheorganizationsshare

dataintothecommunity

Page 26: Data-Driven Threat Intelligence: Metrics on Indicator … · 2018-05-11 · Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief

Someorganizationsareclearlyinabetterpositionoperationallyandlegallytoshare.Andthatis

expectedduetoourpremises.

Page 27: Data-Driven Threat Intelligence: Metrics on Indicator … · 2018-05-11 · Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief

FeedbackMetricButisthedataanygood?

Page 28: Data-Driven Threat Intelligence: Metrics on Indicator … · 2018-05-11 · Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief
Page 29: Data-Driven Threat Intelligence: Metrics on Indicator … · 2018-05-11 · Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief

FeedbackMetric• Almostnosupportonautomation-drivenplatforms• Someallowyoutoleave”comments”or”newdescriptors”fortheIOCs– evenbycountingthoseverylow%inrelationtonewshareddata

• Analyst-drivenenvironmentsallowforcollaborationone-mailsandforumpoststodescribeandrefinestrategiesandbestpractices.

• Howcanwemakethiscollaborationworkonautomation-drivenplatforms?

Page 30: Data-Driven Threat Intelligence: Metrics on Indicator … · 2018-05-11 · Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief

TrustMetricArewehelpingallthecommunity

orjustafeworgsatatime?

Page 31: Data-Driven Threat Intelligence: Metrics on Indicator … · 2018-05-11 · Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief
Page 32: Data-Driven Threat Intelligence: Metrics on Indicator … · 2018-05-11 · Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief

TrustMetric• Theroughestimateseemstobethatmorethan50%of”sharing”(IOCs,messages,etc)happensin”privategroups”insidetheinfrastructureofthesharingplatform

• Allcommunitieshavethem:• PartoftheDNAoftheIC/clearedcommunity• Offsetsthetrustequation,butdefeatsthe”herdimmunity”argument• UsuallyMANDATORYoncollaborationwithLEA

• Butthenthe”good”dataisnothelping”thecommunity”isthereanywaywecanreconcile?

Page 33: Data-Driven Threat Intelligence: Metrics on Indicator … · 2018-05-11 · Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief

TheFutureofSharingAttheveryleastmyhumble

opinionJ

Page 34: Data-Driven Threat Intelligence: Metrics on Indicator … · 2018-05-11 · Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief

#squadgoalsIncreasetheTRUST

amongpeers

ReducetheTECHNICALBARRIERforsharinguseful

information

Page 35: Data-Driven Threat Intelligence: Metrics on Indicator … · 2018-05-11 · Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief

TRUST:Anonymity+GoodCuration

Somesharingcommunitiesacceptanonymoussubmissionsthattheythencurateanddisseminate

toallorganizations

Page 36: Data-Driven Threat Intelligence: Metrics on Indicator … · 2018-05-11 · Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief

IOCs

Feedback

TelemetryLESSMATURE

MOREMATURE

❤ andapologiesto@DavidJBianco

TECHNICALBARRIER:”PyramidofSharing”

Page 37: Data-Driven Threat Intelligence: Metrics on Indicator … · 2018-05-11 · Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief

Takeaways

• IntelligenceSharingisaveryanalyst-centricactivitythatwehavebeentaskedwithscalingout

• Datacanbeasgoodasapaidfeed,butyouhavetobeintherightcirclesoftrust

• Doesnotsolveanalystshortageandmakingtheindicators/strategiesoperationalintoyourenvironment

Page 38: Data-Driven Threat Intelligence: Metrics on Indicator … · 2018-05-11 · Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief

Thanks!

• Q&A?• Feedback!

”Themeasureofintelligenceistheabilitytochange."- AlbertEinstein

AlexPinto@alexcpsec

@MLSecProject

Alexandre Sieira@AlexandreSieira@NiddelCorp