Don't Eat Spaghetti with a Spoon - An Analysis of the Practical Value of Threat Intelligence

Presented at Black Hat Europe 2018, Dec. 6, 2018, 10 a.m. (50 minutes)

Threat Intelligence is a sound proposition that has its place in a mature security operation. But like so many good concepts in our industry, its path to commercialization has involved commoditization to the point of potentially dangerous over-simplification. Intelligence is supposed to be non-obvious, actionable value-added information that is only available through some form of processing and interpretation. In truth, however, the basic premise of most commercial products is that if an entity has been observed acting maliciously in one location, then it should also be expected at other locations and prepared for. On this premise, Threat Intelligence feeds are sold at hundreds of thousands of dollars a year. Does it work? This talk will present an analysis of the ability of Threat Intelligence to predict malicious activity on the Internet. Our analysis involves the investigation of over a million Internet threat indicators over a period of six months. Notably, we've used a diverse set of sensors on real-world networks with which to track a range of malicious activities on the Internet, including port scans, web application scans, DoS & DDoS and exploits. We track the malicious IP addresses detected, looking at their behavior over time and mapping both 'horizontal' correlations - the ability of one sensor to predict activity on a different sensor, or one target to predict for another target - and 'vertical' correlations - the ability of a sensor to predict persistence or re-appearance of an IP indicator. By examining these two set of correlations we believe we can shed some light of the value proposition of basic Threat Intelligence offerings and, in doing so, improve our understanding of their place and value in our security systems and processes. All our data and modeling code will be released after this talk.

Presenters:

  • Sid Pillarisetty - Security Analyst, SecureData
    Sid Pillarisetty is passionate about anything security and enjoys talking about how security professionals can keep ahead of the cat-and-mouse game. As a security analyst at SecureData, he does this on a daily basis as he works to understand and solve problems around detection of malicious activity. In addition, he has a master's in cyber security and management from which he has learned to love doing research. This has also lead to his interest in using machine learning to detect malicious activity.<br>
  • Charl van der Walt - Founder & Chief Strategy Officer, SensePost SecureData
    Charl van der Walt is the original founder of SensePost - a pen testing company in South Africa and in the UK - where he still sits on the board. He has acted in various roles there, including CEO for about five years. After they sold SensePost to SecureData, he took a diverse role with the group that includes leading its research unit, directing security strategy, and leading the "Security Intelligence Unit," which (amongst other things) runs a significant Managed SIEM and Threat Hunting (MDR) Operation. He has spoken on a variety of occasions over the duration of his career, including Black Hat, HITB, Defcon, NATA CCDCOE, BSides, and 44Con. <br>

Links:

Similar Presentations: