Improving Threat Intelligence Platform and Information Sharing by Measuring Real-Time Collaboration in TIP like MISP

No ratings

Presented at FirstConferenceKualaLumpur 2018 by

Information sharing about threats among the community has been demonstrated to be essential in incident response. CERT and CSIRT operators can use the shared information to investigate or prevent attacks or threats against ICT infrastructures, organisations or people.The MISP threat sharing platform is a free and open source software helping information sharing of threat intelligence including cyber security indicators. More than 7000 organisations worldwide are using it to share with, but also to receive from others.Leveraging the publish-subscribe model of one or more MISP instances, an open source dashboard 'MISP-Dashboard' (https://github.com/MISP/misp-dashboard) has been built, allowing to show live data, action and trends that occurs in one or more MISP platform(s). In addition to this, the can be refined and pushed back to the platform.In this the first part of the talk, we propose an overview of 'MISP-Dashboard' by showing use-cases and an example of how information can be refined and pushed back to the community. To illustrate the latter point, historical geolocalised information and how they can support security teams finding threats in their constituency will be presented.In the second part, we will show about an initial implementation to passively add confidence-level to contributions, create incentives to share data and promote collaboration; consisting in a gamification of the MISP Threat Sharing Platform. Attendee will be invited to discuss and give opinions about the model. The FIRST community provides a ground on how to measure collaboration in the field of information security. The objective of the talk is to discuss with the members about the opportunities to drive more collaboration in automated systems like MISP or similar tools.