Why is CTI Automation harder than it needs to be.. and what can security teams do about it.

No ratings

Presented at FirstConferenceKualaLumpur 2018 by

Threat Intelligence is well known as an important part of CERT and Incident Responders toolkit.However, sharing of intelligence across heterogeneous tools and environments that different organizations and groups (e.g. security operations vs threat research vs incident responders) use is a real challenge to the successful use and impact threat intelligence can have. When you expand those problems within a single organization to across different companies, CERTs and countries then the complexity and variability increases significantly.If you then try to drive automation using threat intelligence, such as a firewall or web gateway, in an automated manner then the problems of inconsistent data sets, inconsistent semantics and unexpected behaviors results in significant headaches for security practitioners downstream from the providers of the data.This presentation will cover some real-world problems of Threat Intelligence sharing in heterogeneous environments and provide some insights on how some of the new standards STIXv2/TAXIIv2 and OpenC2 are solving those problems for many of the use cases across a single organization and multiple organizations alike.As part of the recommendations and insights, we will present on what OASIS Cyber Threat Intelligence Interoperability program has defined, what were some of the key CERT & Incident Responder use cases that the program supports and some thoughts for future adoption of the program to future use cases of Threat Intelligence and Automation. We will also include some lessons learned from recent Interoperability plugfest. Finally, we will wrap up with key Interoperability standards aspects that CERTs and other users of Threat Intelligence should consider leveraging in their environments before making decision on threat intelligence data and tool providers.