What’s in a Name? The Need for Global Identifiers of Badness.

No ratings

Presented at FirstConferenceKualaLumpur 2018 by

A recurring theme in the threat analysis community is the need for more “context” surrounding the threat intelligence they consume - cyber threat intelligence lacking context is often described as “not actionable”. The term “context” can refer to many things, from lower-level technical context such as the time window that an indicator is considered valid all the way up to attribution of a threat to a particular named threat actor. Contextual information allows the consumer of the threat intelligence to better understand the threat including its relevance to their organization, the level of risk posed by the threat and potentially how to detect and/or prevent a threat. Context is most useful however, when we are all talking about the same things. Today there are few widely-used sources of freely-available “ground truth” with respect to cyber threats.MITRE’s ATT&CK™ repository is openly-accessible and contains machine-readable STIX™ 2 definitions of well-known contextual information including adversary tactics and techniques, threat actor groups, campaigns and malware families. The goal of the repository is to enable publishers and consumers of threat intelligence to leverage well-known and stable identifiers for these important pieces of contextual information for improved correlation, pivoting and automation. To encourage use of the repository, we are providing a web user interface, a TAXII™ interface and a RESTful API to access repository content. The goal of this work is to provide a rich set of contextual information to enable a variety of use-cases including blue & red-teaming, security posture assessments, adversary emulation and analytic development.This presentation will explore the need for and use of stable, well-known identifiers for key contextual elements and then give a technical overview of the ATT&CK repository, its architecture and the process used to curate and evolve content over time. Specific examples of how to use the repository to enhance and automate aspects of threat intelligence analysis will be discussed.