Practical Integration of Threat Intelligence and CSIRT Processes to Accelerate Efficiency and Timely Response of Incidents: Malaysia CERT Case Study

No ratings

Presented at FirstConferenceKualaLumpur 2018 by

Past Incident Response procedures may not be comprehensive enough to address complex and sophisticated incidents. The ever-increasing scale, complexity and globalization of cyber attacks require quick detection, accurate analytics and eradication of the attacks. Hense, a more practical procedure and approach to fulfill this quest.Nonetheless, the ever-expanding volume of ICT capacity has indeed in multiple occasions, proved the need to modernize the process and workflow of CSIRT around the globe to provide a better experience of cyber incident handling in general. The presentation is also inline with the Conference Theme, whereby, after years of Incident Handling, it is time to be more innovative and effective in the way we respond to incidents.The practical integration of Threat Intelligence unto Computer Security Incident Response Team (CSIRT), can be viewed as a method to overcome certain limitations of CSIRT such as:➢ Accuracy and precision of incident detection. Large amount of data such as logs, can be hard to be processed efficiently by analysts resulting in undetected issues and complication in the particular organization.➢ Time limitation of incident detection may consequently effect immediate preventions of attacks at global level.➢ More on the passive and defensive side of IT Security. Normal CSIRT processes do not cover the scope of understanding attack vectors as well as threat actor information.To prove that the integration has worked for us, we will highlight a case study related to multiple IP addresses originating from Malaysia that belongs to a single network operator in Malaysia, that involved in several large-scale cyber attacks around the world such as data leakage, espionage, commercial fraud, web attacks and malware activities. In this case study we will show how we identified the Indicators of Compromise (IOC), Tactics, Techniques and Procedures (TTPs), and the Threat Actors and how this information helped in the investigation of this incident.The presentation is targeted for established CSIRTs, PSIRTs and also new teams. The key points that we would like to highlight in this presentation are: ➢ The important roles of CSIRTs, CERTs and PSIRTs in eradicating and mitigating large-scale cyber attacks at global level. ➢ Share our integration workflow that illustrates how Threat Intelligence is delivered in the investigation of an uincident for quick and efficient Incident Response, which in this presentation focuses on a case study of Malaysian IP addresses involved in global large-scale attacks.➢ IT security organizations should also emulate mechanism used by major corporations and institution which prioritize information and data collected to further understand their customers and to provide targeted services ➢ Share our in-house developed tools and applications that we used for the investigation of this incident.. ➢ Share the work taken by us to further study the behavioral and anatomy of an incident so as to propagate and reduce the effect of similar type of incident in the future. ➢ How CSIRTs of various countries can be in the forefront of global cyber attacks via means of Threat Intelligence. ➢ Share our tips on customizing existing tools for enhancement and improvement of the Threat Intelligence delivery for effective mitigation of global cyber attacks. ➢ If such integration can be applied in a CSIRT, a better understanding of threat actor and attack vectors can be utilized to tackle cyber security incidents efficiently and with pinpoint accuracy.