Practical method and practice of OSINT for cyber defense

No ratings

Presented at CODEBLUE2018@TOKYO 2018 by

In this talk, I will explain standard method of OSINT (Open Source Intelligence), practical OSINT method learned from my CSIRT tasks, and examples of OSINT. This talk will be intended primarily for infosec staff and CSIRT members of the organization.To avoid or reduce the damage by cyberattack, it is necessary that understanding rapidly and accurately the situation of cyberattack and vulnerability that may affect the organization. However, when we investigate cyberattacks and malwares only observed at the organization, we cannot understand the big picture. There are many cases that cyberattacks against other regions, industries, and organizations later attack the organization.Therefore, it is necessary to gather and use various kinds of information such as occurrences of cyberattacks, information about vulnerabilities, and trends of attackers. This activity is called OSINT and getting attention in cyber security.However, information about cyber security is wide-ranging and huge. Furthermore, the reliability of the information is also diverse. These problems may cause failures such as failing to find necessary information, or failing to handle the incident due to inaccurate information. In this talk, I will present how to avoid these problems and practical OSINT method for cyber defense.