Know Thy Enemy: The Taxonomies That Meta Uses to Map the Offensive Privacy Space

No ratings

Presented at BlackHat USA 2023 by

This talk introduces and examines privacy-inclusive taxonomies Meta has developed and uses to track privacy weaknesses, enumerate privacy adversarial TTPs, deconflict privacy and security efforts, and scale detection and remediation efforts. Taxonomies, such as MITRE's CVE, CAPEC, and ATT&CK® frameworks, have long been used to track and understand cybersecurity weaknesses and the tactics of cyber adversaries. These taxonomies help organizations stay abreast of trends, guide software development best practices, and pinpoint the most effective remediation and detection strategies to common cybersecurity issues. As the field of offensive privacy matures, organizations require similar taxonomies to understand privacy threats and align efforts across security and privacy teams. We will explore how the fundamentals of these systems may be applied to other organizations and detail challenges we encountered in the development of these taxonomies as well as the rationale behind decisions we made to shape them. We will demonstrate how an organization can proactively identify and understand their privacy adversaries through the Privacy Adversarial Framework (PAF). PAF helps deconstruct adversary TTPs in incident response, tailors data-driven red team operations, and tracks adversary trends across your organization while using familiar security tooling.After that, we will unveil a more expansive manner of thinking about vulnerabilities to be more inclusive of certain classes of issues traditionally thought of as "not security" through a comparison of the distinctions and overlap of privacy and security weaknesses. We will cover how these considerations formed the basis for the Meta Weakness Enumeration and how we use it to categorize privacy and security incidents at Meta. Last, we release resources that can help other organizations incorporate more privacy-inclusive taxonomies into their work streams and improve their understanding of the privacy threats and weaknesses to which they are exposed.