3.1 Intelligence-Driven Security and CTI Lifecycle
Join over 3 million cybersecurity professionals advancing their career
Sign up with
Required fields are marked with an *
Already have an account? Sign In »
4 hours 30 minutes
Hey, guys, welcome back to introduction to Savor Trades Intelligence. Today we're gonna be reviewing one of the most recent cyber security strategy for organizations, and that is the intelligence driven security.
This is the first off a series of three parts to cover this topic
with no forger introduction. Let's get right into it.
The classic book, Really, By Sun two. It's an awesome example of what intelligence is.
Every battle is won before it's ever fought.
The work of preparation, the knowledge, this strategy, everything previous to a battle is what actually counts on the field saver dressing. Jillian's is exactly that.
Nonetheless, there are a lot of misconceptions for main implementations, where cyber tracked intelligence is not well implemented and falls down into a not so productive practices and then actually makes this stuff a lot harder for organizations.
Some misconceptions are several trades. Intelligence is that is just that. If it's and pdf reports, when this is the core purpose of the city, I unit organizations often fall down to a whole larger trouble because it just means there's more information available without the right context for the organization
that result in more manual work When an incident happens as we will see in the models ahead.
Another misconception. It's that it is a research service for the Indian response teams. Disbelief somehow is more counterproductive. Since the cyber threat, intelligence analysts become just an extension off the incident response team
without adding this so needed value when attending an incident.
And last, it requires a dedicated team off a high priced elite analyst. This misconception.
It's why some organization just dropped out of having a dedicated server Trident Aliens unit when the threat is far from that,
as we're going to see in the following videos
Now, to counter these beliefs, we can state what cyber trade intelligence really is.
Save it credit intelligence you say you need. That includes information and analysis from a reach a rail sources presented in a way that it's easy to understand and use, causing a more efficient approach when managing the cyber security realm.
It is valuable for all the major teams in the cyber security organization, and that's why, in this curse we will be reviewing how every unit in this area will benefit for the presents off a cyber tracked intelligence team
and last but not least December trade. Intelligent processes can be handled and execute Lee mostly by the existing security staff, and there is no must requirement that needs to be in place. Rate is rated as a high price
justice. Most off working unit in an organization, Cyber Direct Intelligence counts with a specific life cycle. The intelligence cycle is defined by recorded future as direction collection,
processing analyses, dissemination on feedback.
This is how the classic flow of cyber credit intelligence goes. Most of the time.
This flow insures that the cyber threat intelligence activities are aligned with the organization subjective and can provide information with the require meanings.
This cycle allows all organizations to follow specific orders in its task at people. Several credit intelligence objectives allying with the organization's ones and in constant improvement,
which is one of the most important aspect that need to be taking into account in order to maintain cyber tread intelligence. Effective
most of the time, I find that graphic representation of concepts are a big difference, you know, difference trader when understanding a topic.
So hey, we're here. We have a sort of graphic flow of the cyber threat intelligence life cycle created by recorder future.
If you can notice in the upper left corner of the graphic, we have the direction face.
This represents the first step to take in a cyber threat intelligence life cycle and one of the most importance because they spark, although doesn't take much part of the graphic, it's key to review that all the subsequent social activities are lying to the organizations of deck ticks. Next,
we can find a trance versatile section where the first part to take into account our just sources off worthy information is obtained. This is a very important process, since the right surfaces are lying with the organization's objectives. Will provide us ever treat Intelligence Department the necessary information to get the most out of the next
in the middle part of a graph. We have the actual cyber tracked intelligence's manpower. Here's where all the magic magic takes place. The processes of collection processing, another analysis and dissemination Sze are in charge of the cyber tracked Italians unique through its security tools and its analysts.
Lastly, the output of this face will go directly to each one of the department's They're getting benefits from the cyber tracked intelligent analysis on after the intelligence has been used. Ah, feedback is provided. So the cyber tragic millions unit no see what they are providing to these units is actually what they want to get.
Okay, now that we had a general look of the whole process, let's dive into each one of them.
The first part off Cyber tracked Intelligence Life cycle is related to the direction off almost all of its activities. This means the pattern to savor trenchant aliens unit. Most maintain, according to the organization's unit,
this face takes care of defining the goals for the Cyber Threat Intelligence program. It also validates that these girls are like with the organization goals, and this involves the information, assets and business processes that need to be protected.
The potential impacts of losing those assets are interrupting does processes
the types of threat intelligence that the security organization requires to protect assets and respond to threats
and priorities about what to protect.
So basically, this first part of the cycle will focus on defining the cyber trade, intelligent purposes. What are we trying to accomplish?
What is the organization going to use the intelligence for and what units will be using the intelligence collected and so on. And so fort, because the activities of the cyber threat intelligence are directly aimed to the resources available in the organization, is important to the fine. What
assets are going to be benefit since the beginning?
Because when a cyber threat intelligence unit is starting, its capabilities are going to be limited to what the researchers are able to do. And most likely, they won't be able to meet everyone's demands if they're too many. Next, we have the collection face, As we pointed out before the collection, Face will be in charge of obtaining
available through their different sources.
Let's start by getting the actual definition of these face record. A future in its Threat Intelligence Handbook defines collection as a process of gathering information to address the most important intelligence requirements. This would take into account the purpose of this information. Once it reaches its destination,
information gathering can occur organically. Travel relative means this includes pulling metadata, unlocks from internal networks and security devices such as fire wolves, creatures and routers, subscribing to threat feet from industry organizations and say We're security benders
holding conversations and targeted interviews with no little Nolan. Knowledgeable sources.
This item will occur on the man most of the time. Sit, sit involves very specific information to be obtained.
Also it includes is canning up in search, kneels and blocks and is crabbing and Harper Stein in harvesting website firms also infiltrating close stars such as dark Web forums.
Well, all right. This video gave a very wide view of the cyber threat intelligence life cycle, and it started to poke around information sources. Right now, we have gone through the 1st 2 faced vices off the lifecycle direction and collection.
With this new polish, we have a better understanding on how the life cycle of stars
and how it must be a lang with organizations objective in order to pull that provide the intelligence needed.
With that knowledge, we're going to open a parent. This is here and head over to the information searches. This topic is crucial since desserts off the information that your cigarette dreading telling is will be analyzing should be trust and specific,
and if in any case it is not well, they had to be some additional procedures to involve in the analysis face in order to make this information trusted.
Among the certain The searches we will be discussing. We will find technical sources Such a Strat feats like domains. Hi. Bees, hatches, etcetera
Media, all the news about new threats, threat threat actors and anything that enters to our unit Social media This one will be very important to have seen. It is like really life feats of threats and actions that are happening around the world. The challenge here is that these information needs to be normalized.
See, most of the time it comes in a narrative way to be understood that humans,
but not the best, be paired two systems
protective firms. These are the forms to most off the time Attackers go to when having trouble with my hour with evading on anti virus or that sort of issues. This don't need to be heating in the dark web. They can be opening plain sight informs, like Reddit or similar
and last but not least, the gold mine, the dark, where this is one of the most important searches of information. But it is the one that consumes the most time and resources since the good information is really privilege among their users.
And there we have it. I hope this video has really hide you up in order to prove
paired to observe the ope common videos.
Okay, Goodbye. And I hope you have a nice day.