4 hours 42 minutes
Hello and welcome to the second module data processing. This is the second video about common standards used in cyber threat intelligence.
Let me start. It's introducing data standard. So basically a data standards defines how practical or information elements are represented and fines or in communications.
The EU's off common standards is important for exchange off any information
and cyber threat Intelligence, particularly standards, were created to represent actionable information, including their contacts to facilitate their storage. And Scherick,
using a standard format, has mainly three advantages over using at hawk representations.
First, the use off existent processing tools, both to support the standard.
Second, the interpretation off the description should be less subject to misinterpretation because the standard defines of the semantics for information elements
and, third, the ease off sharing and integration.
And this lesson we will discover together
different standards. Use it for cyber threat intelligence. We will start with scoring standards. Then we'll see thread description or taxonomy standards and finally will close with transport senders or particles. One off the most known scoring systems is CVS s
CVS says distance for common vulnerability scoring system and is currently maintained by the form off incident response and security teams first. The current version off, CVS says, is version 3.1
and was released in June 2090.
CVS s measures three areas off concerts, bays, metrics, temporal metrics and environmental metrics. The base core has the most significant influence all the final score. The based group represents the intrinsic qualities off of vulnerability.
The temporal group reflects the characteristics off of vulnerability that change over the time,
and the environmental group represents the correct the characteristics off vulnerability that are unique to users. Environment scores range from 0 to 10 where tanker response to the most critical vulnerability.
A CVS test score is also represented as a vector string. A compressive textile representation. Off values use it to the arrives. The score.
The numerical score can also be translated into a qualitative representation in such low, medium high and critical. As an example, I took the recently discovered vulnerability called Blue Keep or CV 2019 0708
This is a remote code, execution or air see vulnerability in remote desktop protocol Rdp, where an unauthenticated removed attacker can exploit the flow via Siri's off, especially crafted requests to execute arbitrary coat
I hear the vector string
off CBSS 3.1 is attack Vector is network at that. Complexity is low privileges record non user interactions, non scope and changed confidentiality, high integrity, high and availability. Hi!
And the score here is 9.8, which is critical. If we choose to add a temporal or in very mental metric, the score will change.
The second type off standards is thread description or taxonomy. Standers. The motivations for developing taxonomy standards. Waas to find a common language to describe malware infections and all their cyber events
here. We're going to start with the first standards, which is open IOC so open. IOC stands for open indicators off compromise and was introduced by Manion into 2000 and 11. It is used in many in products but has also Bean released as an open standard.
Open, you see
provides a standard format and terms for describing the artifacts encountered during course. Often investigation open IOC is focused on describe and technical characteristics off threat. Through an Extensible XML schema. You can produce or edit
open fire, see files
using the tools provided by fire. These tools can be used for free
hair is an example off threat representation Using open IOC standard.
This example can be found on Forget her purpose it Terry mentioned on the slide and viewed using the tool I see editor mentioned other previous slide or through with all line website are you see back a dot com.
The next thundered from the same category is Sai box
Cyber observable expression or side box is standardized language for representing observable ZX. It was introduced by miter on 2000 and 12 and now maintained by always is now Cy Box has been integrated into sticks to standard side box is used for the finding details
regard unmeasurable events and state ful properties.
The object that can be defined in Sai box can be used in higher level schema like sticks.
Harry's a basic example of side box representation off i p address object. The second standard from the same category is sticks,
sticks, tents for stretcher threat information expression and it is stretchered language for describing cyber threat information so it can be shared, stored and analyzed in a consistent manner. Sticks
is also introduced by miter and now maintained by Oasis. The current version off sticks is 2.0. It uses Jeez on schema for the second version.
The structure of nature off sticks architecture allows it to define relationship between constructs. For example, a campaign can be attributed to a threat. Actor
As I tried several tools dedicated to threat intelligence and some solutions. Sticks is being widely accepted by industry leaders. Sticks to defines 12 sticks domain objects,
sticks objects, categorize each piece of information with specific attributes to be populated,
training multiple objects together through relationships, although for easy or complex representations. Off threat intelligence sticks to domain objects include campaign course of action, identity, Muller, Threat, actor, tool, vulnerability and others.
Sticks to also defines
two sticks relationship or rejects.
The first is a relationship on the Second is citing. Here is a basic example off sticks representation where the first sticks domain object is threat. Actor on the second sticks domain object is identity and varies
sticks relationship object. Linking the first
domain object to the second domain object, which is a relationship