bsides augusta 2015 - building a better analyst using cognitive psychology

29
Building a Better Analyst Using Cognitive Psychology Chris Sanders Bsides Augusta 2015

Upload: chrissanders88

Post on 23-Jan-2018

787 views

Category:

Technology


2 download

TRANSCRIPT

Page 1: BSides Augusta 2015 - Building a Better Analyst Using Cognitive Psychology

Building a Better AnalystUsing Cognitive Psychology

Chris SandersBsides Augusta 2015

Page 2: BSides Augusta 2015 - Building a Better Analyst Using Cognitive Psychology

Chris Sanders

• Christian• Southerner• PhD Researcher• FireEye• GSE• BBQ Pit Master

Page 3: BSides Augusta 2015 - Building a Better Analyst Using Cognitive Psychology

**Disclaimer**

I’m going to talk about matters of the brain, not just the normal tech stuff.

My research for this presentation involved consultation with psychologists.

I, however, am not one….yet.

Page 4: BSides Augusta 2015 - Building a Better Analyst Using Cognitive Psychology

Outline

Objectives: Metacognition Perception Intuition Working Memory

“How metacognitive awareness can help you make better technical decisions during security

investigations.“

Page 5: BSides Augusta 2015 - Building a Better Analyst Using Cognitive Psychology

Metacognition

• Thinking about thinking• Research shows a relationship between

metacognitive awareness and cognitive performance.

• Two Components:– Knowledge of cognition (understand it)– Regulation of cognition (apply it)

Page 6: BSides Augusta 2015 - Building a Better Analyst Using Cognitive Psychology

The Investigation

• Investigations are an attempt to determine the ground truth of what really happened.– Is there a bad guy? – What did they do?

• Investigations introduce cognitive challenges

Page 7: BSides Augusta 2015 - Building a Better Analyst Using Cognitive Psychology

Perception, Reality, and Bias

Page 8: BSides Augusta 2015 - Building a Better Analyst Using Cognitive Psychology

Perception vs. Reality

• Perception: – “A way of regarding, understanding, or

interpreting something.”

• Reality: – “The state of things as they actually exist.”

Page 9: BSides Augusta 2015 - Building a Better Analyst Using Cognitive Psychology

Our investigative path depends on mindset and biases

Page 10: BSides Augusta 2015 - Building a Better Analyst Using Cognitive Psychology

Mindsets and Blur

• Mindsets frame how we see the world

• Quick to form and resistant to change

• The initial picture we see forms our first mindset impression

• Biases applied here carry forward

Page 11: BSides Augusta 2015 - Building a Better Analyst Using Cognitive Psychology

Diminishing Initial Blur

• Provide relevant information up front• Real-istic time alerting• Formalization of triage function

– Put your expertise here– Gather info, make recommendations, pass on– Smaller orgs can use partner analysis

Page 12: BSides Augusta 2015 - Building a Better Analyst Using Cognitive Psychology

Inattentional Blindness (IB)

• Attention – Focusing on something– Overt or covert– Attention is a limited resource– Many things fight for analyst attention

• It is very easy to miss things right in front of us

Page 13: BSides Augusta 2015 - Building a Better Analyst Using Cognitive Psychology
Page 14: BSides Augusta 2015 - Building a Better Analyst Using Cognitive Psychology

Diminishing IB

• Experienced analyst are usually less suceptible• Mastery of your environment

– Mise en place

• Controlling attention– Limit extraneous info– Direct focus– Gaze tracking

Page 15: BSides Augusta 2015 - Building a Better Analyst Using Cognitive Psychology

Intuition and Memory

Page 16: BSides Augusta 2015 - Building a Better Analyst Using Cognitive Psychology

It’s a Hard SOC Life

• Investigative knowledge is tacit– Senior analysts can’t explain their success– Junior analysts can’t effectively learn

• Knowledge transfer is limited– “Watch and learn”

Analysts rely on intuition!

Page 17: BSides Augusta 2015 - Building a Better Analyst Using Cognitive Psychology

Intuition• in·tu·i·tion (noun)

– The ability to understand something immediately, without the need for conscious reasoning.

• Previously not well understood, often dismissed

“It is an illusion to expect anything from intuition.” – Sigmund Freud

Page 18: BSides Augusta 2015 - Building a Better Analyst Using Cognitive Psychology

A Biological Basis for IntuitionPrecuneus

2.1x Larger Response

TED Talk: The Rise of Augmented Intelligence: https://www.youtube.com/watch?v=mKZCa_ejbfg

Page 19: BSides Augusta 2015 - Building a Better Analyst Using Cognitive Psychology

Modeling Memory

Page 20: BSides Augusta 2015 - Building a Better Analyst Using Cognitive Psychology

Using the Visuo-Spatial Sketchpad (VSP)

• A primary component of working memory• Allows for visual manipulation of objects• Studies show that “intuition” is directly tied to

use of VSSP (via the precuneus)

Page 21: BSides Augusta 2015 - Building a Better Analyst Using Cognitive Psychology

Related VSSP Usage

“If you look deep enough you will see music” – Thomas Carlyle

Page 22: BSides Augusta 2015 - Building a Better Analyst Using Cognitive Psychology

Visually Investigating

• Draw a picture!– It’s what your brain is doing anyway– Whiteboards everywhere

• Visualize Data Appropriately– Don’t use viz for the sake of viz (geo maps )– Incident timelines– Link graphs– Identify relationships (nouns/verbs)

Page 23: BSides Augusta 2015 - Building a Better Analyst Using Cognitive Psychology

Thinking Visually - Breakfast

Page 24: BSides Augusta 2015 - Building a Better Analyst Using Cognitive Psychology

Thinking Visually - Breach

Page 25: BSides Augusta 2015 - Building a Better Analyst Using Cognitive Psychology

WM Capacity Limitations

• The capacity of WM is biologically limited• WM capacity is set from birth– Humans can remember 7 items, + or - 2. – Complexity of items matters

Hard to Remember Easy to Remember

248.232.122.193 6.5.4.3

sub29203.domain3789.com sub.domain.com

domain.com/me/?id=29381913 domain.com/path/url.htm

a39e3d50ba4aeb134d95ae7aa4d6c578

system32.dll

Page 26: BSides Augusta 2015 - Building a Better Analyst Using Cognitive Psychology

Diminishing WM Capacity Limitations

• Source Monitoring– Which IP was $suspicious_activity associated with?– Was this file downloaded by $dropper or $attacker?– Which case was $domain

• Chunking– Grouping similar information– Mapping to an existing schema

Page 27: BSides Augusta 2015 - Building a Better Analyst Using Cognitive Psychology

SchemasPicture These Items

StaplerBuffaloBookFootFlag

EggsBaconGrits

SausageCoffee

Unrelated to Schema

Related to Breakfast Schema

Page 28: BSides Augusta 2015 - Building a Better Analyst Using Cognitive Psychology

Conclusion

• The biggest hurdle to overcome when investigating security incidents is our own cognitive limitations

• Metacognition can diminish these limitations

Page 29: BSides Augusta 2015 - Building a Better Analyst Using Cognitive Psychology

Thank You!

E-Mail: [email protected]: @chrissanders88

Blog: http://www.chrissanders.orgFoundation: http://www.ruraltechfund.org