sans cti summit 2016 - data-driven threat intelligence: sharing

51
Data - Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (# ddti ) Alex Pinto Chief Data Scientist MLSec Project / Niddel @alexcpsec @MLSecProject @NiddelCorp

Upload: alex-pinto

Post on 13-Apr-2017

2.368 views

Category:

Data & Analytics


1 download

TRANSCRIPT

Page 1: SANS CTI Summit 2016 - Data-Driven Threat Intelligence: Sharing

Data-DrivenThreatIntelligence:MetricsonIndicatorDisseminationandSharing

(#ddti)

AlexPintoChiefDataScientist

MLSec Project/Niddel@alexcpsec

@MLSecProject @NiddelCorp

Page 2: SANS CTI Summit 2016 - Data-Driven Threat Intelligence: Sharing

• Previouslyon#ddti• ChallengesatTISharing• MeasuringTISharing• TheFutureofSharing

Agenda

Page 3: SANS CTI Summit 2016 - Data-Driven Threat Intelligence: Sharing

Thisisadata-driventalk!Pleasecheckyouranecdotesatthedoor

Page 4: SANS CTI Summit 2016 - Data-Driven Threat Intelligence: Sharing
Page 5: SANS CTI Summit 2016 - Data-Driven Threat Intelligence: Sharing

Previouslyon#ddti• UsefulMethodsandMeasurementsforHandlingIndicators• AnalysisofThreatIntelligenceFeeds• Indirectly,amethodologyforanalyzingTIProviders

• Combine(https://github.com/mlsecproject/combine)• GathersTIdata(ip/host)fromInternetandlocalfiles

• TIQ-Test(https://github.com/mlsecproject/tiq-test)• RunsstatisticalsummariesandtestsonTIfeeds

Page 6: SANS CTI Summit 2016 - Data-Driven Threat Intelligence: Sharing

TIQ-TEST- TonsofThreat-yTests

• NOVELTY – Howoftendothefeedsupdatethemselves?• AGING – Howlongdoesanindicatorsitonafeed?• POPULATION – Howdoesthispopulationdistributioncomparetomydata?

• OVERLAP– Howdotheindicatorscomparetotheonesyougot?

• UNIQUENESS – Howmanyindicatorsarefoundonlyononefeed?

Puttingthisthreatinteldatatowork

Page 7: SANS CTI Summit 2016 - Data-Driven Threat Intelligence: Sharing

OverlapTestMoredataisfine,butmakesure

itisdifferent

Page 8: SANS CTI Summit 2016 - Data-Driven Threat Intelligence: Sharing

OverlapTest- Outbound

Page 9: SANS CTI Summit 2016 - Data-Driven Threat Intelligence: Sharing

UniquenessTestCanwetellifweareclosetofinding*all*thethreats?

Page 10: SANS CTI Summit 2016 - Data-Driven Threat Intelligence: Sharing
Page 11: SANS CTI Summit 2016 - Data-Driven Threat Intelligence: Sharing

Ihatequotingmyself,but…

Page 12: SANS CTI Summit 2016 - Data-Driven Threat Intelligence: Sharing

KeyTakeaway#1

MORE!=BETTERThreatIntelligenceIndicatorFeeds

ThreatIntelligenceProgram

Page 13: SANS CTI Summit 2016 - Data-Driven Threat Intelligence: Sharing

ConstructiveFeedbackfromtheInternet:

“TISharingisTOTALLYgoingtosolvethis”

Right,folks?Right?

Page 14: SANS CTI Summit 2016 - Data-Driven Threat Intelligence: Sharing

TISharingSolutionPlan:

1. ThebestThreatIntelligenceistheonethatyouanalyzefromyourownincidents(homegrown/organicintelligence)

2. Thereisstrengthinnumbers– verticalherdimmunity!

3. ????????

4. PROFIT!!(oratleastSECURITY!!)

Oratleastaroughstrawman

Page 15: SANS CTI Summit 2016 - Data-Driven Threat Intelligence: Sharing

IfCONSUMINGisforthe1%,whatisthepercentageoforganizationsabletoPRODUCE?

Issue1- BYOTI

Page 16: SANS CTI Summit 2016 - Data-Driven Threat Intelligence: Sharing

Issue2- HerdImmunity

Source:www.vaccines.gov

• Wemaybeabletodetectmore”virusstrains”togetherbutweare*terrible*atinoculation.

• Thethingswedetectthemostmutatetoofast(PyramidofPain)

• Whodidn’tgetimmunized,stillgetssick(FOMO-TI)

Page 17: SANS CTI Summit 2016 - Data-Driven Threat Intelligence: Sharing

Issue?- Whatarewesharing• AUTOMATION-DRIVEN(PLATFORMS)• StraighttothepointIOCsharing

• ANALYST-DRIVEN(COMMUNITIES)• Strategicdata,bestpractices,unstructuredIOCs

• ”Analyst-driven”hasbeenaroundforever(innon-IC,atleastsinceFS-ISACwascreated)

• Thesamepeoplewhobash”justIOCsharing”:• BashSTIX/TAXIIfortryingtoencodecomplexity• TellseveryoneitisIMPOSSIBLEtohireanalysts

Page 18: SANS CTI Summit 2016 - Data-Driven Threat Intelligence: Sharing

TheCognitiveDissonancesofTISharing

Everybody shouldshare! TheCIRCLEOFTRUST

Page 19: SANS CTI Summit 2016 - Data-Driven Threat Intelligence: Sharing

Doyoutrustthegroupenoughtoconsume?

TheTwoSidesoftheTrustCoin

Doyoutrustthegroupenoughtoshare?

Page 20: SANS CTI Summit 2016 - Data-Driven Threat Intelligence: Sharing

Okay,I’llbite

Canwemeasureourcurrentsharingplatformscommunities?

Page 21: SANS CTI Summit 2016 - Data-Driven Threat Intelligence: Sharing

ThreatIntelligenceSharingWewouldliketothankthekindcontributionofdatafromthefinefolksatFacebookThreatExchange andThreatConnect

…andalsothesharingcommunitiesthatchosetoremainanonymous.Youknowwhoyouare,andwe❤ youtoo.

Page 22: SANS CTI Summit 2016 - Data-Driven Threat Intelligence: Sharing

SharingCommunitiesARESocialNetworks

SocialNetworkSelfie SharingCommunitySelfie

Page 23: SANS CTI Summit 2016 - Data-Driven Threat Intelligence: Sharing

Let’slookattheindicatorsfirst

UsingTIQ-TESTOverlapandUniquenesstests

Page 24: SANS CTI Summit 2016 - Data-Driven Threat Intelligence: Sharing

OVERLAPSLIDE

Page 25: SANS CTI Summit 2016 - Data-Driven Threat Intelligence: Sharing

OVERLAPSLIDE

Page 26: SANS CTI Summit 2016 - Data-Driven Threat Intelligence: Sharing

UNIQUENESSSLIDE

Lookslikewewouldgetsimilarqualityona”good”ThreatIntelligenceSharingPlatformaswewouldon

a”paidfeed"

Page 27: SANS CTI Summit 2016 - Data-Driven Threat Intelligence: Sharing

SuggestedMetricsforSharing

• ACTIVITY – Howmanyindicators/postsarebeingshareddaybyday?

• DIVERSITY –Whatisthepercentageofthepopulationthatisactivelysharing?

• FEEDBACK – Areorgscollaboratingonimprovingtheknowledgeinthesharingenvironment?

• TRUST– Howmuchdataisshared”openly”inrelationto”privately”?

Lookingforhealthydynamics

Page 28: SANS CTI Summit 2016 - Data-Driven Threat Intelligence: Sharing

ActivityMetricIsthereanyactualsharinggoing

on?

Page 29: SANS CTI Summit 2016 - Data-Driven Threat Intelligence: Sharing

Lessdata/Delays Moredata/Timely

LargeGroupisroughly40xbiggerthanSmallGroup

Page 30: SANS CTI Summit 2016 - Data-Driven Threat Intelligence: Sharing

Organizationsarelesslikelytoshareiftheyperceivethey”lostcontrol”ofwhocanconsume.

Page 31: SANS CTI Summit 2016 - Data-Driven Threat Intelligence: Sharing

DiversityMetricCheckyoursharingprivilege

Page 32: SANS CTI Summit 2016 - Data-Driven Threat Intelligence: Sharing

Roughly10%oftheorganizationssharedataintothecommunity

Page 33: SANS CTI Summit 2016 - Data-Driven Threat Intelligence: Sharing

Someorganizationsareclearlyinabetterpositionoperationallyandlegallytoshare.Andthatis

expectedduetoourpremises.

Page 34: SANS CTI Summit 2016 - Data-Driven Threat Intelligence: Sharing

FeedbackMetricButisthedataanygood?

Page 35: SANS CTI Summit 2016 - Data-Driven Threat Intelligence: Sharing
Page 36: SANS CTI Summit 2016 - Data-Driven Threat Intelligence: Sharing

🙀 I’msurewecandobetterthanthis🙀

Page 37: SANS CTI Summit 2016 - Data-Driven Threat Intelligence: Sharing

FeedbackMetric• Almostnosupportonautomation-drivenplatforms• Someallowyoutoleave”comments”or”newdescriptors”fortheIOCs– evenbycountingthoseverylow%inrelationtonewshareddata

• Analyst-drivenenvironmentsallowforcollaborationone-mailsandforumpoststodescribeandrefinestrategiesandbestpractices.

Howcanwemakethiscollaborationworkonautomation-drivenplatforms?

Page 38: SANS CTI Summit 2016 - Data-Driven Threat Intelligence: Sharing

TrustMetricArewehelpingallthecommunity

orjustafeworgsatatime?

Page 39: SANS CTI Summit 2016 - Data-Driven Threat Intelligence: Sharing
Page 40: SANS CTI Summit 2016 - Data-Driven Threat Intelligence: Sharing

76%.Again,soundsaboutright

Page 41: SANS CTI Summit 2016 - Data-Driven Threat Intelligence: Sharing

Overall”quality”ofdatagoesuptoo!

Page 42: SANS CTI Summit 2016 - Data-Driven Threat Intelligence: Sharing

TrustMetric• Theroughestimateseemstobethatmorethan60%of”sharing”(IOCs,messages,etc)happensin”privategroups”insidetheinfrastructureofthesharingplatform

• Allcommunitieshavethem:• PartoftheDNAoftheIC/clearedcommunity• Offsetsthetrustequation,butdefeatsthe”herdimmunity”argument• UsuallyMANDATORYoncollaborationwithLEA

Butthenthe”good”dataisnothelping”thecommunity”!Isthereanywaywecanreconcile?

Page 43: SANS CTI Summit 2016 - Data-Driven Threat Intelligence: Sharing

TheFutureofSharing🔮Attheveryleastmyhumble

opinion

Page 44: SANS CTI Summit 2016 - Data-Driven Threat Intelligence: Sharing

#squadgoalsIncreasetheTRUST

amongpeers

ReducetheTECHNICALBARRIERforsharinguseful

information

Page 45: SANS CTI Summit 2016 - Data-Driven Threat Intelligence: Sharing

TRUST:ReputationandAnonymity

Page 46: SANS CTI Summit 2016 - Data-Driven Threat Intelligence: Sharing

AlienVault OTXclearlygotthememo

Page 47: SANS CTI Summit 2016 - Data-Driven Threat Intelligence: Sharing

TRUST:Anonymity+GoodCuration

Somesharingcommunitiesacceptanonymoussubmissionsthattheythencurateanddisseminate

toallorganizations

Page 48: SANS CTI Summit 2016 - Data-Driven Threat Intelligence: Sharing

IOCs

Feedback

TelemetryLESSMATURE

MOREMATURE

With❤ andapologiesto@DavidJBianco

TECHNICALBARRIER:”PyramidofSharing”

Page 49: SANS CTI Summit 2016 - Data-Driven Threat Intelligence: Sharing

Takeaways• IntelligenceSharingisaveryanalyst-centricactivitythatwehavebeentaskedwithscalingoutwithautomation.Nowonderitseemssohard.

• Datacanbeasgoodasapaidfeed,butyouhavetobeintherightcirclesoftrust

• Doesnotsolveanalystshortageandmakingtheindicators/strategiesoperationalintoyourenvironment

Page 50: SANS CTI Summit 2016 - Data-Driven Threat Intelligence: Sharing
Page 51: SANS CTI Summit 2016 - Data-Driven Threat Intelligence: Sharing

Thanks!

• Q&A?• Feedback!

”Themeasureofintelligenceistheabilitytochange."- AlbertEinstein

AlexPinto@alexcpsec

@MLSecProject /@NiddelCorp