Data-Driven Threat Intelligence: Metrics on Indicator ......Data-Driven Threat Intelligence: Metrics...

50
Data - Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (# ddti ) Alex Pinto Chief Data Scientist MLSec Project / Niddel @alexcpsec @MLSecProject / Niddel

Transcript of Data-Driven Threat Intelligence: Metrics on Indicator ......Data-Driven Threat Intelligence: Metrics...

Page 1: Data-Driven Threat Intelligence: Metrics on Indicator ......Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief Data Scientist

Data-DrivenThreatIntelligence:MetricsonIndicatorDisseminationandSharing

(#ddti)

AlexPintoChiefDataScientist

MLSec Project/Niddel@alexcpsec

@MLSecProject /Niddel

Page 2: Data-Driven Threat Intelligence: Metrics on Indicator ......Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief Data Scientist

• WhatisTIgoodfor?• CombineandTIQ-test• MeasuringIndicators• ThreatIntelligenceSharing• Futureresearchdirection(i.e.willworkfordata)

Agenda

HTto@RCISCwendy

Page 3: Data-Driven Threat Intelligence: Metrics on Indicator ......Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief Data Scientist

WhatisTIgoodfor(1)Attribution

Page 4: Data-Driven Threat Intelligence: Metrics on Indicator ......Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief Data Scientist

WhatisTIgoodforanyway?

TYto@bfist forhisworkonhttp://sony.attributed.to

Page 5: Data-Driven Threat Intelligence: Metrics on Indicator ......Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief Data Scientist

WhatisTIgoodfor(2)– CyberMaps!!

TYto@hrbrmstr forhisworkonhttps://github.com/hrbrmstr/pewpew

Page 6: Data-Driven Threat Intelligence: Metrics on Indicator ......Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief Data Scientist

WhatisTIgoodforanyway?• (3)Howaboutactualdefense?• Strategicvs.tacticalvs.operational:planning• Technicalindicators:DFIRandmonitoring

Page 7: Data-Driven Threat Intelligence: Metrics on Indicator ......Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief Data Scientist

AffirmingtheConsequentFallacy

1. IfA,thenB.2. B.3. Therefore,A.

1. Evilmalwaretalksto8.8.8.8.2. Iseetrafficto8.8.8.8.3. ZOMG,APT!!!

Page 8: Data-Driven Threat Intelligence: Metrics on Indicator ......Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief Data Scientist

Thisisadata-driventalk!Pleasecheckyouranecdotesatthedoor

Page 9: Data-Driven Threat Intelligence: Metrics on Indicator ......Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief Data Scientist

CombineandTIQ-Test• Combine(https://github.com/mlsecproject/combine)• GathersTIdata(ip/host)fromInternetandlocalfiles• Normalizesthedataandenrichesit(AS/Geo/pDNS)• CanexporttoCSV,“tiq-testformat”andCRITs• h/t@kylemaxwell,@sconzo,@c0wl

• TIQ-Test(https://github.com/mlsecproject/tiq-test)• RunsstatisticalsummariesandtestsonTIfeeds• Generateschartsbasedonthetestsandsummaries• WritteninR(becauseyoushouldlearnastatlanguage)• h/t@hrbrmstr

Page 10: Data-Driven Threat Intelligence: Metrics on Indicator ......Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief Data Scientist

SuddenlyDatahttps://github.com/mlsecproject/tiq-test-Summer-2015

Page 11: Data-Driven Threat Intelligence: Metrics on Indicator ......Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief Data Scientist
Page 12: Data-Driven Threat Intelligence: Metrics on Indicator ......Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief Data Scientist

UsingTIQ-TEST– FeedsSelected• Datasetwasseparatedinto“inbound”and“outbound”

TYto@kafeine andJohnBambenek foraccesstotheirfeeds

Page 13: Data-Driven Threat Intelligence: Metrics on Indicator ......Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief Data Scientist

DataFormatforTIQ-TEST

Page 14: Data-Driven Threat Intelligence: Metrics on Indicator ......Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief Data Scientist

TonsofThreat-yTests

• NOVELTY – Howoftendothefeedsupdatethemselves?• AGING – Howlongdoesanindicatorsitonafeed?• POPULATION – Howdoesthispopulationdistributioncomparetomydata?

• OVERLAP– Howdotheindicatorscomparetotheonesyougot?

• UNIQUENESS – Howmanyindicatorsarefoundonlyononefeed?

Puttingthisthreatdatatowork

Page 15: Data-Driven Threat Intelligence: Metrics on Indicator ......Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief Data Scientist

TonsofThreat-yTests

• NOVELTY – Howoftendothefeedsupdatethemselves?• AGING – Howlongdoesanindicatorsitonafeed?• POPULATION – Howdoesthispopulationdistributioncomparetomydata?

• OVERLAP– Howdotheindicatorscomparetotheonesyougot?

• UNIQUENESS – Howmanyindicatorsarefoundonlyononefeed?

Puttingthisthreatdatatowork

Page 16: Data-Driven Threat Intelligence: Metrics on Indicator ......Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief Data Scientist

OverlapTestMoredataisfine,butmakesure

itisdifferent

Page 17: Data-Driven Threat Intelligence: Metrics on Indicator ......Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief Data Scientist

OverlapTest- Inbound

Page 18: Data-Driven Threat Intelligence: Metrics on Indicator ......Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief Data Scientist

OverlapTest- Outbound

Page 19: Data-Driven Threat Intelligence: Metrics on Indicator ......Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief Data Scientist

UniquenessTestHowmanyfishREALLYarethereatthesea?

Page 20: Data-Driven Threat Intelligence: Metrics on Indicator ......Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief Data Scientist
Page 21: Data-Driven Threat Intelligence: Metrics on Indicator ......Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief Data Scientist
Page 22: Data-Driven Threat Intelligence: Metrics on Indicator ......Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief Data Scientist

Ihatequotingmyself,but…

Page 23: Data-Driven Threat Intelligence: Metrics on Indicator ......Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief Data Scientist

KeyTakeaway#1

MORE!=BETTERThreatIntelligenceIndicatorFeeds

ThreatIntelligenceProgram

Page 24: Data-Driven Threat Intelligence: Metrics on Indicator ......Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief Data Scientist
Page 25: Data-Driven Threat Intelligence: Metrics on Indicator ......Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief Data Scientist

“TISharingisTOTALLYgoingtosolvethis”

Right,people?Right?

Page 26: Data-Driven Threat Intelligence: Metrics on Indicator ......Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief Data Scientist

HerdImmunity,isit?

Source:www.vaccines.gov

Page 27: Data-Driven Threat Intelligence: Metrics on Indicator ......Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief Data Scientist
Page 28: Data-Driven Threat Intelligence: Metrics on Indicator ......Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief Data Scientist
Page 29: Data-Driven Threat Intelligence: Metrics on Indicator ......Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief Data Scientist

ThreatIntelligenceSharingWewouldliketothankthekindcontributionofdatafromthefinefolksatFacebookThreatExchangeandThreatConnect…

…andalsothesharingcommunitiesthatchosetoremainanonymous.Youknowwhoyouare,andwe❤ youtoo.

Page 30: Data-Driven Threat Intelligence: Metrics on Indicator ......Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief Data Scientist

ThreatIntelligenceSharing– Data

Fromaperiodof2015-03-01to2015-05-31:- NumberofIndicatorsShared

§ Perday§ Permember

Notsharingthisdata– privacyconcernsforthemembersandcommunities

Page 31: Data-Driven Threat Intelligence: Metrics on Indicator ......Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief Data Scientist

OVERLAPSLIDE

Page 32: Data-Driven Threat Intelligence: Metrics on Indicator ......Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief Data Scientist

OVERLAPSLIDE

Page 33: Data-Driven Threat Intelligence: Metrics on Indicator ......Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief Data Scientist

UNIQUENESSSLIDE

Page 34: Data-Driven Threat Intelligence: Metrics on Indicator ......Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief Data Scientist

TheCognitiveDissonancesofTISharing

Everybody shouldshare! TheCIRCLEOFTRUST

Page 35: Data-Driven Threat Intelligence: Metrics on Indicator ......Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief Data Scientist

Whatdoyoushare?

Whatdoyouconsume?

TheTwoSidesofTrust

Page 36: Data-Driven Threat Intelligence: Metrics on Indicator ......Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief Data Scientist

ActivityTestIsthereanyactualsharinggoing

on?

Page 37: Data-Driven Threat Intelligence: Metrics on Indicator ......Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief Data Scientist

Updatefrequencychart

High10saverage Low100saverage

Large– 10.000smembers Small– High10smembers

Page 38: Data-Driven Threat Intelligence: Metrics on Indicator ......Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief Data Scientist

DiversityTestCheckyoursharingprivilege

Page 39: Data-Driven Threat Intelligence: Metrics on Indicator ......Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief Data Scientist
Page 40: Data-Driven Threat Intelligence: Metrics on Indicator ......Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief Data Scientist
Page 41: Data-Driven Threat Intelligence: Metrics on Indicator ......Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief Data Scientist

RecallTestButisthedataanygood?

Page 42: Data-Driven Threat Intelligence: Metrics on Indicator ......Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief Data Scientist
Page 43: Data-Driven Threat Intelligence: Metrics on Indicator ......Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief Data Scientist

Whatdoesgoodcurationlookslike?

Page 44: Data-Driven Threat Intelligence: Metrics on Indicator ......Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief Data Scientist

KarmaandAnonymity

Page 45: Data-Driven Threat Intelligence: Metrics on Indicator ......Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief Data Scientist
Page 46: Data-Driven Threat Intelligence: Metrics on Indicator ......Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief Data Scientist

KeyTakeaway#1

'Howcansharingmakemebetterunderstandwhatare

attacksthat“aretargeted”andwhatare“commodity”?'

Page 47: Data-Driven Threat Intelligence: Metrics on Indicator ......Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief Data Scientist

Telemetry>AnalysisNoteveryoneshouldneedtoknowhowtohunttomakeameaningfulcontribution

Page 48: Data-Driven Threat Intelligence: Metrics on Indicator ......Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief Data Scientist

MoreTakeaways

• Analyzeyourdata.Extractmorevaluefromit!• IfyouABSOLUTELYHAVETObuyThreatIntelligenceordata,evaluateitfirst.

• Trythesampledata,replicatetheexperiments:• https://github.com/mlsecproject/tiq-test-Summer2015• http://rpubs.com/alexcpsec/tiq-test-Summer2015

• Sharedatawithus.I’llmakesureitgetsproperexercise!

Page 49: Data-Driven Threat Intelligence: Metrics on Indicator ......Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief Data Scientist
Page 50: Data-Driven Threat Intelligence: Metrics on Indicator ......Data-Driven Threat Intelligence: Metrics on Indicator Dissemination and Sharing (#ddti) Alex Pinto Chief Data Scientist

Thanks!

• Q&A?• Feedback!

”Themeasureofintelligenceistheabilitytochange."- AlbertEinstein

AlexPinto@alexcpsec

@MLSecProject /@NiddelCorp