Cyber Threat Intelligence for Proactive Defense
About 2 min read
Threat intelligence is the activity of systematically collecting and analyzing information about cyberattacks and applying it to an organization's defenses. By feeding IoCs (Indicators of Compromise), such as attacker tactics (TTP: Tactics, Techniques, and Procedures), malware hash values, and malicious IP addresses, into a SIEM or firewall, known threats can be blocked automatically. Because attackers frequently discard and rotate their C2 servers and phishing sites, the value of threat information depends on its freshness - which is why operations favor continuously ingesting it in machine-readable formats over manual updates.
How Long an Indicator Stays Valid
Reflecting received information in defensive settings has a reverse side: when to withdraw it after it has been applied. Information indicating the destinations or origins used in an attack is largely of a kind the attacking side can swap out at short intervals. Once it has been swapped, the entry that was registered loses its power to stop the attack. What remains is one more line in the blocking list. These resources are also reused. A destination that was being used in an attack at one point can later be assigned to an unrelated user. If registrations pile up with no decision to withdraw them, a state arises in which what is being stopped is not the attack but legitimate traffic. Such an error is unlikely to be reported, because the blocked party cannot tell why the communication fails, while from the blocking side nothing appears to be happening at all. When the procedure for applying information is decided, therefore, an expiry or a trigger for review needs to be decided along with it. The other thing that calls for care is that the same observation comes back around through more than one route. Once an observation has been taken up by several providers, it looks to the receiving side as though the same content arrived from separate sources. Where a count is treated as grounds for agreement, a single observation can end up treated as a corroborated fact. Numbers overlapping and something being confirmed independently are not the same thing.
The Threat Intelligence Cycle
Three Levels
Threat intelligence is classified into three levels: strategic, tactical, and operational. Strategic intelligence is aimed at executives, providing industry-wide threat trends and risk assessments. Tactical intelligence analyzes the attacker's TTPs and is used to improve the detection rules of the SOC team. Operational intelligence feeds concrete IoCs (IP addresses, domains, file hashes) into security appliances, directly enabling real-time defense.
Use-Case Scenarios
For example, when a competitor in your industry is hit by a ransomware attack, you can obtain the IP addresses of the C2 servers and the subject-line patterns of the phishing emails used in the attack from a threat intelligence feed and get ahead of the curve in defending your own organization. A technique that uses the MITRE ATT&CK framework to map attacker behavior patterns and visualize gaps in your detection coverage is also effective. Threat intelligence is indispensable for the early warning of supply chain attacks as well.
Key Points for Adoption
Threat intelligence is meaningless if you "just collect it." What matters is the process of prioritizing the collected information against your own environment and translating it into concrete actions (adding rules, applying patches, issuing alerts). Protect access to your intelligence platform with a strong random password to prevent information leaks.
Was this article helpful?