Trust but verify, or How to choose TI sources wisely

More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…
Trust but verify, or How to choose TI sources wisely 😏
In the life of the vast majority of SOC centers, there comes a time when you need to supplement your toolkit with cyber threat intelligence (TI) data.
Perhaps the first place to start is feeds with indicators of compromise and their associated context, which will help expand the detection scope of your security tools. You can find many sources online that provide such data — both open-source and commercial. However, the question arises: how do you choose the most high-quality and relevant ones for your organization? Let’s try to answer this question in this article 📖
It’s no secret that the more events a security tool processes, the more expensive an excessive flow of false positives becomes. If you connect TI sources without pre-screening them, the number of false positives can multiply. To avoid this, we suggest considering the following steps.
Step 1️⃣
First, you should get reacquainted with what you are protecting, namely:
• Study your organization’s infrastructure and critical assets (e.g., servers, databases).
• Understand what you are protecting and from what.
• Identify which security tools are used in the organization’s security system.
• Clarify which TI sources are used “out of the box” in your products and whether they are used at all.
Based on the information gathered, you need to define protection priorities and potential attack vectors relevant to your organization (this is also called the threat landscape). The information obtained will allow you to proceed to the next step — selecting TI sources.
Step 2️⃣
When choosing a source, you can rely on metrics that should be evaluated in terms of their importance. At this stage, we offer you several basic indicators:
• Detection accuracy. The ratio of the number of positive detections to the total number of detections based on TI content from a specific source.
• Detection coverage. The ratio of the number of detections based on data from a TI source to the total number of detections recorded on a specific security tool.
• Data stream relevance. Based on the information from Step 1 (the threat landscape), we have an idea of what is relevant to us and what is not. This refers, for example, to the presence in the data stream of information specific to a particular industry or region, descriptions of hacker group activities, or the operation algorithm of a specific malware family. In other words, everything you consider useful for use in your organization when building information security processes. The more context is linked to our landscape, the higher the metric value.
• Data stream timeliness. This is an assessment of the difference between the time a threat appears (or is discovered) and the time the data is delivered. The smaller the difference between these times, the higher the chance of detecting an attempt to exploit that threat in time.
• Data stream update frequency. A metric that allows you to assess how much the data stream changes between delivery iterations. Essentially, this is a criterion that answers the question of how many unique indicators a source provides per unit of time (e.g., per day).
You are free to come up with your own metrics and rely on them when selecting data sources. For example, you can evaluate the convenience of the data delivery structure (what format it comes in, whether it can be customized), the delivery frequency (e.g., once a day, once an hour, every 10 minutes), or the presence of certain delivery shortcomings (data duplicates, SLA violations).
Step 3️⃣
After you have selected TI data sources based on metrics, you need to connect them to your security tools in a test mode and check how effective and useful they are for your work. If the source performs well during the trial period, it is worth working with and using in “combat” mode.
#TI #tips
@ptescalator
More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…



