[ << ALL_FEED ]

Useful data sources: MISP Warning Lists

More in General

🗂 Useful Data Sources: MISP Warning Lists

Information security analysts deal with massive volumes of threat data on a daily basis. To extract the most relevant events, they spend countless hours performing complex checks. In large quantities, such checks can lead to analyst information overload and, ultimately, errors in analysis.

To avoid this, you can use initial filtering of the incoming security event stream to eliminate false positives using indicator whitelists. The open-source MISP Warning Lists repository is perfect for this purpose. It currently contains 89 different indicator sets, grouped into categories.

All indicator sets in this source can be roughly divided into two groups: “white” and “gray.”

☑️ “White” indicators are unequivocally legitimate. These include sets such as:

• dax30 — a list of known web pages of major German companies;

• security-provider-blogpost — a list of blog addresses from well-known security vendors;

• eicar.com — a list of hash sums for the EICAR test malware.

Such indicators are the most useful way to filter out false positives from security tools.

ℹ️ “Gray” indicators are legitimate in themselves but can be involved in malicious activity. Sets containing such indicators include, for example:

• amazon_aws — a list of Amazon Web Services IP address ranges;

• vpn-ipv4 — a list of IP address ranges belonging to common VPN providers;

• dynamic-dns — a list of known TLD and DDNS providers;

• url-shortener — a list of known URL shortening services.

You can apply such lists to “whitelist” incoming events based on your organization’s security policy and your own experience (for example, you might assume that all traffic between your infrastructure and cloud providers is “white”).

At the same time, these same lists can be used to highlight events that indicate a security policy violation (for example, if DNS resolution events for DDNS domains are observed on a DNS server, this is always suspicious).

💡 A few tips for use:

• Evaluate the usefulness of each specific list for your own infrastructure. Don’t load everything indiscriminately.

• Pay attention to how often lists are updated. Some are updated rarely or not at all.

#tool #tip #TI
@ptescalator

More from ti_author

More from ti_author

More in General