Education

Cyber Threat Intelligence


Cyber Threat Intelligence is an essential part of an organization's defensive plan. Read to find out why.

Intelligence is information that can be acted upon to change outcomes.

Cyber Threat Intelligence (CTI) is organized, analyzed and refined information about potential attacks threatening an organization. CTI is any form of information that may help an organization to identify, assess, monitor and respond to cyber threats and attacks. It is used to prevent current and future threats, including the most common and severe threats, as well as in-depth information about threats that are specific to the organization.

By deploying highly-automated CTI solutions, the organization will be able to protect itself from the types of attacks that could do the most damage. Implementing CTI in a company consumes a lot of manpower and time. The organization must evaluate the right sources for information on CTI and constantly update them to ensure trouble-free function in all aspects.

CTI is divided into four subtypes: 1. Strategic, 2. Tactical, 3. Technical and 4. Operational (Fig 1).

A pie chart about threat intelligence showing four quadrants. The top left quadrant is Long-term Use and High Level: Strategic. The top right quadrant is Long-term Use but Low Level: Tactical. The bottom right quadrant is Short-term Use and Low Level: Technical. The bottom left quadrant is High Level and Operational. The left half of the pie chart shows high-level threats; the right half shows low-level threats. The top half of the pie chart shows long-term use; the bottom half shows short-term use and low level.

1. Strategic Threat Intelligence is consumed by high-level strategists within an organization. It gives insight into changing threat levels from different sources.
E.g. information published by a CTI Provider about the general growth of malware infections (Fig 2) or information about which platforms (Office, Flash, Android, Java, Browsers, PDF) are targeted. It normally contains no information about specific techniques or codes.

A chart showing the growth of malware infections from 2016 to 2018. The first bar for 2016 is 38%, the second bar for 2017 is 48%, the last bar for 2018 is 52%.

2. Tactical Threat Intelligence is information about how threat actors conduct threats. Tactical Threat Intelligence is consumed by defenders and responders in order to ensure that defenses, alerts and investigation are prepared for current attacks. The source for Tactical Threat Intelligence are white papers, technical press or communication with peers and other organizations.
E.g. a feed of a CTI Provider publishing which domains have been taken over by spreading malicious code.

3. Technical Threat Intelligence is information consumed through technical means (e.g., a feed of blacklisted IP addresses that can be imported to firewalls) and has a short lifetime as attackers can easily change IP addresses or checksums.

4. Operational Threat Intelligence is information about a specific impending attack (e.g., the Yatron virus or Bluekeep, Fig 3) against your organization and is normally directed to higher-level security staff. Such critical information about a direct current attack requires instant reaction.

A warning message in the style of a Windows pop-up stating: Oops, Your Files Are Encrypted. There is a message from Yatron, the threat actors, explaining "Your documents, photos, databases and Other have been encrypted ? the files that you looked for not readable ? We are the only ones who can decrypt your files Through the unique key. what should I do for decrypting my files? If you want to recover your files, you must purchase a unique key. send300$ btc  to address: 36Bz7B1gsc1WdBf7tnRNbKUGiQjQ2qHGoo" The next message states "Send us your ID after your payment Email to contact us :   yatronraas@gmail.ru" There are text boxes below the main message containing payment information: one is regarding "Amount Bitcoins" with a speace for the victim to add the number. The next box is "Wallet for sending bticoins" with a space to add wallet information. The next is "Your ID" with a space to add the ID number. The final box is "Contact Us" containing their email address. The final text says "you have 3 Days to pay or Your files will be deleted" with a countdown below stating "Time Left" and then "52:59:49".

As you can see, CTI is a wide field of gathering, consuming and correlating data, which is highly labor-intensive and challenging.

Our service provides your organization with essential and up-to-date information on potential attack sources relevant to your business. We help you to develop your own CTI to give you the most current and effective tools to defend your organization.

Micaela
May 13, 2024