Chapter 4 Signature Flashcards
1
Q
Data collection methods
A
2
Q
Types of data
A
3
Q
Types of threat intelligence data collection
A
4
Q
Building a threat intelligence collection plan
A
A good threat intelligence collection plan can drive the intelligence collection teams to generate good results in reducing the organizational risks.
- Design a threat intelligence collection strategy
- Understand the limitations of the area of operations
- Understand the area of interest
- Understand different collection sources and solutions that match your needs
- Ensure reliability of Data Collection method providing actionable data
- Align the collected internal external data and data sources to your organisational specific intelligence analysis needs in further stages
- Normalise the information with industry standard
- Store the information in secure and easily accessible infrastructure
- Share the information with other analysis team
5
Q
Threat intelligence feeds
A
Threat intelligence feeds refer to a stream of indicators or data derived from the various sources related to potential or evolving threats to an organization’s security.
-
External intelligence feeds: includes information that is acquired from globally available sources
- Journals groups forums and blogs
- Law enforcement feeds
- Business associations
- Security researchers
- Underground forums
- Hash records
- GEOIP statistics
-
Internal intelligence feeds: includes information that is acquired from locally available sources and from local infrastructure or system
- Fraud analysis
- Security activity data
- Mailbox misuse information
- Human intelligence
- Vulnerability information
- Sandbox
-
Proactive surveillance feeds: includes information that is required using real-time assessment of system activities and events
- Honeynets
- Malware forensics
- Brand monitoring
- P2p monitoring
- DNS monitoring
- Watchlist monitoring
- Infrastructure and application logs
-
External intelligence feeds: includes information that is acquired from globally available sources
6
Q
Threat intelligence sources
A
Apart from the sources mentioned above, you can also collect the threat information from the following government and law enforcement sources:
-
-
Open source intelligence (OSINT) information is collected from publicly available sources and analysed to obtain a rich use full form of Intelligence
- Media
- Internet
- Public government data
- Corporate/academic publishing
- Literature
-
Human intelligence (HUMINT) Information is collected from interpersonal contacts
- Foreign defence personnel and Advisors
- Accredited diplomats
- NGOs
- Prisoners of War(POW)
- Refugees
- Traveler interview for debriefing
-
Signals intelligence (SIGINT) Information is collected by intercepting the signals
- Communication intelligence(COMINT): Obtained from interception of communication signals
- Electronic intelligence(ELINT): Obtained from Electronic sensors like radar and lider
- Foreign instrumentation signals intelligence (FISINT): signals detected from nonhuman communication systems
-
Technical intelligence (TECHINT) Information is collected from an adversary’s equipment or captured any material (CEM)
- Foreign equipment
- Foreign weapon systems
- Satellites
- Technical research papers
- Foreign media
- Human contacts
-
GEO-spatial intelligence (GEOINT) Information is collected by exploitation and evaluation of Geo spatial information to assess the human activities on earth
- Satellite imagery
- Unmanned aerial vehicles(UAV) imagery
- Maps
- GPS waypoints
- IMINT (imagery intelligence)
- National Geospatial Intelligence Agency (NGA)
-
Imagery intelligence (IMINT) Information is collected from objects that are used to reproduce the real scenario electronically by any kind of electronic media or device
- Visual photography
- Infrared sensors
- Synthetic aperture radar (SAR)
- MASINT (measurement and signature intelligence)
- LASER
- Electro-optics
-
Measurement and signature intelligence (MASINT): information is collected from the sensors that are intended to record distinctive characteristics signatures of fixed or dynamic targets
- Electro-optical
- Acoustic sensors like Sonars
- Infrared
- Radar sensors
- Laser
- Spectroscopic sensors
-
Covert human intelligence sources (CHIS)
- Information is collected covertly from the target person by maintaining a personal or other relationship with the target person
- CHIS is generally referred to a person or an agent under the regulation of investigatory Powers Act 2000 (RIPA) UK
- CHS sources are target persons from whom the information will be extracted
-
Financial intelligence(FININT) information is collected from adversaries financial affairs and transaction that may involve tax evasion or money laundering etc which in turn provide information about the nature capabilities and intentions of the advisory. Sources include
- Financial intelligence unit
- Banks
- SWIFT
- Informal value transfer system (IVTS)
-
Social media intelligence(SOCMINT): Information is collected from social networking sites and other types of social media sources
- Telegram
-
Cyber counter intelligence(CCI) : Information is collected from proactively established security infrastructure or by employing various threat manipulation techniques to liya entrapped threats
- Honeypots
- Passive DNS monitors
- Online web trackers
- Sock puppets(fake profiling) on online forums
- Publishing false reports
-
Indicators of compromise (IoCs): Information is collected from network security threats and breaches and also from the alerts generated on security interest share which will likely indicate the intrusion
- Commercial and industrial sources
- Free IOC specific sources
- Online security related sources
- Social media and news feeds
- IOC buckets
-
Industry associations and vertical communities: Information is collected from various threat intelligence sharing communities where organisations share that intelligence information among each other vertical communities sources include the following:
- Financial services Information sharing and analysis centre(FS-ISAC)
- MISP (Malware Information sharing platform)
- MineMeld
- Dakreading.com
- kerberosonsecurity.com
-
Commercial sources Information is collected from commercial entities and security vendors that provide the threatinformation to various organisations. Commercial sources include the following
- Kaspersky threat intelligence
- McAfee
- Avast
- Fortiguard
- Secureworks
- Cisco
-
Government and law enforcement sources information is collected from Government and law enforcement sources Government sources include the following
- Us computer emergency response team (US-CERT)
- European Union agency for Network and information security (ENISA)
- FBI cyber crime
- Stop thinkConnect
- CERIAS Blog
- International Police Organization (Interpol)
- Central Intelligence Agency (CIA)
- National Security Agency (NSA)
- Homeland Security (DHS)
- Central Bureau of Investigation (CBI)
- National Investigation Agency (NIA)
-
Open source intelligence (OSINT) information is collected from publicly available sources and analysed to obtain a rich use full form of Intelligence
7
Q
A