Analytics
8/13/2014
12:00 AM
Dark Reading
Dark Reading
Infographics
Connect Directly
RSS
E-Mail
50%
50%

Get Smart About Threat Intelligence

Is threat intel the best way to improve defenses and stay ahead of new and complex attacks? Nearly 400 respondents to Dark Reading's new Threat Intelligence Survey seem to think so.

Get Smart About Threat Intelligence

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
JasonSachowski
50%
50%
JasonSachowski,
User Rank: Author
9/10/2014 | 6:42:21 PM
Re: Disconnect?
I wouldn't go as far to say this is attributed directly to the process aspect. Sure we could enhance our processes to make improvements on the flow of data between the doers and the decision makers; but there's also the challenge of data getting lost in translation. Not so much because of process, but because the doers speaking in a technical language (0&1) and the decision makers speak in a business language ($$$). By improving the way we communicate information, the process disconnect to improve data flow would somewhat fix itself.
Marilyn Cohodas
50%
50%
Marilyn Cohodas,
User Rank: Strategist
9/10/2014 | 7:44:46 AM
Re: Disconnect?
@JasonSachowski, So you are saying that there needs to be a better process communicating tactical information from to the analysts who are developing defensive strategies and action plans.... 
JasonSachowski
50%
50%
JasonSachowski,
User Rank: Author
9/9/2014 | 8:22:55 PM
Re: Disconnect?
Sure @MarilynCohodas... As I mentioned before, threat intelligence is a collection of (somewhat) similar information to tactically mitigate individual an threat. And for the most part, those security analysts who are directly involved in taking action from this intelligence aren't necessarily those senior professionals who are involved in decision making. However, the tactical intelligence collected and disseminated by the security analysts can be correlated and become a large contributor to strategic road maps developed by senior professionals.
Marilyn Cohodas
50%
50%
Marilyn Cohodas,
User Rank: Strategist
9/8/2014 | 9:26:42 AM
Re: Disconnect?
@JasonSachowski, you wrote that security practitioners need "to take what we learn from threat intelligence and feed that into a larger form of security intelligence.." to move from the tactical to the strategic.  Care to give an example of what that would look like?
JasonSachowski
50%
50%
JasonSachowski,
User Rank: Author
9/6/2014 | 12:38:59 PM
Re: Disconnect?
The way threat intelligence is delivered to us is that it is mostly information about individuals threats. It provide us with the information we need to safeguard against each threat and is mostly tactical. If we really want to get ahead of the game, we need to take what we learn from threat intelligence and feed that into a larger form of security intelligence. This way, we can get away from the tactical/linear approaches and develop more strategic/cyclical methodologies.
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
8/31/2014 | 8:44:17 AM
Re: Disconnect?
This is disheartening. One of the main principles of information security is that analysis/scans without action/adaptation is a useless practice. Threats evolve so the security in turn and strategies needs to evolve. A waterfall approach cannot be taken with an agile vector.
Bprince
50%
50%
Bprince,
User Rank: Ninja
8/15/2014 | 8:47:51 PM
Re: Disconnect?
Yeah I find that an interesting stat too. I guess that means the threat intel is confirming what they know already and have already been preparing for. Or it could be that they are not digesting that intelligence well.

BP
Marilyn Cohodas
50%
50%
Marilyn Cohodas,
User Rank: Strategist
8/15/2014 | 9:12:34 AM
Re: Threat Intel
Yes, it's overall an encouraging report. I find it interesting (not totally surprising) that socal media is getting scant attention from respondents. jJust 13% of respondents said they are looking at FB, Twitter and blogs. I wonder if that will change over the next year?
RiskIQBlogger
50%
50%
RiskIQBlogger,
User Rank: Author
8/14/2014 | 12:48:41 PM
Threat Intel
Interesting information, it seems like threat intelligence is becoming a more prevelant strategic initiative.  Things are hopefully headed in the right direction!
Marilyn Cohodas
50%
50%
Marilyn Cohodas,
User Rank: Strategist
8/13/2014 | 1:56:13 PM
Disconnect?
85 percent of respondents says threat intellegience plays some role in their security activities but 90% says that threat intel analysis has't changed their defense strategy. What's up with that?
Register for Dark Reading Newsletters
Partner Perspectives
What's This?
In a digital world inundated with advanced security threats, Intel Security seeks to transform how we live and work to keep our information secure. Through hardware and software development, Intel Security delivers robust solutions that integrate security into every layer of every digital device. In combining the security expertise of McAfee with the innovation, performance, and trust of Intel, this vision becomes a reality.

As we rely on technology to enhance our everyday and business life, we must too consider the security of the intellectual property and confidential data that is housed on these devices. As we increase the number of devices we use, we increase the number of gateways and opportunity for security threats. Intel Security takes the “security connected” approach to ensure that every device is secure, and that all security solutions are seamlessly integrated.
Featured Writers
White Papers
Cartoon
Current Issue
Dark Reading's October Tech Digest
Fast data analysis can stymie attacks and strengthen enterprise security. Does your team have the data smarts?
Flash Poll
Threat Intel Today
Threat Intel Today
The 397 respondents to our new survey buy into using intel to stay ahead of attackers: 85% say threat intelligence plays some role in their IT security strategies, and many of them subscribe to two or more third-party feeds; 10% leverage five or more.
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-0334
Published: 2014-10-31
Bundler before 1.7, when multiple top-level source lines are used, allows remote attackers to install arbitrary gems by creating a gem with the same name as another gem in a different source.

CVE-2014-2334
Published: 2014-10-31
Multiple cross-site scripting (XSS) vulnerabilities in the Web User Interface in Fortinet FortiAnalyzer before 5.0.7 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2014-2336.

CVE-2014-2335
Published: 2014-10-31
Multiple cross-site scripting (XSS) vulnerabilities in the Web User Interface in Fortinet FortiManager before 5.0.7 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2014-2336.

CVE-2014-2336
Published: 2014-10-31
Multiple cross-site scripting (XSS) vulnerabilities in the Web User Interface in Fortinet FortiManager before 5.0.7 and FortiAnalyzer before 5.0.7 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2014-2334 and CVE-2014-2335.

CVE-2014-3366
Published: 2014-10-31
SQL injection vulnerability in the administrative web interface in Cisco Unified Communications Manager allows remote authenticated users to execute arbitrary SQL commands via a crafted response, aka Bug ID CSCup88089.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Follow Dark Reading editors into the field as they talk with noted experts from the security world.