Analytics // Threat Intelligence
5/9/2013
03:55 AM
Tim Wilson
Tim Wilson
Commentary
Connect Directly
RSS
E-Mail
50%
50%

Five Questions To Ask When Choosing A Threat Intelligence Service

Threat intelligence services are becoming an essential weapon in the enterprise security arsenal. Do you know how to choose one?

Today's emerging threat intelligence services have the potential to change the way enterprises measure security risk and prepare their defenses for the next wave of attacks. If you subscribe to the Art of War's mantra, "know your enemy," threat intelligence is a key weapon in any IT security arsenal.

As they hit the market, however, it's becoming painfully clear that there is a huge disparity between the offerings that vendors are calling "threat intelligence service." Some of them are single-source RSS feeds, not too much different than what you might get from CERT (or even Dark Reading). Others are in-depth analytical services that can not only report and analyze the threats, but also tell you how they might affect your specific IT environment.

Dark Reading filed a report on how to choose threat intelligence tools last year, but at that point, a lot of these services were still in their formative stages. So recently I spoke to Lance James, director of threat intelligence services at security vendor Vigilant, and asked him for some thoughts on what questions security professionals should ask of prospective service providers. I should note that James, like most threat intelligence experts, recommends that enterprises should use multiple services, rather than just one. But if your organization is not made of money, you may have to be selective. Here are some questions that may be helpful in researching and choosing a threat intelligence service.

1. How many sources does the threat intelligence service pull from?
Some services are a single feed from a specific vendor's research arm, or even a white-labeled feed from another company. Other threat intelligence services collect and correlate data from dozens of different sources, giving a more comprehensive view of the threats.

"That's not to say that all the data has to be confirmed by multiple sources," James notes. "Sometimes a single anomaly from a single source is your first indication of a zero-day attack."

2. How frequently is the threat intelligence updated?
Different threat intelligence services approach their reporting with different philosophies. Some send out data constantly, offering just the basics on what they are seeing. Others take time to analyze the data and correlate it before they publish it. Timing may be important to some providers and not to others.

3. How are the threats evaluated?
Some threat intelligence services simply send out the data they collect, without ranking or evaluating it. Others offer a simple ranking, similar to the "critical" and "important" rankings used to measure new vulnerabilities.

In some cases, the threats may be given a specific score, using a system that ranks criteria such as potential damage and likelihood of infection. Some services correlate this data from many different sources and come up with an overall ranking.

4. How is the data formatted?
Particularly in cases where the threat intelligence comes from multiple sources, it can be extremely difficult to interpret and manage. Different sources have different ways of measuring and interpreting threat data, and getting a feed from all of those sources can result in a jumble of information that isn't much more helpful than no data at all.

A useful threat intelligence service will provide a way to normalize the threat information and present it in a way that can be reported consistently over a particular time period and plugged into reports that the enterprise already does.

5. Can the threat data be correlated with information that the enterprise already has about its security posture?
One of the great promises of threat intelligence is that it might be tailored so that it doesn't just give general threat information, but also provides insight as to whether a particular threat might affect a specific organization. Correlating threat data with information about the current state of the enterprise defenses allows an organization to come up with a real assessment of risk.

In many cases, however, the threat data you receive from an intelligence service does not reflect the specific systems your organization has, or the specific data it's trying to protect. A sophisticated attack against Unix devices might be ranked highly on the threat meter, but it may be moot if your enterprise is an all-Windows shop.

Over time, many threat intelligence services are tying into security information and event management (SIEM) systems that collect and correlate enterprise security posture data. The combination of current threat data and up-to-the-minute security posture information may eventually make it easier for enterprises to make defensive decisions that fit their specific situation, and to more accurately assess the risks they face from a particular threat. Tim Wilson is Editor in Chief and co-founder of Dark Reading.com, UBM Tech's online community for information security professionals. He is responsible for managing the site, assigning and editing content, and writing breaking news stories. Wilson has been recognized as one ... View Full Bio

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
Partner Perspectives
What's This?
In a digital world inundated with advanced security threats, Intel Security seeks to transform how we live and work to keep our information secure. Through hardware and software development, Intel Security delivers robust solutions that integrate security into every layer of every digital device. In combining the security expertise of McAfee with the innovation, performance, and trust of Intel, this vision becomes a reality.

As we rely on technology to enhance our everyday and business life, we must too consider the security of the intellectual property and confidential data that is housed on these devices. As we increase the number of devices we use, we increase the number of gateways and opportunity for security threats. Intel Security takes the “security connected” approach to ensure that every device is secure, and that all security solutions are seamlessly integrated.
Featured Writers
White Papers
Cartoon
Current Issue
Dark Reading's October Tech Digest
Fast data analysis can stymie attacks and strengthen enterprise security. Does your team have the data smarts?
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-3304
Published: 2014-10-30
Directory traversal vulnerability in Dell EqualLogic PS4000 with firmware 6.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the default URI.

CVE-2013-7409
Published: 2014-10-30
Buffer overflow in ALLPlayer 5.6.2 through 5.8.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in a .m3u (playlist) file.

CVE-2014-3446
Published: 2014-10-30
SQL injection vulnerability in wcm/system/pages/admin/getnode.aspx in BSS Continuity CMS 4.2.22640.0 allows remote attackers to execute arbitrary SQL commands via the nodeid parameter.

CVE-2014-3584
Published: 2014-10-30
The SamlHeaderInHandler in Apache CXF before 2.6.11, 2.7.x before 2.7.8, and 3.0.x before 3.0.1 allows remote attackers to cause a denial of service (infinite loop) via a crafted SAML token in the authorization header of a request to a JAX-RS service.

CVE-2014-3623
Published: 2014-10-30
Apache WSS4J before 1.6.17 and 2.x before 2.0.2, as used in Apache CXF 2.7.x before 2.7.13 and 3.0.x before 3.0.2, when using TransportBinding, does properly enforce the SAML SubjectConfirmation method security semantics, which allows remote attackers to conduct spoofing attacks via unspecified vect...

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Follow Dark Reading editors into the field as they talk with noted experts from the security world.