Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Analytics

5/31/2018
04:00 PM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
50%
50%

Building Blocks for a Threat Hunting Program

Guidance for businesses building threat intelligence strategies while overwhelmed by threats, lack of talent, and a healthy dose of skepticism about the market.

The number and severity of cyberattacks are sending businesses scrambling to figure out their threat intelligence strategies: how to collect threat data, organize it into actionable information, prioritize the most severe threats, and address the biggest problems.

Threat intelligence is among the hottest buzzwords in cybersecurity today, and with good reason. As attacks become more severe, frequent, and complex, businesses struggle to detect and mitigate them with limited resources. New platforms promise artificial intelligence to pick up the slack by processing alerts, freeing up employees for focus on more complex tasks.

In the past, threat intel has meant a tactical feed of malicious IP addresses feeding into the security operations center (SOC) with little context or relation to the business. Now, it means feeds of domains, hashes, and IP address related to malicious activity, with threat intelligence platforms attempting to organize them. These platforms aim to supplement existing tech like SIEMs, IPS systems, and firewalls.

But the infosec community isn't fully sold. A recent study by the Ponemon Institute found 70% of security professionals surveyed think threat intelligence is too overwhelming or intricate to offer usable insight. Only 27% report their organization is "very effective" in using threat data to detect threats; only 31% of board and C-level members receive intelligence on security issues.

Part of the appeal of threat intelligence platforms is they're intended to perform the function of a tier-one SOC analyst, someone who is normally responsible for clicking through alerts generated by firewalls, IDS/IPS, SIEM, and endpoint security tools and gauging their intensity. This ideally gives employees more time to focus on mitigating advanced threats.

The problem is there are precious few people who know what to do with threat intelligence once they have it, and they don't come cheap. Even companies with generous security budgets have to figure out how to hire these employees and keep them on board. Corporate giants struggle with these issues because they lack sufficient resources, says JASK CEO Greg Martin.

"You don't have to have ten years of experience to be a threat hunter, but you have to have the aptitude, you have to know what you're doing to be effective in this space," says Martin. "Only the best companies in the world have true threat-hunting teams internally."

Building a Threat Management Program

"I think a lot of people approach threat hunting in the wrong way," says Alert Logic principal analyst Matt Downing, who shares a few pointers for building a threat management strategy. He, of course, starts with people.

"You have to allocate manpower," he emphasizes, adding that companies should form a team for this if they don't already have one. "You need an experienced staff to go in and look at this … have you seen threats, seen how attackers operate."

The most popular threat hunting skills for security pros include threat intelligence (69%), user and entity behavior analytics (57%), automatic detection (56%), and machine learning and automated analytics (55%), Alert Logic discovered in a recent survey.

Next, he advises reading through publicly reported incidents and asking whether it would happen to your company. Alert Logic does a lot of network inspection, he explains, and specifically focuses on endpoints. No matter how sophisticated and fancy the attacker is, they need to communicate with the target machine, he explains.

When asked about the biggest challenge in threat hunting, Downing says a major obstacle is lack of knowledge about what attacks look like. Threat management challenges include detecting advanced threats (55%) and lack of security expertise (43%).

"Part of it is understanding what people do normally," he continues. "You have to understand what's benign if you're going to understand what's malicious." By taking this approach and looking at the tactics, processes, and tools used in an attack, you get an end-to-end story of detection that can serve as a blueprint for pinpointing future threats.

New Approaches to Threat Hunting

What if you don't have the manpower in-house? In an effort to mitigate challenges for short-staffed companies, JASK launched a service called Special Ops. The idea can be summed up as Threat Hunting-as-a-Service: JASK supplements clients' existing security staff with its "Special Ops" team, which has threat analysts and researchers poached from Palo Alto Networks, Dell SecureWorks, and RSA FirstWatch.

The role of SpecialOps is to detect threats, help analysts identify what they should care about, and provide guidance for next steps. If JASK analysts detect an anomaly, they alert the company. From there, they escalate internally with the team and, if necessary, connect them with law enforcement or a partner like CrowdStrike or Mandiant to pursue an investigation.

"A lot of organizations come to us because they don't have the resources," he explains.

With talent expensive and hard to find, this service puts skilled analysts in one place so companies from enterprises to SMBs have them on-call. Instead of digging through the data themselves, or relying on software, they have a means of leveraging human talent to weed out threats. More than three-quarters (76%) of Alert Logic respondents say not enough time is spent searching for emerging and complex threats in the SOC. 

"We used to kill ourselves looking for the needle in the haystack," Martin notes. "We have a big stack of needles, now we need to find out which is the sharpest."

Related Content:

Kelly Sheridan is the Staff Editor at Dark Reading, where she focuses on cybersecurity news and analysis. She is a business technology journalist who previously reported for InformationWeek, where she covered Microsoft, and Insurance & Technology, where she covered financial ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
NSA Appoints Rob Joyce as Cyber Director
Dark Reading Staff 1/15/2021
Vulnerability Management Has a Data Problem
Tal Morgenstern, Co-Founder & Chief Product Officer, Vulcan Cyber,  1/14/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win an Amazon Gift Card! Click Here
Latest Comment: This is not what I meant by "I would like to share some desk space"
Current Issue
2020: The Year in Security
Download this Tech Digest for a look at the biggest security stories that - so far - have shaped a very strange and stressful year.
Flash Poll
Assessing Cybersecurity Risk in Today's Enterprises
Assessing Cybersecurity Risk in Today's Enterprises
COVID-19 has created a new IT paradigm in the enterprise -- and a new level of cybersecurity risk. This report offers a look at how enterprises are assessing and managing cyber-risk under the new normal.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-27221
PUBLISHED: 2021-01-21
In Eclipse OpenJ9 up to version 0.23, there is potential for a stack-based buffer overflow when the virtual machine or JNI natives are converting from UTF-8 characters to platform encoding.
CVE-2021-1067
PUBLISHED: 2021-01-20
NVIDIA SHIELD TV, all versions prior to 8.2.2, contains a vulnerability in the implementation of the RPMB command status, in which an attacker can write to the Write Protect Configuration Block, which may lead to denial of service or escalation of privileges.
CVE-2021-1068
PUBLISHED: 2021-01-20
NVIDIA SHIELD TV, all versions prior to 8.2.2, contains a vulnerability in the NVDEC component, in which an attacker can read from or write to a memory location that is outside the intended boundary of the buffer, which may lead to denial of service or escalation of privileges.
CVE-2021-1069
PUBLISHED: 2021-01-20
NVIDIA SHIELD TV, all versions prior to 8.2.2, contains a vulnerability in the NVHost function, which may lead to abnormal reboot due to a null pointer reference, causing data loss.
CVE-2020-26252
PUBLISHED: 2021-01-20
OpenMage is a community-driven alternative to Magento CE. In OpenMage before versions 19.4.10 and 20.0.6, there is a vulnerability which enables remote code execution. In affected versions an administrator with permission to update product data to be able to store an executable file on the server ...