Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Perimeter

10/12/2018
10:30 AM
Rick Costanzo
Rick Costanzo
Commentary
Connect Directly
LinkedIn
RSS
E-Mail vvv
100%
0%

Threat Hunters & Security Analysts: A Dynamic Duo

Fighting spying with spying, threat hunters bring the proactive mindset of network reconnaissance and repair to the enterprise security team.

Take a look at the job listings on LinkedIn, Indeed, or any of the major sites, and you'll find hundreds of openings for threat hunters, something you wouldn't have seen just a few years ago. Many of these listings are from big banks, global telecoms, and defense contractors, institutions where data security is of primary importance and signaling others will follow.

As the pace, scale and harm-quotient of cyberthreats continue to grow, companies will increasingly shift thinking and resources to finding attackers before they cause problems. Clearly, the typical breach scenario — where internal teams discover an attack has taken place well after the fact, and then go into damage control — is frustrating for security professionals, customers, and shareholders. If you consider that the dollar amount of damage caused by a data breach is typically about commensurate with the cost of bad publicity resulting from the attack, having your CEO making a public mea culpa is neither a good strategy or investment.  

As a result of this changing dynamic, companies are hiring threat hunters to work alongside security analysts to create a continuum of protection — some on the offense, digging for vulnerabilities, others playing defense, protecting assets and patching holes.

Threat Hunter vs. Security Analyst
Threat hunters are, first of all, experienced security analysts. Because the role is to anticipate problems, it's critical for candidates to have a history of dealing with ransomware, phishing schemes, and cryptojacking. Good threat hunters, who are born from security analysts, maintain their education, and keep close watch on cybersecurity information and research, such as the nonprofit, federally funded research and development centers, known as MITRE, which include cybersecurity among its specialties. 

Successful threat hunters also must have a broad knowledge of network topology in order to assemble disparate signals into comprehensive views. Combined with a hacker's curiosity, threat hunters are armed to take educated hunches and explore the internal network, within the perimeter, to look for weaknesses and anomalies.

Threat-hunting teams, like hackers, undertake exploratory missions of their networks. They proactively look for specific malware intrusions as they are produced, maintain a steady eye on their organizations most sensitive data silos, and routinely patrol those areas of the network. They also develop a sixth sense for what is normal behavior at endpoints, the better to question subtle changes.

Threat hunters' analytical and technical expertise is complemented by other skill sets, like persuasive communication. Threat hunters often find themselves explaining the hypothetical to stakeholders who may still be stuck in a mindset of dealing with cyberattacks after they happen. That's in contrast to traditional cybersecurity analysts, who are tilted toward intrusion analysis, digital forensics, damage control, and repair. One role complements the other.

A Brave New World
Threat hunters thrive in places where top management understands the flip side of convenience. For example, cloud-based systems and connected devices are great for employees, contractors, and partners to communicate and share information. But this also creates porosity — or holes. The threat landscape is further complicated by today's more sophisticated breed of hacker who is profit-driven and, in some cases, handsomely paid by hostile governments, a trend we expect to accelerate in the next 24 months as the scale, complexity, and persistence of today's modern cyber threats increases. Organizationally, this means that security operations center teams will place a greater focus on dedicated threat hunting.

Furthermore, as part of the threat hunters' new role in identifying bad actors while they are still in reconnaissance mode, they need to write rules to map and detect TTPs (tactics, techniques, and procedures) that will identify who their adversaries are. From malicious pranksters to nation-sponsored attackers, threat hunters can spot emerging problems by knowing and continually mapping their favored TTPs.

The bottom line: Organizations need to adopt an aggressive, threat-hunting posture to compete with the proliferating threat universe. No longer is it sufficient to rely solely on incident-response teams that are already stretched thin and approaching problems after the fact. Threat hunters fight spying with spying, which will bring the proactive mindset of network reconnaissance and repair to protect an enterprise's vital data assets.

Related Content:

 

Black Hat Europe returns to London Dec. 3-6, 2018, with hands-on technical Trainings, cutting-edge Briefings, Arsenal open-source tool demonstrations, top-tier security solutions, and service providers in the Business Hall. Click for information on the conference and to register.

Rick Costanzo is an executive who has stoked a start-up mentality at some of the world's biggest companies, and a leader bringing new technologies from the theoretical to practical, everyday use. As CEO of RANK Software, Rick helps companies with one of the most critical ... View Full Bio
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
REISEN1955
50%
50%
REISEN1955,
User Rank: Ninja
10/12/2018 | 12:59:55 PM
Threat Hunting - an art with a science
It's not easy.  The skill set is entirely different than standard support and virus remediation.  I am just getting into it and it is like learning Mandarin Chinese - a ton of data exists and you have to be skilled in manipulation, conversion and analysis.  And the results of a 1,000 suspect hits produce  1 or 2 hits so it is alot of patience too.  Invaluable to do though.
Data Leak Week: Billions of Sensitive Files Exposed Online
Kelly Jackson Higgins, Executive Editor at Dark Reading,  12/10/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: Our Endpoint Protection system is a little outdated... 
Current Issue
The Year in Security: 2019
This Tech Digest provides a wrap up and overview of the year's top cybersecurity news stories. It was a year of new twists on old threats, with fears of another WannaCry-type worm and of a possible botnet army of Wi-Fi routers. But 2019 also underscored the risk of firmware and trusted security tools harboring dangerous holes that cybercriminals and nation-state hackers could readily abuse. Read more.
Flash Poll
Rethinking Enterprise Data Defense
Rethinking Enterprise Data Defense
Frustrated with recurring intrusions and breaches, cybersecurity professionals are questioning some of the industrys conventional wisdom. Heres a look at what theyre thinking about.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-12420
PUBLISHED: 2019-12-12
In Apache SpamAssassin before 3.4.3, a message can be crafted in a way to use excessive resources. Upgrading to SA 3.4.3 as soon as possible is the recommended fix but details will not be shared publicly.
CVE-2019-16774
PUBLISHED: 2019-12-12
In phpfastcache before 5.1.3, there is a possible object injection vulnerability in cookie driver.
CVE-2018-11805
PUBLISHED: 2019-12-12
In Apache SpamAssassin before 3.4.3, nefarious CF files can be configured to run system commands without any output or errors. With this, exploits can be injected in a number of scenarios. In addition to upgrading to SA 3.4.3, we recommend that users should only use update channels or 3rd party .cf ...
CVE-2019-5061
PUBLISHED: 2019-12-12
An exploitable denial-of-service vulnerability exists in the hostapd 2.6, where an attacker could trigger AP to send IAPP location updates for stations, before the required authentication process has completed. This could lead to different denial of service scenarios, either by causing CAM table att...
CVE-2019-5062
PUBLISHED: 2019-12-12
An exploitable denial-of-service vulnerability exists in the 802.11w security state handling for hostapd 2.6 connected clients with valid 802.11w sessions. By simulating an incomplete new association, an attacker can trigger a deauthentication against stations using 802.11w, resulting in a denial of...