top of page

Your Threat Feed Probably Isn't Intelligence

Writer: Matthew Wold
Matthew Wold
11 minutes ago
4 min read

I was in a meeting with a security vendor recently when they casually mentioned that they could provide us with Cyber Threat Intelligence, then continued right along with the meeting. There wasn't anything particularly unusual about what they said. Security vendors talk about threat intelligence feeds, threat intelligence platforms, threat intelligence reports and threat intelligence data all the time. I've probably used some of those same terms myself without thinking much about them.


But this time, for whatever reason, it stuck with me. What exactly were they offering to provide us? Was it really Cyber Threat Intelligence? Or have we just gotten so used to calling everything related to cyber threats "intelligence" that we've stopped thinking about what the word actually means? The more I thought about it, the more I realized that most of what we call Cyber Threat Intelligence isn't intelligence at all.


It's data.



Cyber Threat Data

An IP address associated with command-and-control infrastructure is data. So is a malicious domain, file hash, CVE, malware sample or list of techniques associated with a threat actor. Even a well-written report about a new ransomware campaign is primarily information about a threat.


That doesn't mean any of it is useless. Quite the opposite. We need this information. Some of it has been researched, analyzed, enriched and curated by some very smart people before it ever reaches us. There's a substantial difference between a random collection of indicators and a curated emerging-threat feed produced from observations across a large security platform.


But that still doesn't necessarily make it intelligence for my organization.

This distinction matters because it's very easy to subscribe to a few feeds, dump everything into a Threat Intelligence Platform and feel pretty good about what we've built. The platform is ingesting thousands or millions of indicators. Things are being correlated and enriched. There are dashboards showing threats from all over the world.


We have Cyber Threat Intelligence. We can sleep better tonight.


Except we may not actually know anything more about the threats to our organization than we did before. We just have considerably more data about bad things happening on the Internet.


Intelligence Is Different

The part that I think gets lost is that intelligence needs context. More importantly, it needs a question.


Knowing that a threat actor is actively exploiting a particular vulnerability is useful information. Knowing that my organization has 37 systems with that vulnerability changes things. Knowing that three are Internet-facing, one supports a critical business function and exploitation has been observed against organizations similar to mine changes things considerably more.


Now I have something I can use.


That's also why I don't think Cyber Threat Intelligence can ever be completely generic. My intelligence requirements aren't necessarily your intelligence requirements. My technology, people, business functions, geography, risk tolerance and priorities aren't yours either.


A vendor can tell both of us that something is happening. Whether either of us should care, and how much, depends on what is happening inside our own organizations.


We May Be Starting Backwards

This becomes clearer when you look at the intelligence cycle. There are different versions of the cycle, but they generally include some variation of direction, collection, processing, analysis and dissemination, with feedback helping to start the process over again. I'm not going to turn this into Intelligence 101, but there is something important about that order: collection isn't first.


Before collecting anything, you're supposed to figure out what you need to know. That's almost the opposite of how we frequently approach Cyber Threat Intelligence. One of the first questions becomes: What feeds should we ingest? So we start collecting. We add another feed, and another one, and maybe a few open-source feeds because they're free. Then we add CVE information, threat actor information, indicators, news and whatever else we can get into the platform.


Eventually we have an impressive collection of threat data, and then we try to figure out what to do with it. Maybe the first question shouldn't be what feeds we can ingest. Maybe it should be much simpler:


What do we need to know?


What Should Cyber Threat Intelligence Look Like?

If I'm responsible for vulnerability management, I probably don't need to know about every vulnerability being exploited somewhere in the world. I need to know which vulnerabilities are being exploited that exist in my environment, which systems are affected, how exposed they are and whether something about the current threat changes their priority.


A SOC may have completely different questions. So might the CISO.


Once we know the questions, we can determine what information we need to answer them. That's when the feeds become useful. That's when external threat information can be combined with asset inventories, vulnerability scanners, identity information, network data, security controls and everything else we know about our own environment.


At that point we're no longer just collecting information about threats. We're trying to answer a question. And I think that's the point where Cyber Threat Intelligence actually starts.


So What Are We Buying?

I'm not suggesting organizations should cancel their threat feeds or throw out their Threat Intelligence Platforms. The raw material is important, and the tools that collect, normalize, enrich and correlate it can make the process considerably easier.

But we should probably be more honest about what we're buying.


If someone sells me a general feed containing threat indicators, they're selling me threat data. If they've analyzed, enriched and curated that information before sending it to me, they're selling me something considerably more useful. There may have been some very good intelligence work involved in creating it.


What they're generally not selling me is finished Cyber Threat Intelligence for my organization. They can't. They don't know enough about my organization to do that.


Starting a Cyber Threat Intelligence program by asking which feeds we should ingest is backwards. Start with the questions you need answered. Then figure out what information you need to answer them.


You can buy threat data. You can buy analysis. You can buy tools that help process both. But somebody still has to turn those things into intelligence for your organization.

 
 
 

Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating
bottom of page