Tuesday, 13 June 2023
The Power of Collective Intelligence: Leveraging Threat Intelligence to Protect Against Cyber Threats
Thursday, 17 November 2022
What Is Threat Modeling, and What Are Its Most Important Advantages?
What Is Threat Modeling?
What Are the Types of Threat Modeling?
What Are the Advantages of Threat Modeling?
Sunday, 9 October 2022
How to Identify Network Security Threats and Vulnerabilities
What Is a Network Threat?
What Are Network Vulnerabilities?
What Are the Types of Network Security Threats?
What Are the Main Types of Security Vulnerability?
Learn More About Risk and Vulnerability Assessment with C|ND
Tuesday, 28 June 2022
What Is Threat Modeling?
Data breaches cost companies USD 8.64 million on average (Johnson, 2021), but many companies report they don’t have adequate protection against these vulnerabilities because there aren’t enough IT security professionals to help. The shortage of cybersecurity professionals leaves these organizations vulnerable to costly data breaches.
Threat modeling is a technique cybersecurity professionals use to identify security vulnerabilities in a company’s IT infrastructure and develop techniques to protect its resources. This guide explores cyber threat modeling and explains which threat modeling skills and tools companies need most.
How Cybersecurity Professionals Use Threat Modeling
Cyberattacks are getting more sophisticated and causing more damage to companies’ systems by the day. Security professionals use a structured process to identify the threats that plague organizations.
A threat intelligence professional’s goal is to identify potential cyberthreats and determine their impact. Once the threat intelligence analyst has this information, they can strategize how to prevent each type of attack. Security teams use a process called threat modeling to identify the areas of the organization’s systems and networks that are most vulnerable to attack.
The Cyber Threat Modeling Process
Cybersecurity professionals have several objectives they must meet to evaluate whether they’ve successfully mitigated a risk.
Define Scope
Determining scope helps narrow the focus to a specific area. Attempting to tackle too broad an area may cause analysts to miss vulnerabilities. Often, analysts focus on one or two areas of the system at a time.
Decompose the System
The threat analysis itself starts with decomposing the system. Security analysts must understand every event or action that takes place in the system. Their research highlights the following information.
External Dependencies
External dependencies represent systems outside the target system. For example, an external dependency could be:
◉ A system within the organization, such as a customer relationship management or human resources information system
◉ A system at a third-party vendor or business partner that provides information to the target system, such as updated information from a supplier’s inventory database
Entry and Exit Points
Entry points represent the specific locations where an attacker could enter the system. An example entry point is input fields on a web form. Exit points define where data leaves the system. Entry and exit points define what is known as the “trust boundary.”
Assets
When an attacker targets a system, they have a goal in mind—often, this is access to a particular organizational asset. For example, a malicious hacker may want a list of a company’s customers and each customer’s personal information.
Trust Levels
Trust level represents specific access rights for the system. Threat intelligence analysts cross-reference these access rights against the entry points and exit points. This enables them to see what privileges an attacker needs to interact with to access the asset.
Data Flow
Threat intelligence professionals create data flow diagrams to obtain a high-level picture of the path of information as it flows through the system. These diagrams show analysts what happens to the data at each step.
Identify Threats
At this stage, the analyst chooses a threat model. A threat model represents the process analysts use to pinpoint weak spots in the system. Two of the most common threat models are:
◉ STRIDE. The STRIDE model—an acronym for six threat categories (Spoofing identity, Tampering with data, Repudiation of threat, Information disclosure, Denial of service, and Elevation of privilege)—applies a general set of rules to evaluate a system and identify common vulnerabilities (Geib et al., 2022).
◉ Attack trees. Attack trees represent a graphical way of attacking a system in tree form. The root is the goal, and leaves are possible methods of achieving that goal. Each branch represents a separate attack.
List and Prioritize Threats
In this stage, the analyst creates a list of threats based on the risks the threat modeling identifies. Each risk represents what the company must fix to secure the system.
Mitigate Risk
Cybersecurity professionals share the list created in the previous step with the appropriate parties in the organization to mitigate risks. Common fixes include:
◉ Operating system updates
◉ Code changes
◉ Hardware updates for the network
Validate Outcomes
After addressing risks, the analyst verifies that the solutions work. They perform another evaluation of the system to confirm the results.
Threat Modeling Tools
Manual threat modeling is generally too time consuming for threat intelligence analysts. Instead, they rely on cyber threat modeling tools to speed up the process. These tools make the process more efficient and create accurate documentation of the outcome. Analysts have a variety of options for tools to help with this process.
Cairns
Cairns is a web-based tool that enables users to create attacker personas. The persona includes information such as attack goals, resources the hacker may use, and possible attack paths. The tool automatically spots attack patterns and recommends mitigation strategies.
IriusRisk
IriusRisk is a questionnaire-based system that asks analysts a set of questions to collect data about the system. IriusRisk uses the information from the questionnaire to create a list of potential threats, including suggested mitigation strategies for each threat. IriusRisk integrates with issue trackers such as Jira as well as Continuous Integration/Continuous Delivery tools to run as a part of a DevOps pipeline.
Threagile
Threagile is an integrated developer environment (IDE) tool. It focuses on threat modeling at the coding level. Developers input infrastructure information and risk rules into the tool. Threagile generates models that identify potential weak points. That way, developers can address these weak points before releasing code.
Start Your Threat Modeling Career
From 2020 to 2021, deployment of security technologies rose from 15% to 84% in response to the rise in security threats (Gartner, 2021). This increased investment signals the strong demand for trained threat intelligence professionals equipped to address cyberthreats.
Investing in cybersecurity training is important for success in this field. EC-Council’s Certified Threat Intelligence Analyst (C|TIA) certification is an excellent step in your cybersecurity career journey. The C|TIA program equips learners with skills in threat intelligence data collection, complete threat analysis process methodologies, understandings of various cyberthreats and attack types, and more.
Source: eccouncil.org
Tuesday, 28 September 2021
Potential Security Threats To Your Computer Systems
A computer system threat is anything that leads to loss or corruption of data or physical damage to the hardware and/or infrastructure. Knowing how to identify computer security threats is the first step in protecting computer systems. The threats could be intentional, accidental or caused by natural disasters.
More Info: 312-50: Certified Ethical Hacker (CEH)
In this article, we will introduce you to the common computer system threats and how you can protect systems against them.
What is a Security Threat?
Security Threat is defined as a risk that which can potentially harm computer systems and organization. The cause could be physical such as someone stealing a computer that contains vital data. The cause could also be non-physical such as a virus attack. In these tutorial series, we will define a threat as a potential attack from a hacker that can allow them to gain unauthorized access to a computer system.
What are Physical Threats?
A physical threat is a potential cause of an incident that may result in loss or physical damage to the computer systems.
The following list classifies the physical threats into three (3) main categories;
◉ Internal: The threats include fire, unstable power supply, humidity in the rooms housing the hardware, etc.
◉ External: These threats include Lightning, floods, earthquakes, etc.
◉ Human: These threats include theft, vandalism of the infrastructure and/or hardware, disruption, accidental or intentional errors.
To protect computer systems from the above mentioned physical threats, an organization must have physical security control measures.
The following list shows some of the possible measures that can be taken:
◉ Internal: Fire threats could be prevented by the use of automatic fire detectors and extinguishers that do not use water to put out a fire. The unstable power supply can be prevented by the use of voltage controllers. An air conditioner can be used to control the humidity in the computer room.
◉ External: Lightning protection systems can be used to protect computer systems against such attacks. Lightning protection systems are not 100% perfect, but to a certain extent, they reduce the chances of Lightning causing damage. Housing computer systems in high lands are one of the possible ways of protecting systems against floods.
◉ Humans: Threats such as theft can be prevented by use of locked doors and restricted access to computer rooms.
What are Non-physical Threats?
A non-physical threat is a potential cause of an incident that may result in;
◉ Loss or corruption of system data
◉ Disrupt business operations that rely on computer systems
◉ Loss of sensitive information
◉ Illegal monitoring of activities on computer systems
◉ Cyber Security Breaches
◉ Others
The non-physical threats are also known as logical threats. The following list is the common types of non-physical threats;
◉ Virus
◉ Trojans
◉ Worms
◉ Spyware
◉ Key loggers
◉ Adware
◉ Denial of Service Attacks
◉ Distributed Denial of Service Attacks
◉ Unauthorized access to computer systems resources such as data
◉ Phishing
◉ Other Computer Security Risks
To protect computer systems from the above-mentioned threats, an organization must have logical security measures in place. The following list shows some of the possible measures that can be taken to protect cyber security threats
To protect against viruses, Trojans, worms, etc. an organization can use anti-virus software. In additional to the anti-virus software, an organization can also have control measures on the usage of external storage devices and visiting the website that is most likely to download unauthorized programs onto the user’s computer.
Unauthorized access to computer system resources can be prevented by the use of authentication methods. The authentication methods can be, in the form of user ids and strong passwords, smart cards or biometric, etc.
Intrusion-detection/prevention systems can be used to protect against denial of service attacks.There are other measures too that can be put in place to avoid denial of service attacks.
Source: guru99.com
Tuesday, 6 April 2021
What Are The Most Important Types Of Cyber Threats?
A cyber threat is a malicious act that seeks to steal data, damage data, and disrupt digital life in general. Being said that, the different types of cyber threats include data breaches, computer malware, and viruses, and Denial of Service attacks among others. Cyber threats also aim to gain unauthorized access to systems and networks to steal, damage, or disrupt intellectual property or other forms of sensitive data. Thus, making it necessary for a business leader to have a basic understanding of the cyber threat.
In this article, we will discuss the cyber threat, different types of cyber threats, and various sources of cyber threats.
What Is Cyber Threat?
The internet has evolved exponentially over the last decade or two. With businesses around the world going digital and putting their resources, information, and sensitive data on the internet, many people are looking to get their hands on it through malicious techniques. This process of getting access to the organizational information and system in an unauthorized manner is referred to as a cyber threat. Being said that, the organization makes use of cyber threat intelligence to deal with and stop such malicious attempts at their networks and systems.
Types of Cyber Threats
The following are the different types of cyber threats that various organizations have to deal with daily using different threat modeling and threat intelligence models.
1. Malware
Malware is malicious software such as ransomware, spyware, worms, and viruses. Such a type of cyber threat is activated when the user clicks on the malicious link sent to them through an email attachment. Therefore, leading to the installation of damaging software on their system. Being said that, once the malware is activated, it can block access to key network components, disrupt system operation and covertly obtain sensitive information among others.
2. Denial of Service
It is a type of cyber threat that floods the network or the computer so that it cannot respond to different requests. Denial of Service is very much similar to Distributed Denial of Service attack. However, in this case, the attack originates from the computer network. Being said that, attackers often use a flood attack for disrupting the handshake process and carries out a Denial of Service attack. However, other techniques might also be used for disrupting the service of the network.
3. Phishing
Phishing is another type of cyber threat which is commonly used by attackers to gain access to confidential information and data. In this technique, attackers make use of fake communication such as email to trick users into the opening and carrying out the instructions inside the email. For instance, providing them with credit card numbers. The overall goal of this type of cyber threat is to steal the sensitive information of the user.
4. Advanced Persistent Threats
This is another type of cyber threat that organizations monitor continuously using threat modeling and threat intelligence. In such types of attacks, unauthorized users gain access to the network or system and remain there without being detected for an extended period.
Sources of Cyber Threats
While identifying a cyber threat, more than the technology used in attack, important is to know who is behind the threat? Though the technology is ever evolving, the sources of cyber threat have remained the same. Someone falling for a clever trick suggests that there is always a human element involved. The real source of cyber threat would be a motive that lies behind every attack.
With the evolving role that the internet is playing in the growth of businesses around the world, cyber threats can originate from a variety of places, people, and contexts. Being said that, the following are the most common sources of cyber threats that one should know about.
1. Individuals who create attack vectors using their tools and techniques
2. Criminal organizations which look like normal corporations but develops attack vectors and executes attacks
3. Terrorists
4. Nation-states
5. Business competitors
6. Organized crime groups
7. Industrial spies
These are some of the most important sources of cyber threats that one should look after and know about.
Source: eccouncil.org
Sunday, 27 December 2020
OCTAVE Threat Modeling – All You Need to Know
With the increase in advanced persistent threats (APTs), defenders are constantly trying to safeguard an organization’s information systems by tailoring their defense mechanisms to preempt future attacks. As a result, organizations are recognizing the value of cyber threat intelligence and are planning to increase threat intelligence spending in upcoming quarters.
In cybersecurity, no prediction is perfect, but if we have the correct threat modeling protocols in place, then it provides a context to the gathered intelligence and helps analysts to identify, classify, and prioritize threats.
What Is the OCTAVE Threat Model?
OCTAVE is a threat modeling framework to assess and manage risks in an organization in the event of a data breach. It follows a comprehensive assessment methodology that allows an organization to identify the assets that are important and the threats and vulnerabilities in those assets. What information is at risk can be determined by putting the information on assets, threats, and vulnerabilities together. This helps the organization to design and implement a defense strategy to minimize the overall risk exposure of its information assets.
OCTAVE Threat Model Background
OCTAVE was developed in 2001 at Carnegie Mellon University (CMU) Software Engineering Institute (SEI) in collaboration with CERT for the U.S. Department of Defense. It’s useful for creating a risk-aware corporate culture and is highly customizable as per the organization’s specific security objectives and risk environment. There are 2 versions of OCTAVE:
1. OCTAVE-S, a simplified methodology for smaller organizations that have flat hierarchical structures, and
2. OCTAVE Allegro, a more comprehensive version for large organizations or those with multilevel structures.
Importance of OCTAVE Threat Model
OCTAVE is a flexible and self-operated risk assessment method. People from the business units and the IT department work together to address the security needs of the organization. The team defines the current state of security, identify risks to critical assets, and create a security strategy. Unlike other risk assessment methodologies, the OCTAVE model is driven by operational risk and security practices — not technology. The purpose of the OCTAVE model is to allow organizations to:
1. Assess and manage information security risks.
2. Take decisions based on the risks.
3. Protect key information assets.
4. Effectively communicate security information.
How to Implement the OCTAVE Threat Model
Phases of the OCTAVE Threat Model
Saturday, 12 December 2020
Trike Threat Modeling as a Risk-Management Tool
Why Trike?
Requirement Model
Risk Assessment
Data Flow Diagram
Assigning Risk Values
Thursday, 10 December 2020
Threat Data Collection Through Cyber Counterintelligence (CCI)
Introduction
Cyberspace is an unpredictable domain, with cybercriminals constantly devising advanced techniques and technologies to exploit system vulnerabilities and networks.
In a recent Microsoft survey, 22% of organizations across the world ranked cyber risks to be the top concern over other significant business risks. A lack of robust cyber defense led to companies being extorted by cybercriminals. To this end, many organizations have started to explore threat intelligence to better understand the motive/techniques behind an attack and mount a counterattack before it escalates.
As the famous saying goes, “The best defense is a good offense.” In this article, we will breakdown everything you need to know about cyber counterintelligence and how to implement it.
What Is Threat Intelligence?
Threat intelligence is essentially data analysis using tools and techniques to gather information about existing and emerging cyber threats that might target an organization and mitigate risks. Furthermore, cyber intelligence provides organizations with a faster and more informed security decision in an effort to change their behavior from reactive to proactive for combatting attacks.
Cyber Threat Data Collection
Data acquired on IOC systems may be malicious and can compromise the network security system of an organization, which can leave sensitive data compromised. That’s why organizations need to routinely collect real-time intelligence data from both internal and external sources. One of the important steps for creating cyber threat intelligence is to gather relevant data threats for analysis and processing.
The data collection is conducted via several sources by using the predefined TTP (Tactics, Techniques, and Procedures).
Sources of Threat Data
Internal Sources: These are network logs, security lapses, reports on past cyber incidents, risk analysis reports, etc.
External sources: These include threat feeds from communities and forums, the dark web, open web, and other online sources.
Tools & Techniques for Data Collection
Here are some tools that you can use to gather data for threat intelligence.
◉ Human intelligence such as interrogation, interviews, and social engineering.
◉ Open-source intelligence (OSINT) such as web services, emails, search engines, URL/IP/DNS lookup, website footprinting, etc.
◉ Indicators of Compromise (IoCs) like internal, external, and custom built IoCs.
◉ Cyber counterintelligence such as passive DNS monitoring, malware sinkholes, honeypots, adversary’s infrastructure, YARA rules, etc.
◉ Existing malware analysis.
Cyber Counterintelligence
Cyber counterintelligence (CCI) is the umbrella term for the efforts taken by an organization to prevent cyberattacks on its infrastructure from adversaries. These include competitor intelligence advances, malicious actors, nation-states, or criminal organizations that are involved in sensitive information gathering and exploitation of an organization’s IT weaknesses.. Furthermore, while the major objective of cyber counterintelligence is to defend, much of the methods are usually offensive.
This simply means that for cyber counterintelligence to be effective, it must be on both the defensive and offensive sides.
Data Collection Through Cyber Counterintelligence
CCI’s main purpose is to identify, degrade, neutralize, and protect organizations from adversarial intelligence activities. This can be done by utilizing both passive and active counterintelligence approaches to gather data.
Defensive cyber counterintelligence
Defensive cyber counterintelligence is used to identify and understand cyber threats and minimize the threat landscape a cyber attacker can exploit. This helps protect the organization against vulnerabilities from internal and external threats. Cyber intelligence analysts can gather data through a variety of venues, such as penetration testing, threat hunting, vulnerability assessment, threat management, etc.
Offensive cyber counterintelligence
Offensive cyber counterintelligence is a term used for active interaction with attackers. This includes gathering information about the hostile intelligence gathering process, capabilities, and techniques, and devising deceit tactics to trick attackers into thinking they have successfully accessed confidential information.
There are numerous ways of data collection using offensive cyber counterintelligence like honeypots, honeynets, sock puppets, false flags, publishing false reports and information to deceive adversarial intrusion attempts, and so on. Moreover, these efforts can be performed from both inside and outside your networks.
Source: eccouncil.org
Tuesday, 13 October 2020
How to Build a Cyber Threat Intelligence Team
Nowadays, cyber threats are rapidly evolving because of the increased sophistication of attacks and motivations behind an attack. However, organizations can protect themselves from cyber threats by hiring expertise available outside of the organization. Security professionals and executives need threat intelligence to get more information about cyber threats that go beyond the physical edge of your network.
What Is Cyber Threat Intelligence?
Cyber threat intelligence is a cybersecurity branch that deals with collecting and analyzing information about potential attacks currently targeting the organization. A cyber threat intelligence analysis’s major goal is to get in-depth information on threats that can cause greater risk to an organization’s infrastructure.
What Is Cyber Threat Analysis?
Cyber threat analysis is how the knowledge of an organization’s internal and external information weakness is tested against real-world cyberattacks. The cyber intelligence analysis will provide the organization with the best practices to maximize their security tools without turning back to usability and functionality conditions. It is the method that cybersecurity threat analysts use to determine the components of a system that needs protection and the type of security threats to protect the component from. Information from threat analysis is also used to determine the strategic locations in network architecture and design to implement security effectively.
How Do You Implement Cyber Threat Intelligence?
Certain challenges are associated with implementing cyber threat intelligence data processes. However, it is possible to carry out a cyber threat analysis. Furthermore, cybersecurity threat analysts can easily accelerate the detection and response to control potential threats proactively. Some of the rules that cybersecurity threat analysts can follow are stated below.
◉ Prepare a plan
◉ Identify the assets you want to protect
◉ Build the right team
◉ Deploy the right tools and techniques
◉ Integration with existing systems
◉ Disseminate the intelligence with the appropriate stakeholders
How to Build a Threat Intelligence Team?
You can build a cyber threat intelligence team and define their roles and responsibilities according to their skillsets and core competencies. You can create a talent acquisition strategy and define the needed skill set, professional certifications, qualifications, and positioning of the threat intelligence team.
Saturday, 25 July 2020
How to Identify Network Security Threats and Vulnerabilities?
It is no secret that no system, device, website, or network, are above network security threats, risks, and vulnerabilities. Network security is a critical aspect of any organization, and it is possible to become careless with your security approach as time goes by. This is why there is a growing need for Certified Network Defenders.
Every business needs a Certified Network Defender that is capable of executing a thorough analysis, through specific techniques and technology that would be exclusive to each organization. EC-Council offers a number of certification programs in the field of Ethical Hacking, so your organizational data is as safe as possible from threats and potential malicious attacks.
What are network security threats?
A network security threat is an effort to obtain illegal admission to your organization’s network, to take your data without your knowledge, or execute other malicious pursuits. Your network security is at risk or vulnerable if or when there is a weakness or vulnerability within your computer network.
Some network security threats are intended to upset your organization’s processes and functionality instead of noiselessly collecting information for espionage or financial motives. With the extensive use and accessibility of the internet, comes the increase in all kinds of threats. The most prevalent technique is the Denial of Service (DoS) attack.
Having the essential mechanisms and tools to identify and categorize network security threats and irregularities in your system or network is critical. You don’t know the importance of a Certified Network Defender, until your computer network and other systems fall victim to an unidentified attack.
















