{"id":20016,"date":"2018-07-03T15:45:25","date_gmt":"2018-07-03T14:45:25","guid":{"rendered":"http:\/\/www.intelligentcio.com\/africa\/?p=20016"},"modified":"2018-07-03T15:45:25","modified_gmt":"2018-07-03T14:45:25","slug":"applying-threat-intelligence-to-secure-the-enterprise-network","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/africa\/2018\/07\/03\/applying-threat-intelligence-to-secure-the-enterprise-network\/","title":{"rendered":"Applying threat intelligence to secure the enterprise network"},"content":{"rendered":"<p><em><strong><span style=\"font-family: 'Arial',sans-serif\">By Ashraf Sheet, Regional Director, Middle East and Africa at Infoblox<\/span><\/strong><\/em><\/p>\n<p><span style=\"font-size: 12.0pt;font-family: 'Arial',sans-serif\">In a world in which cybercriminals are becoming increasingly stealthy and using increasingly sophisticated techniques, from ransomware to DNS hijacking, it is becoming more difficult, more expensive and less effective for businesses alone to defend themselves against threats.<\/span><\/p>\n<p><span style=\"font-size: 12.0pt;font-family: 'Arial',sans-serif\">According to <span style=\"color: windowtext;text-decoration: none\">research<\/span> recently carried out in the US and EMEA by the Ponemon Institute on behalf of Infoblox, more organisations than ever are reaching out to sources including their peers, industry groups, IT vendors and government bodies for threat intelligence data. This increase could be attributed to the fact that two thirds of the IT security practitioners surveyed said they now realised that threat intelligence could have prevented or minimised the consequences of a cyberattack or data breach.<\/span><\/p>\n<p><span style=\"font-size: 12.0pt;font-family: 'Arial',sans-serif\">However, despite this exchange and use of threat intelligence, the majority of respondents to the survey claimed not to be satisfied with the current quality of the data.<\/span><\/p>\n<p><strong><span style=\"font-size: 12.0pt;font-family: 'Arial',sans-serif\">A question of trust<\/span><\/strong><\/p>\n<p><span style=\"font-size: 12.0pt;font-family: 'Arial',sans-serif\">The most important objectives of a successful threat intelligence programme are to enhance an organisation\u2019s overall security posture, improve its incident response and quickly detect attacks. However, less than a third of respondents rated their company\u2019s defence against cyberattacks as highly effective, and only a quarter thought the same about their company\u2019s process of using internal sources such as configuration log activities.<\/span><\/p>\n<p><span style=\"font-size: 12.0pt;font-family: 'Arial',sans-serif\">Although IT security practitioners are increasingly satisfied with their ability to obtain threat intelligence, there are still a number of concerns about how the information is obtained; that it\u2019s not timely, for example, or that it\u2019s too complicated to ensure speed and ease of use. Much of this dissatisfaction may be due to the way in which the data is actually sourced.<\/span><\/p>\n<p><span style=\"font-size: 12.0pt;font-family: 'Arial',sans-serif\">While two fifths of companies consolidate their threat intelligence data from a number of different sources, most engage in informal peer-to-peer exchange of threat intelligence, rather than taking a more formal approach, such as using a threat intelligence exchange service or joining a consortium. What\u2019s more, a similar number reported using manual methods to consolidate their data, often due to a lack of qualified staff.<\/span><\/p>\n<p><span style=\"font-size: 12.0pt;font-family: 'Arial',sans-serif\">Regardless of the approach used, however, around three in five respondents claimed not to trust the sources of intelligence they used. It\u2019s not surprising, therefore, that companies will often use fee-based threat intelligence because they think it\u2019s better quality, that it\u2019s more effective in stopping security incidents and because they don\u2019t have confidence in free sources.<\/span><\/p>\n<p><span style=\"font-size: 12.0pt;font-family: 'Arial',sans-serif\">Trust is an issue when it comes to giving too, as well as receiving. While around three quarters of organisations provide threat intelligence in addition to using data from other sources, around half claim that the potential liability of sharing meant they would only partially participate in a threat intelligence exchange programme. It\u2019s for this reason perhaps, that organisations prefer sharing with a neutral party or a trusted intermediary rather than sharing with organisations directly, indicating the need for a trusted, neutral exchange platform.<\/span><\/p>\n<p><strong><span style=\"font-size: 12.0pt;font-family: 'Arial',sans-serif\">Automation and efficiencies<\/span><\/strong><\/p>\n<p><span style=\"font-size: 12.0pt;font-family: 'Arial',sans-serif\">Indicators such as suspicious host names, IP addresses and file hashes, threat intelligence will typically be disseminated internally through alerts. However, security personnel in around two thirds of organisations are spending more than 50 hours a week responding to these alerts, when their time could be better spent proactively hunting for signs of criminal activity.<\/span><\/p>\n<p><span style=\"font-size: 12.0pt;font-family: 'Arial',sans-serif\">Currently, only half of the companies surveyed use automated solutions to investigate threats, with just one in five claiming to use advanced technology such as AI and machine learning. Interestingly, the use of slow manual sharing processes were also cited by over a third of businesses as a reason for not participating in the exchange of threat intelligence information.<\/span><\/p>\n<p><span style=\"font-size: 12.0pt;font-family: 'Arial',sans-serif\">The most important objective of an organisation\u2019s threat intelligence activities is to quickly detect attacks and improve incident response. For the intelligence to be actionable it needs to be received in a timely manager, immediately prioritising the threats contained. However, as shown above, a large number of organisations are not satisfied with the timeliness of the intelligence, believing that it becomes stale within a matter of minutes.<\/span><\/p>\n<p><span style=\"font-size: 12.0pt;font-family: 'Arial',sans-serif\">With so many inefficient manual processes in place both in compiling and responding to threat intelligence, it\u2019s clearly time for businesses to embrace more automation or, at the very least, consider a hybrid approach.<\/span><\/p>\n<p><strong><span style=\"font-size: 12.0pt;font-family: 'Arial',sans-serif\">Taking measurements<\/span><\/strong><\/p>\n<p><span style=\"font-size: 12.0pt;font-family: 'Arial',sans-serif\">A threat intelligence provider is only ever as good as the information it provides, of course. Just over two fifths of businesses will use their threat intelligence programme to define and rank levels of risk of not being able to prevent or mitigate threats using indicators based on uncertainty about the intelligence\u2019s accuracy, and an overall decline in the quality of the provider\u2019s services. <\/span><\/p>\n<p><span style=\"font-size: 12.0pt;font-family: 'Arial',sans-serif\">A similar number will evaluate the quality of a threat intelligence provider and the information it delivers based on its ability to prioritise threat intelligence and deliver it in a timely manner. A similar number again will evaluate the threat intelligence itself using a risk score based on factors including whether it is actionable, confidence in its source, and the veracity of the threat indicator and the indicator type.<\/span><\/p>\n<p><span style=\"font-size: 12.0pt;font-family: 'Arial',sans-serif\">More than anything, the survey reveals a real need for actionable, timely and effective threat intelligence sharing. What\u2019s more, many respondents to the survey said their organisations are using threat intelligence in a non-security platform, such as DNS, indicating that we\u2019re now seeing a blurring of lines between what are considered security tools and what are considered pure networking tools. Securing today\u2019s networks means using threat intelligence for defence-in-depth, plugging all gaps, and covering all products. <\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>By Ashraf Sheet, Regional Director, Middle East and Africa at Infoblox In a world in which cybercriminals are becoming increasingly stealthy and using increasingly sophisticated techniques, from ransomware to DNS hijacking, it is becoming more difficult, more expensive and less effective for businesses alone to defend themselves against threats. According to research recently carried out [&hellip;]<\/p>\n","protected":false},"author":28,"featured_media":20019,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[6,399,54],"tags":[496,859,449,160,847,5830,3926,161,169,392,162,285,849,5831],"class_list":["post-20016","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-insights","category-more-news","category-research","tag-ai","tag-cyberattacks","tag-cybercriminals","tag-dns","tag-emea","tag-hijacking","tag-hybrid","tag-infoblox","tag-ip","tag-machine-learning","tag-network","tag-ponemon-institute","tag-threat-intelligence","tag-trust"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts\/20016","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/users\/28"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/comments?post=20016"}],"version-history":[{"count":1,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts\/20016\/revisions"}],"predecessor-version":[{"id":20018,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts\/20016\/revisions\/20018"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/media\/20019"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/media?parent=20016"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/categories?post=20016"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/tags?post=20016"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}