Cyber Threat Intelligence An Introduction

Cyber Threat Intelligence An Introduction


Over the course of 40 years the Internet has developed so much that today nearly half of the Earths population are using it (more precisely 46.1% ). People now have an access to enormous amounts of data that was unavailable before. These possibilities eventually brought sensitive information about a large number of individuals up there as well. They are mostly uploaded by the same person voluntarily, with some of it becoming publicly available to everyone who visits that particular site (ex. Pictures on a social network). Other, "sensitive" kind of information stay hidden from prying eyes, such as credit card info, passwords and so on... Unfortunately, information that are not public are not entirely safe either and can be sometimes accessed by a third party. To prevent that from happening, there are ways to protect data from attackers. To effectively defend sensitive information you need to be aware of the potential attacks.
Cyber Threat Intelligence (CTI) is in charge of that. In its core meaning, Cyber Threat Intelligence provides analyzed and refined information about potential outside attacks. Its main purpose is to help organizations understand the risks of the most common and severe external threats (ex. Zero-day) so they can protect themselves from outside attacks.

To study specifically what Cyber Threat Intelligence does, we need to understand these several terms:
A hacker is a skillful computer expert that can bypass the security of a computer system by using its bugs and exploits. While this definition intuitively categorizes hacker as a "bad" person, in reality they are split into 3 groups: White ("good") hats, Grey ("neither good nor bad") hats and Black ("bad") hats which we will refer to as attackers.
A bug in software terms is a fault in a program that causes an unexpected behavior. If we want to extend this definition in that way that it includes hardware and human mistake, then the correct term would be vulnerability. 
An exploit is a piece of code that takes advantage of a vulnerability of a software in order to change its behavior.
Another term worth mentioning is Zero-day. It represents a unreported bug that can be exploited by attacker.
Social Engineering is a psychological manipulation of people in order to give out sensitive information to the attacker. There are several attack types which will be covered later in my research.

In last couple of years, the defense of a computer system has become more important than ever. Attackers are using more and more sophisticated ways of exploits which represents real problem for most organizations. Seeing that today managing a high-end company will attract the most attention from attackers, logically it will require the best possible defense. Thats where CTI comes to take place.

In my next several posts, i will research the way that CTI works as well as trying to figure out patterns in attackers behavior by studying a specific group of attackers.





download file now