Home / Other / Threat Intelligence Awakens: Intelligence Data on Threats Needed

Threat Intelligence Awakens: Intelligence Data on Threats Needed

Everywhere something is being observed or someone is being spied on, but it has always been this way; it just seems to the average worker, manager, or anyone else that due to technology, it is more pronounced today than ever. Sometimes it seems that companies are almost put in a position, or soon will be, that they must establish their own counterintelligence services to prevent attacks on themselves, whether due to cybercrime or industrial espionage from competitors or actions by criminal organizations against them.

What is happening to others…

Of course, there is no need to panic or fuel conspiracy theories because, as Miroslav Krleža once said, ‘never has it been that it hasn’t been, and never will it be that it won’t be’ (which is certainly easier to write than to say for someone not from Zagorje), so it is with attacks on companies – the economy will exist even after them. However, the saying ‘just not me, how will it be’ is often used, although, in reality, we need to think that we are always a potential target. Thus, this wisdom ultimately leads us to think in advance about who could attack us (our company) and why. Especially since opponents are exceptionally well hidden, often because they use legitimate credentials and tools, making it difficult for defenders to detect security breaches. It sounds somewhat eerie that the fastest cyber attack to date was completed in two minutes and seven seconds. In other words, you went to the restroom during the watch, and the enemy has already penetrated your company.

The Smallest and Most Vulnerable

The term threat intelligence (TI) is already known worldwide. It refers to intelligence data that is collected and analyzed, after which companies react based on their security services’ suggestions. The sooner, the better, although we know of many cases where they were late to react or reacted too late. The most vulnerable are small companies that do not have enough money, and their managers are likely not even aware that they need to take preventive action against attacks. It seems to us that even the responsible investigative bodies do not have a particularly great interest in investigating attacks and espionage against smaller companies. However, every company can, if nothing else, hire specialized IT companies to do the job of collecting intelligence data on possible attacks or espionage by organized criminals or competitors.

Explosion of AI Threats

Searching the internet, we see that threats exploded last year, particularly those supported by generative artificial intelligence. With all its advantages, generative AI can also create false information, images, or videos, thus aiding manipulation, deception, and abuse, which can have serious consequences for society and individuals. With the help of artificial intelligence, attackers use new techniques for faster breaches such as identity theft, social engineering, and purchasing legitimate credentials from brokers to gain access. Tactics such as SIM card swapping, bypassing multi-factor authentication (MFA), and using stolen application programming interface (API) keys for initial access are becoming popular. Unsurprisingly, thieves have adapted and devised new tactical attacks, which all potential victims must consider and thus collect data on potential and actual attackers. We said it is about threat intelligence, i.e., collecting intelligence data to analyze and provide information to the management or director of the company about actions taken against it. Of course, the report also includes a proposal for protection against potential attacks or those that have already begun.

The use of threat intelligence has reportedly become key to the security of every organization. Without information about threats, they say, nothing can be done to defend systems and data

How TI Works

Threat intelligence in a broader sense means collecting and analyzing data and information about attacking activities to use them to build a better defense. It encompasses data such as indicators of compromise (IOC), those about malicious IP addresses, domains, URLs, techniques, tactics, and procedures of attacks, and similar. Unlike TI, cyber threat intelligence (CTI) focuses on cyber threats and primarily deals with incident analysis and attacking tactics and techniques. What the analysis will be depends on the cooperation of the endangered company with those involved in data analysis. As one interlocutor once told us on this topic, a well-posed question is half the answer. Although there is a vast amount of information available about threats, it consists of raw data that, to be a bit blunt, is of no use and requires thorough analysis and cleansing before it becomes intelligence data that can be used to support decision-making.

Supply and Demand

How great the need for this is today is perhaps sufficiently illustrated by the data from Microsoft’s website that its community (as it describes its group of people since it cannot be referred to as a team) of threat intelligence consists of more than eight thousand world-class experts, security researchers, analysts, and threat hunters who analyze 65 trillion signals daily to detect threats and provide timely and relevant insights into client protection. Although TI is still a novelty for us, services of this kind are increasingly in demand. Companies are simply forced into this because, whether they want to or not, as we mentioned, technological capabilities are exploited for good purposes but also for bad. As technology advances, companies will increasingly seek threat intelligence services, which is a step towards establishing counterintelligence services. We do not want to be ominous prognosticators, but its application practically confirms this to us. When we previously wrote on this topic, we received significant help from experts from CARNET, as well as younger cybersecurity specialist Ante Marić (Duplico) and cybersecurity analyst Mate Matijašević (Span), who also mentioned tools used in this process.

It is hard to say which are the best tools for defense against, for example, cyber attacks. Our experts told us that the choice of tools depends primarily on specific needs but also on capabilities. It is desirable that these tools can easily integrate with others to create a security system tailored to the already known model of layered protection.

The TI report implies collecting intelligence data to analyze and provide information to the management or director of the company about actions taken against it. Of course, it also implies a proposal for protection against potential attacks or those that have already begun

Important Tools

There are several particularly important tools, such as SIEM (security information and event management), which collects large amounts of data about events on computers, servers, networks, and applications. This includes login attempts, changes in system configurations, or detection of suspicious activities. Marić explained to us that SIEM is particularly useful because it can correlate different types of data and detect unusual patterns. By visualizing this data, it can alert IT staff about suspicious events. Unlike SIEM, TIP (threat intelligence platform) collects information from various sources across the internet about known cyber threats. This can include data about viruses, malware, hacker groups attacking organizations in specific industries, and similar.

CARNET’s experts told us that they have a plethora of commercial tools available on the market, but they did not want to recommend which is the best, advising users on various open-source tools that are already known to the security community. There is no best tool, they emphasized, because in practice there is not just one solution or tool that offers complete protection. Cybersecurity is an uninterrupted process: establishing, maintaining, measuring, improving, and reinforcing all technical and human aspects of security in a constant cyclical process. In addition to investing in technical protective measures, it is necessary to raise awareness and educate system users about protective measures, cybersecurity hygiene, and proper and secure use of systems. For this, we need clear, understandable, and written rules that illustrate this process and allow easier tracking of the maturity and resilience of systems and users in cyberspace.

Vulnerability Hunters

Threat hunters are often engaged in defense against attacks. This refers to active processes in cybersecurity where trained individuals actively seek, identify, and isolate advanced threats that evade existing security solutions within an organization’s system (company). Often, threat hunting and threat intelligence are applied together. In fact, it is difficult to effectively search for threats without good intelligence data. As Marić told us, just as maintaining a home or car requires regular cleaning and maintenance, IT infrastructure also needs attention to remain safe from cyber threats. In the cyber world, this role is performed by vulnerability management tools that find, assess, and prioritize issues to eliminate even the smallest flaws in an organization’s IT systems. When flaws are found, these tools create detailed reports on which vulnerabilities exist and often describe ways to remediate them.

As it is with the most common cyber threats, so it is with others, including physical ones, so collecting intelligence data in the future may be just one of the key activities of companies. Thus, we have come this far, but we must live with it.

Tagged: