enterprisesecuritymag

| | Jan-Feb 2017ENTERPRISE SECURITY8Getting In Front: Thinking Differently about Threat IntelligenceBy Tim Callahan, SVP, Global Security, & Global CSO, Aflacany information security professionals will remember when we relied primarily on a defensive posture to protect our organizations from cyber threats. We spoke about the layers of defense and took comfort if we could architect in three or four layers to keep the bad guys out. However, the criminals found the soft underbelly of defenses and began attacking us ­ using innocent technology users through social engineering, phishing and other methods to get through. This meant security professionals had to start looking at security from a different perspective. Ideas began flowing about new ways to get ahead of criminals, including ethical hacking ­ assessing our environment from the criminals' standpoint. By looking at our network and systems from an outside view, we could determine the vulnerabilities criminals could find and fix them. This is a great concept, but we began to find there was an ever-increasing string of vulnerabilities and, in some cases, it was difficult or impossible to patch without rewriting an application. So, we put application firewalls in place to help mitigate or hide vulnerabilities. It seems the in-depth security defense philosophy has become more of a "whack-a-mole" concept. Therefore, we have to find a way to not just react to a threat, but to get out in front it.One of the most promising ways to get in front is to implement a threat intelligence program that includes predictive analysis and dark web inspection. What do we mean by intelligence? Einstein said, "The true sign of intelligence isn't knowledge, but imagination." He wasn't specifically talking about intelligence in the same sense, but there is a principle here. To be useful, intelligence isn't just knowledge. Dictionary definitions say: "the ability to acquire and apply knowledge and skills" or "the collection of information of military or political value." Threat intelligence then isn't just knowledge or information. What is the difference?Intelligence begins with information, but information in itself isn't intelligence. Threat intelligence must be specific and actionable. A simplistic example may be: "The gray-haired hacking group is using IP 192.168.1.1 to in My OpinionM Tim Callahan
< Page 7 | Page 9 >