Skip to main content

Posts

Lessons from Crumpton's Art of Intelligence

A few months ago, I finished reading Henry Crumpton's book, The Art of Intelligence: Lessons from a Life in the CIA's Clandestine Service . It was simply amazing and I highly recommend it for all the insights it adds to hidden conflicts the public will never fully understand. I will not be writing a review of the book however, but try to mirror some of the key points from the book into what we see today in the information security spectrum. While I would never attempt to equate the life and death struggles of patriots to the things we do in InfoSec, I believe in drawing from other realms to further our understanding of problems. Diverse Backgrounds (pg 64) "There was an overwhelming consensus, according to James, that whether in operations or analysis, the best officers were usually those who had accumulated a broad range of diverse and enlightening experiences prior to joining government service. These men and women developed more open, more empathetic views of othe...

MIRCon 2013 - It's a wrap

MIRcon 2013 - What Really Happened My first MIRcon is in the books and I have to say it was a great experience from start to finish. The agenda, food, staff, accommodations, and attendees were all top notch. Some people may complain based on the fact that this year’s conference was the first year they started charging, however I would find it very hard to believe it was for any profit, but more to slightly offset the costs which I think far exceeded any registration fees. I also really love the fact that the conference is relatively small. I believe this is want people want compared to the horribly overcrowded RSA & Blackhat experience. I also heard they were considering adding a more technical 3 rd track and I think that would be a great idea. Also, how about hosting a capture the attacker event? How cool would that be. Richard Bejtlich, Chris Bream, Kevin Mandia, and Grady Summers all brought their A game and delivered a home run in terms of their speaking and moder...

Threat Intelligence Learning Plan

So over the last few years, there seems to be a trend of non-DIB companies starting to build internal threat intelligence teams and a big spike in security companies offering it as a subscription service. Ten years ago a paid service got you vulnerability alerts, some open source geopolitical information, and dated commodity botnet information. This space has matured quite a bit, even though some providers are simply repackaging free indicator feeds and CVEs as threat intelligence. I think the value proposition is there by using intelligence to reduce the dwell time of an adversary and potentially on good day thwarting the attacks from the start. I think the formation of strong, sector specific intelligence sharing groups will be key to being better defenders. Having had access in the past to great intelligence via clearances, I know what a huge advantage it is. Hence my strong interest in the subject. At the same time, I have little traditional intelligence analysis experience. Mo...

SANS Cyber Threat Intelligence Summit 2013

     I recently attended the first SANS CTI Summit in Washington DC. While there was plenty of brain power in the room, and good discussions were to be had, overall it was just ok. There was a big focus on what CTI is and why you should be doing it, or at least consuming it. There wasn't enough discussion, aside from one talk, on how you should be doing it. It basically reinforced my beliefs that this is still very much a small, closed off club of insiders, where nobody is sharing tradecraft. I love that SANS is getting involved in this space though, and it sounds like Mike Cloppert will be writing a SANS course on Threat Intelligence in the future. I would very much be interested in that and I expect it would sell out quickly.      Mike Cloppert opened the day by discussing the old vulnerability centric approach focused on reducing attack surface as opposed to the new threat centric model focused on reducing the risk of the actual threats affecting your ...

The Broken 1.0

So as we are about to close out 2012, many of us in the IT Security community look around and try to assess where we were, what we have accomplished this year, and what is next. I’ve been working in IT since the late 90s, with a focus on security for much of that time. Most of my work has been in large private sector companies, with a brief, but very rewarding stint working for the government. To me while much has changed, many of the core issues remain today as they were back then. Our security condition has actually worsened in many cases. While that is up for debate, no one can argue the pace, sophistication, and impact of major cyber events related to nation-sponsored, organized crime, and hacktivism threats has increased exponentially in the last 4-5 years. This new normal has been applicable to the government and defense industrial base for a long time, but really surfaced in the private sector around ~2007. You would assume that with all that increased attention, dollars ...