threat intelligence là gì

From Wikipedia, the không lấy phí encyclopedia

Cyber threat intelligence (CTI) is knowledge, skills and experience-based information concerning the occurrence and assessment of both cyber and physical threats and threat actors that is intended đồ sộ help mitigate potential attacks and harmful events occurring in cyberspace.[1] Cyber threat intelligence sources include open source intelligence, social truyền thông intelligence, human Intelligence, technical intelligence, device log files, forensically acquired data or intelligence from the mạng internet traffic and data derived for the deep and dark trang web.

Bạn đang xem: threat intelligence là gì

In recent years, threat intelligence has become a crucial part of companies' cyber security strategy since it allows companies đồ sộ be more proactive in their approach and determine which threats represent the greatest risks đồ sộ a business. This puts companies on a more proactive front - actively trying đồ sộ find their vulnerabilities and prevents hacks before they happen.[2] This method is gaining importance in recent years since, as IBM estimates, the most common method companies are hack is via threat exploitation (47% of all attacks).[3]

Threat vulnerabilities have risen in recent years also due đồ sộ the COVID-19 pandemic and more people working from trang chính - which makes companies' data more vulnerable. Due đồ sộ the growing threats on one hand, and the growing sophistication needed for threat intelligence, many companies have opted in recent years đồ sộ outsource their threat intelligence activities đồ sộ a managed security provider (MSSP).[4]

Process - intelligence cycle[edit]

The process of developing cyber threat intelligence is a circular and continuous process, known as the intelligence cycle, which is composed of five phases,[5][6][7][8] carried out by intelligence teams đồ sộ provide đồ sộ leadership relevant and convenient intelligence đồ sộ reduce danger and uncertainty.[7]

The five phases are: 1) planning and direction; 2) collection; 3) processing; 4) analysis; 5) dissemination.[5][6][7][8]

In planning and directing, the customer of the intelligence product requests intelligence on a specific topic or objective. Then, once directed by the client, the second phase begins, collection, which involves accessing the raw information that will be required đồ sộ produce the finished intelligence product. Since information is not intelligence, it must be transformed and therefore must go through the processing and analysis phases: in the processing (or pre-analytical phase) the raw information is filtered and prepared for analysis through a series of techniques (decryption, language translation, data reduction, etc.); In the analysis phase, organized information is transformed into intelligence. Finally, the dissemination phase, in which the newly selected threat intelligence is sent đồ sộ the various users for their use.[6][8]

Xem thêm: Loại giày chạy bộ nào tốt xứng đáng để lựa chọn ?


There are three overarching, but not categorical - classes of cyber threat intelligence:[1] 1) tactical; 2) operational; 3) strategic.[1][5][8][9][10] These classes are fundamental đồ sộ building a comprehensive threat assessment.[5]

  • Tactical: Typically used đồ sộ help identify threat actors. Indicators of compromise (such as IP addresses, Internet domains or hashes) are used and the analysis of tactics, techniques and procedures (TTP) used by cybercriminals is beginning đồ sộ be deepened. Insights generated at the tactical level will help security teams predict upcoming attacks and identify them at the earliest possible stages.[1][5][7][8][10]
  • Operational: This is the most technical level of threat intelligence. It shares hard and specific details about attacks, motivation, threat actor capabilities, and individual campaigns. Insights provided by threat intelligence experts at this level include the nature, intent, and timing of emerging threats. This type of information is more difficult đồ sộ obtain and is most often collected through deep, obscure trang web forums that internal teams cannot access. Security and attack response teams are the ones that use this type of operational intelligence.[1][5][8][10]
  • Strategic: Usually tailored đồ sộ non-technical audiences, intelligence on general risks associated with cyberthreats. The goal is đồ sộ deliver, in the khuông of white papers and reports, a detailed analysis of current and projected future risks đồ sộ the business, as well as the potential consequences of threats đồ sộ help leaders prioritize their responses.[1][5][8][10]

Benefits of cyber threat intelligence[edit]

Cyber threat intelligence provides a number of benefits, which include:

  • Gives organizations, agencies or other entities, the ability đồ sộ develop a proactive and robust cybersecurity posture and đồ sộ bolster overall risk management and cyber security policies and responses.[11]
  • Drives momentum toward a proactive cybersecurity posture that is predictive, not simply reactive after a cyber attack.[2]
  • It provides context and insights about active attacks and potential threats đồ sộ aid decision making.[5]
  • It prevents data breaches from releasing sensitive information, thus preventing data loss.[10]
  • Reduce costs. Since data breaches are costs, reducing the risk of data breaches helps save money.[10]
  • It helps and provides instructions đồ sộ institutions on how đồ sộ implement security measures đồ sộ protect against future attacks.[10]
  • Enables sharing of knowledge, skills and experiences among the cyber security community of practice and systems stakeholders.[10]
  • It helps đồ sộ more easily and better identify risks and threats, as well as delivery mechanisms, indicators of compromise across the infrastructure, and potential specific actors and motivators.[12]
  • Helps in the detection of attacks during and before these stages.[12]
  • Provides indicators of actions taken during each stage of the attack.[12]
  • Communicates threat surfaces, attack vectors and malicious activities directed đồ sộ both information technology and operational technology platforms.
  • Serve as fact-based repository for evidence of both successful and unsuccessful cyber attacks.
  • Provide indicators for computer emergency response teams and incident response groups.

Key elements[edit]

There are three key elements that must be present for information or data đồ sộ be considered threat intelligence:[8]

  • Evidence-based: For any intelligence product đồ sộ be useful, it must first be obtained through proper evidence-gathering methods. Through other processes, such as malware analysis, threat intelligence can be produced.
  • Utility: For threat intelligence đồ sộ have a positive impact on the outcome of a security sự kiện, it must have some utility. Intelligence must provide clarity, in terms of context and data, about specific behaviours and methods.
  • Actionable: kích hoạt is the key element that separates information or data from threat intelligence. Intelligence must drive action.


Cyber threats involve the use of computers, storage devices, software networks and cloud-based repositories. Prior đồ sộ, during or after a cyber attack technical information about the information and operational technology, devices, network and computers between the attacker(s) and the victim(s) can be collected, stored and analyzed. However, identifying the person(s) behind an attack, their motivations, or the ultimate sponsor of the attack, - termed attribution is sometimes difficult. Recent[when?] efforts in threat intelligence emphasize understanding adversary TTPs.[13]

Xem thêm: addfr có nghĩa là gì

A number of recent[when?] cyber threat intelligence analytical reports have been released by public and private sector organizations which attribute cyber attacks. This includes Mandiant's APT1 and APT28 reports,[14][15] US CERT's APT29 report,[16] and Symantec's Dragonfly, Waterbug Group and Seedworm reports.[17][18][19]

CTI sharing[edit]

In năm ngoái U.S. government legislation in the khuông of the Cybersecurity Information Sharing Act encouraged the sharing of CTI indicators between government and private organizations. This act required the U.S. federal government đồ sộ facilitate and promote four CTI objectives:[20]

  1. Sharing of "classified and declassified cyber threat indicators in possession of the federal government with private entities, nonfederal government agencies, or state, tribal, or local governments";
  2. Sharing of "unclassified indicators with the public";
  3. Sharing of "information with entities under cybersecurity threats đồ sộ prevent or mitigate adverse effects";
  4. Sharing of "cybersecurity best practices with attention đồ sộ the challenges faced by small businesses.

In năm nhâm thìn, the U.S. government agency National Institute of Standards and Technology (NIST) issued a publication (NIST SP 800-150) which further outlined the necessity for Cyber Threat Information Sharing as well as a framework for implementation.[21]

See also[edit]

  • Cyber Intelligence Sharing and Protection Act
  • Denial-of-service attack
  • Indicator of compromise
  • Malware
  • Malware analysis
  • Ransomware
  • Zero-day (computing)


  1. ^ a b c d e f Bank of England. (2016). CBEST Intelligence-Led Testing: Understanding Cyber Threat Intelligence Operations.
  2. ^ a b CyberProof Inc. (n.d.). Managed Threat Intelligence. CyberProof. Retrieved on April 03, 2023 from
  3. ^ IBM (2022-02-23). "IBM Security X-Force Threat Intelligence Index". Retrieved 2022-05-29.
  4. ^ "MSSP - What is a Managed Security Service Provider?". Check Point Software. Retrieved 2022-05-29.
  5. ^ a b c d e f g h "What is Cyber Threat Intelligence used for and how is it used?". Retrieved 2023-04-12.
  6. ^ a b c Phythian, Mark (2013). Understanding the Intelligence Cycle (PDF) (1st ed.). Routledge. pp. 17–23.
  7. ^ a b c d Kime, Brian (March 29, 2016). "Threat Intelligence: Planning and Direction". SANS Institute.
  8. ^ a b c d e f g h Gerard, Johansen (2020). Digital Forensics and Incident Response: Incident response techniques and procedures đồ sộ respond đồ sộ modern cyber threats (2nd ed.). Packt Publishing Ltd.
  9. ^ Trifonov, Roumen; Nakov, Ognyan; Mladenov, Valeri (2018). "Artificial Intelligence in Cyber Threats Intelligence". 2018 International Conference on Intelligent and Innovative Computing Applications (ICONIC). IEEE. pp. 1–4. doi:10.1109/ICONIC.2018.8601235. ISBN 978-1-5386-6477-3. S2CID 57755206.
  10. ^ a b c d e f g h Kaspersky. (n.d.). What is threat intelligence? Definition and explanation. Retrieved on April 03, 2023 from
  11. ^ Berndt, Anzel; Ophoff, Jacques (2020). Drevin, Lynette; Von Solms, Suné; Theocharidou, Marianthi (eds.). "Exploring the Value of a Cyber Threat Intelligence Function in an Organization". Information Security Education. Information Security in Action. IFIP Advances in Information and Communication Technology. Cham: Springer International Publishing. 579: 96–109. doi:10.1007/978-3-030-59291-2_7. ISBN 978-3-030-59291-2. S2CID 221766741.
  12. ^ a b c Shackleford, D. (2015). Who’s Using Cyberthreat Intelligence and How?. SANS Institute.
  13. ^ Levi Gundert, How đồ sộ Identify Threat Actor TTPs
  14. ^ "APT1: Exposing One of China's Cyber Espionage Units | Mandiant" (PDF).
  15. ^[bare URL PDF]
  16. ^[bare URL PDF]
  17. ^ "Dragonfly: Western energy sector targeted by sophisticated attack group".
  18. ^ "Waterbug: Espionage Group Rolls Out Brand-New Toolset in Attacks Against Governments".
  19. ^ "Seedworm: Group Compromises Government Agencies, Oil & Gas, NGOs, Telecoms, and IT Firms".
  20. ^ Burr, Richard (2015-10-28). "S.754 - 114th Congress (2015-2016): To improve cybersecurity in the United States through enhanced sharing of information about cybersecurity threats, and for other purposes". Retrieved 2021-06-09.
  21. ^ Johnson, Christopher S.; Badger, Mark Lee; Waltermire, David A.; Snyder, Julie; Skorupka, Clem (October 2016). "Guide đồ sộ Cyber Threat Information Sharing". doi:10.6028/nist.sp.800-150.

Further reading[edit]

  • Boris Giannetto - Pierluigi Paganini (2020). Mastering Communication in Cyber Intelligence Activities: A Concise User Guide. Cyber Defense Magazine.
  • Anca Dinicu, "Nicolae Bălcescu" Land Forces Academy, Sibiu, Romania, Cyber Threats đồ sộ National Security. Specific Features and Actors Involved - Bulletin Ştiinţific No 2(38)/2014
  • Zero Day: Nuclear Cyber Sabotage, Đài truyền hình BBC Four - the Documentary thriller about warfare in a world without rules - the world of cyberwar. It tells the story of Stuxnet, self-replicating computer malware, known as a 'worm' for its ability đồ sộ burrow from computer
  • What is threat intelligence? - Blog post providing context and adding đồ sộ the discussion of defining threat intelligence.
  • Threat hunting explained - Short article explaining cyber threat intelligence.