Copyright © 2014 BAE Systems. All Rights Reserved. BAE Systems is a trade mark of BAE Systems plc 1 Commercial in Confidence Intelligence-led security Understanding threat intelligence
Copyright © 2014 BAE Systems. All Rights Reserved. BAE Systems is a trade mark of BAE Systems plc 2 Commercial in Confidence SIX STEPS TO INTELLIGENCE-LED SECURITY 1. PERFORM THREAT ASSESSMENT 2. DETERMINE INTELLIGENCE REQUIREMENTS 3. BUILD COLLECTION SOURCES 4. OPERATIONALIZE THREAT INTELLIGENCE 5. INTRODUCE SECURITY ANALYTICS 6. GAIN SITUATIONAL AWARENESS
Copyright © 2014 BAE Systems. All Rights Reserved. BAE Systems is a trade mark of BAE Systems plc 3 Commercial in Confidence Malware signaturesMalware signatures IOCs / IOAsIOCs / IOAs Domain blacklistsDomain blacklists IP reputation listsIP reputation lists Security mailing listsSecurity mailing lists RSS feedsRSS feeds Open-source reportsOpen-source reports Targets (sector / region)Targets (sector / region) Motivation / PersistenceMotivation / Persistence Tools / Tactics / ProceduresTools / Tactics / Procedures Attribution / AffiliationAttribution / Affiliation Socio-political contextSocio-political context Business impactsBusiness impacts Suggested mitigationsSuggested mitigations THREAT INTELLIGENCE UNDERSTANDING THREAT INTELLIGENCE
Copyright © 2014 BAE Systems. All Rights Reserved. BAE Systems is a trade mark of BAE Systems plc 4 Commercial in Confidence Dissemination Direction Collection Analysis Production Non-linear process with multiple feedback loops THE TRADITIONAL INTELLIGENCE LIFECYCLE
Copyright © 2014 BAE Systems. All Rights Reserved. BAE Systems is a trade mark of BAE Systems plc 5 Commercial in Confidence Infrastructure DRIVES THE BUILDING OF INTELLIGENCE MODELS Malware Criminals Victims Banks Police Investigators CERTs Researchers
Copyright © 2014 BAE Systems. All Rights Reserved. BAE Systems is a trade mark of BAE Systems plc 6 Commercial in Confidence SHYLOCK – A CYBER CRIMINAL INTELLIGENCE PROBLEM
Copyright © 2014 BAE Systems. All Rights Reserved. BAE Systems is a trade mark of BAE Systems plc 7 Commercial in Confidence SHYLOCK FINANCIAL CRIME OPERATION Estimated at over 50K machines compromised Global victimisation, but with a preference for UK, US, and Italy
Copyright © 2014 BAE Systems. All Rights Reserved. BAE Systems is a trade mark of BAE Systems plc 8 Commercial in Confidence SHYLOCK – A CYBER CRIMINAL INTELLIGENCE PROBLEM Intelligence Model Criminals Malware Infrastructure Victims
Copyright © 2014 BAE Systems. All Rights Reserved. BAE Systems is a trade mark of BAE Systems plc 9 Commercial in Confidence HOW IT WORKS – COMPROMISING THE VICTIM Intelligence Model Criminals Malware Infrastructure Victims
Copyright © 2014 BAE Systems. All Rights Reserved. BAE Systems is a trade mark of BAE Systems plc 10 Commercial in Confidence HOW IT WORKS – MALWARE AUTOMATION Intelligence Model Criminals Malware Infrastructure Victims
Copyright © 2014 BAE Systems. All Rights Reserved. BAE Systems is a trade mark of BAE Systems plc 11 Commercial in Confidence HOW IT WORKS – MALWARE AUTOMATION Intelligence Model Criminals Malware Infrastructure Victims
Copyright © 2014 BAE Systems. All Rights Reserved. BAE Systems is a trade mark of BAE Systems plc 12 Commercial in Confidence HOW IT WORKS – MALWARE AUTOMATION Intelligence Model Criminals Malware Infrastructure Victims
Copyright © 2014 BAE Systems. All Rights Reserved. BAE Systems is a trade mark of BAE Systems plc 13 Commercial in Confidence HOW IT WORKS – BANKING WEBSITE MODIFICATION Intelligence Model Criminals Malware Infrastructure Victims
Copyright © 2014 BAE Systems. All Rights Reserved. BAE Systems is a trade mark of BAE Systems plc 14 Commercial in Confidence FINDING THE C2 INFRASTRUCTURE Intelligence Model Criminals Malware Infrastructure Victims
Copyright © 2014 BAE Systems. All Rights Reserved. BAE Systems is a trade mark of BAE Systems plc 15 Commercial in Confidence LINKS TO MULE RECRUITMENT Intelligence Model Criminals Malware Infrastructure Victims
Copyright © 2014 BAE Systems. All Rights Reserved. BAE Systems is a trade mark of BAE Systems plc 16 Commercial in Confidence THE SHYLOCK TAKEDOWN – INTELLIGENCE INTO ACTION
Copyright © 2014 BAE Systems. All Rights Reserved. BAE Systems is a trade mark of BAE Systems plc 17 Commercial in Confidence BAE Systems Applied Intelligence Surrey Research Park Guildford Surrey GU2 7RQ United Kingdom T: +44 (0) F: +44 (0) Copyright © BAE Systems All rights reserved. BAE SYSTEMS, the BAE SYSTEMS Logo and the product names referenced herein are trademarks of BAE Systems plc. BAE Systems Detica and BAE Systems Applied Intelligence are trading names of Detica Limited registered in England (No ) with its registered office at Surrey Research Park, Guildford, England, GU2 7RQ.