Главная
Study mode:
on
1
Intro
2
who are we
3
lets go
4
the basics
5
the pyramid of pain
6
math talk
7
can we measure this
8
IP addresses
9
Can we measure
10
What are we measuring
11
Separate inbound and outbound
12
Experiment with IP addresses
13
Experiment with DNS
14
Dont do maps
15
Data set
16
Novelty test
17
Information asymmetry
18
Novelty tests
19
Overlap test
20
Outbound data
21
Population test
22
True population
23
Hypothesis testing
24
Confidence intervals
25
Animal names
26
Comparing different populations
27
GPL
28
Combine
29
Conclusion
30
Main takeaway
31
QA
32
False positives
Description:
Explore the effectiveness of threat intelligence feeds in this BSidesLV 2014 conference talk. Dive into the concept of measuring the IQ of threat intelligence feeds, covering topics such as the pyramid of pain, mathematical approaches, and various measurement techniques. Learn about experiments with IP addresses and DNS, data set analysis, novelty tests, and information asymmetry. Examine outbound data, population tests, hypothesis testing, and confidence intervals. Gain insights into comparing different populations, GPL, and combining data sources. Conclude with main takeaways and a Q&A session addressing false positives and other critical aspects of threat intelligence evaluation.

Measuring the IQ of Your Threat Intelligence Feeds

Add to list
0:00 / 0:00