Explore the effectiveness of threat intelligence feeds in this BSidesLV 2014 conference talk. Dive into the concept of measuring the IQ of threat intelligence feeds, covering topics such as the pyramid of pain, mathematical approaches, and various measurement techniques. Learn about experiments with IP addresses and DNS, data set analysis, novelty tests, and information asymmetry. Examine outbound data, population tests, hypothesis testing, and confidence intervals. Gain insights into comparing different populations, GPL, and combining data sources. Conclude with main takeaways and a Q&A session addressing false positives and other critical aspects of threat intelligence evaluation.
Measuring the IQ of Your Threat Intelligence Feeds