Indicators of Compromise for Cyber Threat Intelligence and Incident Response.pdf

(2434 KB) Pobierz
Indicators of Compromise
per Cyber Threat Intelligence e
Incident Response
M. Costa – Sinergy
G. Zanoni
Symantec
Security Summit Roma 2016
Agenda
Threat Intelligence
(M. Costa)
Lo scenario
Definizione di Threat Intelligence
Indicator of Compromise (IoC)
Cosa sono e a cosa servono gli IoC?
IoC – Creazione, Raccolta, Condivisione
Standard e Tools
Incident Response (G. Zanoni)
La Threat Intelligence nella realtà: SOC, MSSP
2
Incident Management - Scenario
Threat
Intelligence
Security
Advisory
Gestione degli
Incidenti di Sicurezza:
elementi principali
Monitoring
3
Incident Response
Incident Management - Attività
Advisory
Monitoring
Threat
Intelligence
Incident
Response
• Progettare e implementare
• Controllo on-site
• Analisi
• Gestire l’attacco
4
Incident Management - Attori
Advisory
Monitoring
Threat
Intelligence
Incident
Response
• Security Partner
• MSS & Security Partner
• Managed Security Service
Provider
• MSS & Security Partner
5
Zgłoś jeśli naruszono regulamin