Seven Ways to Apply the Cyber Kill Chain with a Threat Intelligence Platform

Seven Ways to Apply the Cyber Kill Chain with a Threat Intelligence Platform

 

ABSTRACT

Threat Intelligence Platforms (TIP) are an emerging technology supporting organizations as they consume and then act on cyber intelligence. Lockheed Martin believes that a TIP helps an organization transition from relying solely on external intelligence sources to producing their own intelligence based on what is observed in their environment. The result is elevated cyber maturity and improved resilience against attackers.

 

INTRODUCTION

Within the past decade, computer network defense has shifted from a culture of sharing minimal information to one of intelligence overload. Previously, information regarding system breaches, malware, or attack attribution was rarely shared between organizations. Today the more common issue is how to sift through all the emails, reports, and indicators to identify actionable intelligence.

Threat intelligence is evidence-based knowledge about a threat that can be used to inform decisions regarding the response to that threat (McMillan, 2013). It includes the details of the motivations, intent, and capabilities of threat actors (Holland, 2014). In order to successfully defend against the multitude of Advanced Persistent Threats (APT) facing an organization, consuming external threat intelligence has become an increasingly important aspect of cybersecurity. However, exactly how to ingest the intelligence and successfully leverage it within an organization’s environment often remains a challenge.

In addition to external intelligence, an influx of data from one’s own organization can further complicate matters. Alerts from a myriad of technologies including Intrusion Detection Systems (IDS), firewalls, mail scanners, Host Intrusion Prevention Systems (HIPS), and proxies can overwhelm a defender who is trying to respond to and disposition each alert. External intelligence can quickly become an afterthought as there is no time to evaluate and implement countermeasures, making it useless. Conversely, external intelligence fed directly into these tools results only in more noise if it is not properly vetted for one’s environment and mitigations are not appropriately tuned.

In order to process all of this internal and external data and have it result in actionable intelligence, a TIP can be employed. A TIP is the central management repository for all external and internal intelligence, and can provide the mechanism to act upon this intelligence.

This paper is organized as follows: section two of this paper documents related work on defining the requisite components of a TIP. Section three introduces an expansion of this definition that is based upon the Intelligence Driven Defense® approach to computer network defense. Section four outlines the seven ways an organization can apply the Cyber Kill Chain® framework in their environment using a TIP. Section five introduces the PalisadeTM solution, Lockheed Martin’s Threat Intelligence Platform, and section six summarizes the paper.

 

Read the article below: 

A White Paper Presented by: Lockheed Martin Corporation

Browse our Suppliers and their Products & Services

Products & Services

more products or services
Metrology
Metrology

The innovation engine of Pulse Technologies, our state-of-the-art, fully equipped metallurgy and metrology lab is where we ask the big questions that lead to even bigger breakthroughs.

Custom Precision Solutions, Inc.: Brakes, Clutches & Solenoids
Custom Precision Solutions, Inc.: Brakes, Clutches & Solenoids

Your Source for Custom, American Made Precision Miniature Electro-Magnetic Clutches, Brakes, Solenoids, and Torque Indicators.

MILMAST Lifting Systems Inc., Naval Series Mast
MILMAST Lifting Systems Inc., Naval Series Mast

FTM Series is designed and produced for 'Heavy Loads' between 120 kg and 300 kg. With its Carbon Composite body, it is robust and long-lasting in all conditions.

IMAC heater in army colours
IMAC heater in army colours

Heating of transit sheds, workshops and warehouses.

Turbo Cast Aerospace Products
Turbo Cast Aerospace Products

Turbo Cast (India) Pvt. Ltd. is India's First Indigenous Investment Casting foundry, started in 2015, especially for Aerospace, Defense, Medical & Aluminum Alloy, Accredited for AS9100D & Nadcap (NDT) & Nadcap (Welding) Certification.

JR-UAV, Piston Engine, DA 35cc 2 Stroke EFI
JR-UAV, Piston Engine, DA 35cc 2 Stroke EFI

Renown Desert Aircraft piston engines combined with the leading edge fuel injection system by INFInject provide amazing reliability in all conditions and deficient fuel consumption.

Anodising
Anodising

As aluminium "rusts" it produces a loose dry white powder, aluminium oxide. The anodising process artificially produces this film but as a hard, dense wear resistant surface.

Air Data Computers
Air Data Computers

The Shadin Avionics F/ADC-2000 Fuel/Airdata Computer gives you access to more real-time flight information than ever before.

City Security Management System (CSMS)
City Security Management System (CSMS)

Within the scope of the system, two basic monitoring and management subsystems have been developed and these subsystems form an important infrastructure for the efficient use of smart city applications.

Gimbals & RF Microwave components
Gimbals & RF Microwave components

AMD is an approved supplier for Offset from the Department of Industrial Policy Promotion (DIPP) under the aid of the Indian Ministry of Defence.

Automatic Pilot Test & Repair
Automatic Pilot Test & Repair

AVP supportscustomers worldwide on testing and repairing Autopilots and acceleration sensors for the C-130H and SA-330 Puma and SA-332 Super Puma.

Menatek Defense Technologies, Maintenance, Repair & Overhaul (MRO)
Menatek Defense Technologies, Maintenance, Repair & Overhaul (MRO)

Menatek’s premium quality inventory is ready to provide and support various MRO programs. We focus on full life cycle support and we reserve smart stocks and spares.

Ader Savunma

ADER DEFENCE A.Ş. is the result of the collaboration of a team of experts in order to improve the industrial and high-tech manufacturing capabilities of Turkey.

Etion Create

Our reputation as a supplier of innovative electronic solutions has resulted in our products being used in various land, sea and air applications for over 20 years.

Chemtron Pte Ltd.

We carry a complete portfolio of solutions that is making rapid head way into various industries such as manufacturing, medical, jewellery, aerospace and dental markets.

Poweration Inc.

Poweration, Inc. is a leading supplier of power electronics equipment focusing mainly on R&D, design, and manufacturing with a wide variety of products for harsh-environment power electronics equipment.

CSM Industry

CSM Industry is a manufacturer of MULTI-PURPOSE TELESCOPIC EXCAVATOR for the defense sector.

BNR EXPORTS

We are pleased to Introduce BNR EXPORTS as a 100% EOU established in the year 2000 Manufacturing precision machined and turned components.

Koç Bilgi ve Savunma Teknolojileri A.Ş.

Koç Bilgi ve Savunma Teknolojileri A.Ş. was established in 2006 in order to meet the defense industry needs of our country with indigenous solutions and to provide added value to the defense sector.

Coskunoz Aerospace&Defence Inc.

We produce to the highest standards, fully aware of our responsibilities as a company working proudly under the umbrella of a holding, with a history going back 71 years. Today, we are among the leading integrated solution partners in the industry.

RCF Technologies Inc

RCF Technologies, founded in 1975, is a woman owned, Hubzone certified company, designing and manufacturing components for industries including aerospace, automotive, marine, defense and industrial.

Download our app to your mobile phone