OSS is changing the Security information sharing landscape.
Focus on the MISP objects and other recent improvements on the platform Rapha¨ el Vinot - TLP:WHITE
info@circl.lu
RMLL 2017
OSS is changing the Security information sharing landscape. Focus on - - PowerPoint PPT Presentation
OSS is changing the Security information sharing landscape. Focus on the MISP objects and other recent improvements on the platform Rapha el Vinot - TLP:WHITE info@circl.lu RMLL 2017 TL;DR Started in 2012 by Christophe Vandeplas (Belgian
Focus on the MISP objects and other recent improvements on the platform Rapha¨ el Vinot - TLP:WHITE
info@circl.lu
RMLL 2017
Fraud analysts)
2 of 31
consumer and/or a contributor/producer.
3 of 31
4 of 31
CSV feed
Threat SharingSIEMs Enrichment modules Analyst input Analyst Proposals Remote instances Remote instances Incident response Viper IDS Other formats Other formats Analysis tools
Sandboxes CSV feed CSV feed
Threat Sharing Threat Sharing5 of 31
6 of 31
7 of 31
8 of 31
usage : pcapreader . py [−h ] −r READ [− f FILTER ] [−s SOURCE] [−t TYPE] [−v ] [−d ]
arguments : −r READ, − −read READ pcap/dumpcap f i l e that should be read by t s h a r k −f FILTER , − −f i l t e r FILTER P r e f i x that should be skipped ( s u b s t r i n g ) −s SOURCE, − −source SOURCE De scr ibe the source
the pcap −t TYPE, − −type TYPE S p e c i f y the type
s i g h t i n g s : 0=Default ,1= F a l s e p o s i t i v e
9 of 31
”... and create my own names?”
10 of 31
commonalities became more and more pressing
descriptive
attribution was a mess
11 of 31
are meant for human consumption
are loose key value lists
12 of 31
Synonym: APT28, Fancy Bear)
using a specific tool)
13 of 31
adversaries
Microsoft
threats
14 of 31
15 of 31
events
They will simply see the tags until they upgrade.
16 of 31
17 of 31
1 { 2 ”meta” : { 3 ”synonyms” : [ 4 ”APT 28” , ”APT28” , ”Pawn Storm” , ”Fancy Bear ” , 5 ” Sednit ” , ”TsarTeam” , ”TG −4127” , ”Group−4127” , 6 ”STRONTIUM” , ”Grey−Cloud ” 7 ] , 8 ” country ” : ”RU” , 9 ” r e f s ” : [ 10 ” h t t p s : // en . w i k i p e d i a . org / w i k i / Sofacy Group ” 11 ] 12 } , 13 ” d e s c r i p t i o n ” : ”The Sofacy Group ( a l s o known as APT28 , 14 Pawn Storm , Fancy Bear and Sednit ) i s a cyber 15 espionage group b e l i e v e d to have t i e s to the 16 Russian government . L i k e l y
s i n c e 2007 , 17 the group i s known to t a r g e t government , m i l i t a r y , 18 and s e c u r i t y
I t has been 19 c h a r a c t e r i z e d as an advanced p e r s i s t e n t t h r e a t .” , 20 ” v a l u e ” : ” Sofacy ” 21 } ,
18 of 31
”They said it will make me sleep better at night. I like sleeping.” 19 of 31
20 of 31
21 of 31
”Yes, I know, STIX is awful, but my boss wants me to use it” 22 of 31
with the events shared (e.g. allowing to share events with yet unknown objects).
1https://github.com/misp/misp-objects 23 of 31
VBA Macro, Embedded JavaScript, ...
24 of 31
25 of 31
26 of 31
27 of 31
28 of 31
29 of 31
r2graphity/blob/master/GraphDracula_Recon17.pdf
30 of 31
31 of 31