官术网_书友最值得收藏!

Threat intelligence

Threat intelligence is controlled, calculated, and refined information about potential or current attacks that threaten an organization. The primary purpose of this kind of intelligence is to ensure organizations are aware of the current risks, such as Advanced Persistent Threats (APTs), Zero Day exploits, and other severe external threats, such as information about a million credit cards being stolen from retail Company A through APTs, and this alert being already passed on to Company B to step up their security.

However, it is most likely that organizations take a very long time to make an actionable decision due to a lack of trusted sources, and also the cost involved due to the nature and probability of the threats. In the preceding example, Company B may have 2,000 stores to replace, or may have to halt all transactions.

This information can be potentially utilized by attackers to exploit the network. However, this information is considered to be a passive reconnaissance activity since there has, as yet, been no direct attack launched on the target.

Penetration testers or attackers will always subscribe to open source threat intelligence frameworks, such as STIX and TAXII.

主站蜘蛛池模板: 辉县市| 朝阳区| 黔南| 新竹市| 富平县| 剑川县| 曲水县| 垫江县| 信阳市| 闽清县| 通渭县| 千阳县| 商南县| 大英县| 鸡西市| 陕西省| 芦溪县| 乐至县| 平陆县| 寻乌县| 景洪市| 镇沅| 德安县| 海原县| 乌拉特前旗| 延寿县| 大渡口区| 宜兰县| 府谷县| 清水河县| 尤溪县| 长子县| 蕉岭县| 攀枝花市| 白银市| 隆德县| 罗甸县| 崇左市| 越西县| 洛阳市| 芜湖县|