From: FederalNewsRadio.com 1500AM
By Jason Miller
Agencies are taking a deeper dive to understand not only how their computers are being attacked but the pattern of the attacker.
Cyber threat intelligence is a growing trend across the government. It’s more than just knowing that one’s computer network is under attack, and it’s more than knowing even who or what kind of attacker is going after your data—whether a nation state actor or a cyber criminal group or even just a run-of-the-mill nuisance hacker.
The idea behind cyber threat intelligence is to understand more about the attack and the attacker than ever before by matching up patterns, anomalies and other characteristics of the bad guys.
“One of the challenges that offers the most promise for cybersecurity is figuring out faster ways to do analytics on this rich set of data that we already have,” said Gil Vega, the Energy Department’s chief information security officer, at the McAfee Public Sector Summit in Arlington, Va. Tuesday. “We had a zero day attack the other day that we orchestrated a really good response to, but it was clear in the postmortem that we had breadcrumbs of this event a lot earlier than this detection. We had that on disk ready to be exploited in our defense of our systems.”
He said those signs, or breadcrumbs, weren’t brought to the forefront to use in Energy’s defense as quickly as they could be.
“That’s where a big focus of our efforts, budget and energies are on right now,” Vega said. “We have the data, how do we exploit it quicker? How do we share the information quicker with our cyber defenders around the cyber complex?”
Leave a Reply