Studio 471

Intel 471

Join us into the world of cybercrime. Studio 471 brings you the latest trends, emerging threats, and expert advice to arm you with the insights needed to protect your business. By unraveling the mysteries of the underground, our series empowers teams, organizations, and communities to make informed decisions and discover actionable strategies to safeguard your digital footprint.

  1. 28 Jul

    Writing high-quality IDS detection rules ft. Eindhoven University of Technology on Studio 471

    Security operations centers, or SOCs, are a core defensive component for organizations.  Quickly processing alerts can give a clue if an organization is under attack. But the volume and quality of alerts can greatly vary depending on how well the detection rules have been written. Some rules may return too many low-quality alerts, which can distract analysts from more important ones. Luca Allodi and Koen Teuwen of Eindhoven University of Technology co-authored a recent academic study that examines how to write lower-noise rules for intrusion detection systems (IDSs). The researchers developed six design principles for rule writing that balance specificity with coverage. The aim is to help analysts make better sense of what’s going on in their networks. The research also resulted in the development of a command-line tool, suricata-check, which gives feedback on how a rule written for the Suricata open-source IDS can be improved. Participants:Luca Allodi, Associate Professor and head of the Threat Analysis group within the Security Cluster of the Eindhoven University of TechnologyKoen Teuwen, PhD Candidate at Eindhoven University of TechnologyJeremy Kirk, Executive Editor, Cyber Threat Intelligence, Intel 471---------- Stay in Touch! Twitter: https://twitter.com/Intel471Inc LinkedIn: https://www.linkedin.com/company/intel-471/ YouTube: https://www.youtube.com/channel/UCIL4ElcM6oLd3n36hM4_wkg Discord: https://discord.gg/DR4mcW4zBr Facebook: https://www.facebook.com/Intel471Inc/

  2. 23 Jun

    Cybersecurity Regulations: Will Processing CTI Become Legally Risky? | Studio 471

    In this video, learn about cybersecurity regulations and if processing CTI could become a potential legal risk.  An increasing number of regulations in different countries and regions require data to be processed locally for privacy and national security reasons. But these regulations have potential negative impacts on cybersecurity, such as limiting the sharing of information useful for threat hunting and penetration testing. For example, Europe’s General Data Protection Regulation considers IP addresses – a common indicator of compromise – as personal data. Since 2021, Professor Peter Swire of Georgia Tech’s College of Computing has led a team that has published two papers (linked below) studying the effects of data localization on the provision of cybersecurity services. In this Studio 471, Swire discusses the regulatory environment, how it could impact the use of cyber threat intelligence and what could be done to ensure attackers don’t leverage these changes to their advantage. Participants:Peter Swire, Professor, Georgia Tech College of ComputingJeremy Kirk, Executive Editor, Cyber Threat Intelligence, Intel 471---------- Stay in Touch! Twitter: https://twitter.com/Intel471Inc LinkedIn: https://www.linkedin.com/company/intel-471/ YouTube: https://www.youtube.com/channel/UCIL4ElcM6oLd3n36hM4_wkg Discord: https://discord.gg/DR4mcW4zBr Facebook: https://www.facebook.com/Intel471Inc/

About

Join us into the world of cybercrime. Studio 471 brings you the latest trends, emerging threats, and expert advice to arm you with the insights needed to protect your business. By unraveling the mysteries of the underground, our series empowers teams, organizations, and communities to make informed decisions and discover actionable strategies to safeguard your digital footprint.