Wednesday, July 12, 2017

CYBER-650 Week 6--Resources Revisited

A few weeks ago, I provided a list of resources that are useful in cybersecurity, specifically in threat modeling. Well, since then I've done a bit of threat modeling myself, which means I had an opportunity to use those resources (or not)*. So now that I have some "real life" experience, let's revisit those resources.

My biggest takeaway was that a lot of my resources aren't super useful when initial threat modeling is being done. Blogs and news articles tend to cover up-and-coming threats and only reinforce the basic principles of computer security (found in textbooks, websites, and other sources around the Internet and globe). So I wasn't going through Bruce Schneier's blog or Microsoft's security advisories looking for data; I was instead assimilating my knowledge of threats I've gained from long-term reading of such resources and applying them to general security and vulnerability scenarios. In other words, I wasn't tracking down individual vulnerabilities these resources covered; I focused on fixing classes of issues these resources addressed.

In a real-time threat analysis, these tools would be better. When an article about a rise in Mac ransomware comes up, a mature threat analysis program can take that as a hint to examine Mac security. So while articles like this wouldn't be terribly useful in an overarching threat analysis, it is quite useful in real-time threat analysis.

However, I did use one of my provided resources for this threat-modeling exercise--the Verizon Data Breach Investigations Report. This was because it provides overarching data useful for an overarching threat model. What is more, the system I was threat modeling was significantly threatened by a data breach, making Verizon's DBIR particularly applicable. Since almost all the other resources I listed applied to current, singular threats, they were not as useful as this resource.

So the overarching conclusion I've come to is that threat information resources are most useful when they align with the type of threat modeling being done. If one is doing real-time threat modeling, real-time sources of information (like news articles) are quite useful. If, on the other hand, long term, overarching threat modeling is being done, resources with long-term, overarching data are more useful. However, long-term principles can be gleaned from news articles, especially if many articles are synthesized over a period of time.

*(I'm not sharing the threat modeling report here--unless the Internet needs a free copy of my stuff, I'd rather not give it one. :) ).

No comments:

Post a Comment