课程: ISC2 Certified Information Systems Security Professional (CISSP) (2024) Cert Prep

免费学习该课程!

今天就开通帐号,24,600 门业界名师课程任您挑!

Automating threat intelligence

Automating threat intelligence

- [Instructor] Threat intelligence is one of the areas where automation can provide tremendous benefits. Let's take a look at a few examples. One of the most useful security automations that an organization can easily adopt is the automated blacklisting of IP addresses reported by threat intelligence services as the source of malicious activity. These threat intelligence services often include a direct feed of IP addresses that's updated in real time as malicious activity is detected across their client's networks. These threat feeds are designed for direct integration with firewalls, intrusion prevention systems, routers, and other devices with the capability of automatically blocking traffic. Technologists are often worried about deploying any tool that automatically blocks traffic, and this is a legitimate operational concern. For this reason, organizations considering this automation should first deploy the threat intelligence feed in alert only mode to identify traffic that would…

内容