Uniting Threat Vulnerability and Risk
Credit-Mitre

Uniting Threat Vulnerability and Risk

I have an unclear vision for a long time on “how i can combine Risk, Vulnerability and Threat data available and use it flexibly for various needs with an output readable by machines and humans”

That thought became a reality last week.! Clearly planned the stages and i was able to execute it as per design. I got Vulnerability data from NVD, Threat data from CTID and MITRE, Risk Framework data from NIST SP800 53. After getting these data, there was a challenge in finding an analytical tool where i can import the data and do various operations on data (Slice and dice, aggregate, extract, explode, join, replace etc).

I did few searches and experimented some analytic tools — Google, Zoho, ADX, Superset, Splunk, Tableau etc. Nothing makes me feel the best than ADX (Azure Data Explorer). So fixed ADX as the tool, with the available subscription, i was able to aggregate, pack and extract needed data.

Below is my effort and outcome of the analytics.

No alt text provided for this image

We can summarize based on NIST Control Family or CVE or Attack Techniques. This output data can be exported in machine readable formats like Json, XML etc and can be a feed to other systems or products. This can also be used for correlating with other data for further analytics or enrichment.

Ref

https://ctid.mitre-engenuity.org/our-work/nist-800-53-control-mappings/

https://github.com/center-for-threat-informed-defense/

Use Cases

If you get an advisory saying “An attack Technique say T1234 is very active and is targeting your industry say Banking”. We will be able to relate past known vulnerability exploited by the group and the controls which are to be checked and validated to counter these actors upon us. These actions will give us necessary information to give confidence to board that we will not be a opportunistic victim of this campaign. These information will help to prioritize Vulnerably remediation based on Threat landscape. This knowledge can also be used on strengthening and revalidating focused Protective controls.

要查看或添加评论,请登录

Shankar Murali的更多文章

  • Slow or Fast - Its a Choice

    Slow or Fast - Its a Choice

    Life is a series of choices, each leading to the next, shaping the path we take. I wasn't always a book lover.

  • Create you first ML Model

    Create you first ML Model

    The feeling of creating our own first Machine learning model is Awesome - like any creation we do for the first time…

    2 条评论
  • The Personal Mastery Framework

    The Personal Mastery Framework

    (A framework for Healthy, Happy and Contented Life) Below is my Novel work, simplified for general Audience. During my…

    1 条评论
  • Vande Mukunda Hare..!

    Vande Mukunda Hare..!

    It is Krishna's Birthday, he is now 97 yrs old. He woke up at 5 am and did Yoga, Pooja and other rituals which he was…

  • Financial Preparedness Program with Mermaid Visualisation

    Financial Preparedness Program with Mermaid Visualisation

    Was trying to create a financial preparedness program with mermaid visuals using Python. After few iteration am able to…

  • What exactly is Services and Programs in Windows?

    What exactly is Services and Programs in Windows?

    This is a common question in minds of any Security Practitioners. This article will throw some light on execution of…

  • Ordinary Man with Extra Ordinary Mind

    Ordinary Man with Extra Ordinary Mind

    Once upon a time, i was walking to my new office in Bangalore. Suddenly a stranger came and ask me “where is the…

  • The Short Fable about Economy and Business

    The Short Fable about Economy and Business

    Long before Government of Richland Printed new 100 r notes and distributed to economy (citizens). We will take a sample…

    1 条评论
  • The Story of Bob and Sally - The Power of Data

    The Story of Bob and Sally - The Power of Data

    A Fictional Story Sally is working in a Search Engine company. She was assigned to experiment "behavior changing"…

  • Python Basics

    Python Basics

    Credit - MIT Open Courseware - https://ocw.mit.

社区洞察

其他会员也浏览了