Biases of Customer Base in Cyber Threat Intelligence

Let’s start with a little bit of background. I was a translator (Russian, some Serbian) in the US Army and worked in the intelligence field from when I was 18 until I was 25 and this rewired my brain somewhat. From late 2012 to early 2015, I ran Akamai’s Customer Security Incident Response Team (CSIRT) with a mission of incident response and Cyber Threat Intelligence (CTI) sharing. When I was living in Asia, I was involved in several data feed projects including one that I programmed from scratch as a proof of concept.

And this is a fact that we have to work around: every intelligence sensor or data source has bias. Signals intelligence is good for command and control but not for things that don’t use radio and telephone. On the ground reconnaissance patrols and observation posts are good at seeing troop movements but only inside of their field of view. Malware CTI is different from web and phishing CTI. In order to get the full picture of what is happening, you have to combine all of these sensors in order to counter out their biases.

For CTI vendors, once your remove the technology type, CTI usually translates into a bias for your customer base. And this can be further divided into 2 core groups: by industry and by country.

CTI by Industry

Industry is easiest to understand. If you are a cybersecurity vendor, it’s relatively easy to sell to financial services first, then eCommerce, then government. Media, manufacturing, publishing, food producers, etc are much harder–either they don’t have a lot of IT assets or their IT systems are relatively unique) so they are drastically underrepresented in CTI data.

CTI by Country

And then there is country. I think this is the biggest bias that I want to address here, and this conversation is all about North America. Americans in particular think that global statistics are valid globally, but if 80% of your customers are inside the US, global statistics are really US statistics.

It’s a mildly humorous anecdote, but one time when I was in India I had a CISO pull out my company’s global threat report and say that since, according to the report, India is not attacked so therefore there was no demand for our solution there and in fact, we should pay them for the amount of data that we would collect from their infrastructure. I laughed because I love the bargaining tactic. Of course, if you’re talking to the same CISO and it’s not a sales call, they will tell you about how they are the most heavily attacked company on the planet.

And this story repeats throughout all of Asia.

If you take a look inside any country–I’ve seen this in Singapore, Japan, Australia, Brazil, and the UK–they have some unique CTI demands that are different from the US:

  • Different banks
  • Regional telcos, often state-owned
  • Unique government agencies
  • One countrywide single-sign-on/login for government services
  • Culturally-specific love-interest and customs-fine scams
  • Rival countries that are not China, Russia, or Iran
  • Analysts speaking different languages
  • New-ish organizations like a CERT and cybersecurity regulator
  • Possibly not a lot of native companies but a lot of multinationals with a presence inside of the country

And lastly, we should talk about the rarified air of dividing up CTI by both targeted country and industry, and maybe that gives you a choice of 2 organizations that you’re viewing attack statistics from and you work for one of them. In other words, if you segment CTI to a deeper level, you’re able to unmask the target. =) This is not necessarily bad since the attacks were detected and presumably blocked, it just has weird perception issues.

But on the positive side, if you are an American bank, there is lots of relevant CTI for you to look at. And I would take CTI for other organizations before I have to live with no CTI because at least you’re starting with something.

So at this point you must be saying, “Michael, that’s all well and great and I understand the limitations, but what do you expect us to do about it?”

Well, I’m glad you asked. Like many things in life, understanding your bias is the first step towards solving it.

For CTI Vendors:

You have to constantly understand your collection and reporting biases and find new ways to balance them out with additional data sources and analyst training. This might mean partnerships. It might mean providing free/low-cost sensors to markets where you don’t have a large customer base.

Where you provide data feeds or reports, have them tagged by target industry and country to help your customers filter better.

For underrepresented customer segments, consider grouping them with other areas. For instance, with Singapore you could group all of Southeast Asia into an ASEAN feed; Singapore, US, UK, Australia, Canada, and NZ into an “Allied Nations” feed, or an “4 Asian Tigers” feed. You can also get creative with industries if you don’t have enough data in a specific industry to be statistically meaningful.

For Security Managers:

If you’re in one of the underrepresented industries and countries, realize that only a fraction of CTI is relevant to you, one of your keys to success in having a successful CTI plan is being able to collect, analyze, and share your own intelligence. This means that you need to be more active in Threat Hunting and getting other intelligence.

Information Sharing and Analysis Organizations are organized around industry and country. If you are unsupported in either of those, find your peers and partner up. It might be as simple as introducing your CSIRT and SOC managers to each other and giving them permission to talk freely with each other. It might be something like organizing a quarterly working group session between teams.

Ask your security vendors to periodically bring their CTI folks around to talk to you without sales and marketing people present. You can ask for tactics and techniques to get logs out of the product, what tools they are using for analysis, and any techniques they have to learn about your attackers.



Published on March 3, 2021.
Last Updated on 6 months ago.

Leave a Reply

Your email address will not be published. Required fields are marked *