Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - How To Close Security Gaps With A Threat Intelligence Library
Articles

How To Close Security Gaps With A Threat Intelligence Library

Anthony PerridgeBy Anthony PerridgeOctober 15, 2018Updated:July 4, 20244 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Companies have invested in protection technologies for decades – firewalls, web and email security gateways and endpoint protection. Over time, these technologies have increasingly relied upon threat intelligence to create real-time block lists for malware signatures, bad domains and IP addresses, file hashes and more. Despite these measures, attacks still get through.

People tend to think this is result of a coverage gap: the vendor doesn’t have a signature for the attack. But there is also a timing gap when the vendor doesn’t have a signature for the attack when the attack happens. Apart from coverage and timing gaps, organisations also have the problem of physical coverage gaps. They may not have a security device in the area being attacked, so blocking or detecting the attack at the point of intrusion is impossible.

Are companies doomed to live with these security gaps, or is there something they can do to compensate? In truth, companies probably have much of what they need to address these challenges. They just need to find a way to make better use of the security technologies and teams they already have in place.

By creating a library of threat intelligence, security teams can use existing security information and event management (SIEM) log data to help close the coverage, timing and physical security gaps. It may seem like a duplication of effort to create your own threat intelligence library, given most security technologies have their own threat libraries. But, in fact, it is key to leveraging the organisation’s existing security investments. Here’s how:

The signature coverage gap. No vendor covers every attack. In an analysis of the blacklist ecosystem, researchers at Carnegie Mellon University found that the contents of blacklists generally do not overlap. In fact, of the 123 lists reviewed, almost all indicators appeared only on a single list. Further, devices like firewalls have memory limits on the number of signatures they can store at any point in time, and it is up to the vendor to choose which signatures get deployed. A threat library can provide an additional list of signatures tailored to and scored based on the organisation’s context and parameters and therefore trustworthy and relevant. Threat intelligence collection, prioritisation and signature deployment to security tools can be automated when an organisation trusts the data because it is scored accurately.

The physical coverage gap. Many non-security devices, like DNS’s or internal servers, create logs which provide valuable data. A threat library can unlock this security potential through integration with the SIEM, turning non-security devices into security sensors providing visibility into areas of your infrastructure that other tools can’t. Feeding raw threat data into a SIEM generates a lot of noise and so the threat library’s function is to deduplicate, normalise and prioritise raw threat data to deliver high-fidelity threat intelligence to the SIEM.

The timing gap. The threat library also serves as the organisation’s threat memory. It can go back in time and automatically perform rear-view mirror searches on logs to identify and alert on attacks that have fallen through the cracks because they were not identified as malicious at the time.

Automated threat hunting. A central threat library can also help to address these gaps by automating threat hunting. When a protection technology fails or simply isn’t in place because of physical limitations, breaches happen. Costs start to escalate dramatically because at that point threat hunting is the only way to identify nefarious activity and mitigate damage. But not all threat hunting is the same. Automating as much of the threat hunting process as possible will save time and costs over manual methods. In a survey by the SANS Institute, “Threat Hunting: Open Season on the Adversary”, threat hunters say that better detection and automation top the list of capabilities needed to improve their hunting practices. The report recommends, “threat hunting must be done on a continuous basis utilising automated tools, with manual expertise alerted when anomalies are detected.”

By automatically prioritising threat intelligence, a threat library can determine what to hunt for within your environment. With this focus, you can start an investigation by importing several high-risk indicators of compromise associated with an adversary or high-profile intrusion and then run selected operations to pull in supplemental data points. You can also compare indicators across your infrastructure with internal log data to find additional connections. As new data and learnings are added to the threat library, intelligence is continuously reprioritised to support ongoing threat hunting.

Bringing together the security tools, technologies and teams you already have in place, a central threat intelligence library can help close the coverage, timing and physical security gaps you face. With the ability to quickly focus on relevant, high-priority events, you can improve detection and prevention and accelerate investigations to mitigate impact and reduce costs when a breach happens.

Anthony Perridge

VP International at ThreatQuotient, Inc.

  • Anthony Perridge
    Pandemic Sees Organisations Of All Sizes And Industries Invest In Cyber Threat Intelligence
  • Anthony Perridge
    Nobody Said Threat Intelligence Would Be Easy

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read

Why OSINT deserves the same status as other intelligence disciplines

March 17, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}