39
Retaining Collective Intelligence in Incident Response and Controls Effectiveness through Gamification Mark Jaster, Founder & CEO [email protected] (610) 742-9366 www.418intelligence.com

Retaining Collective Intelligence in Incident Response and ... · Effectiveness through Gamification Mark Jaster, Founder & CEO [email protected] (610) 742-9366 . RADICAL TRANSPARENCY

  • Upload
    others

  • View
    5

  • Download
    0

Embed Size (px)

Citation preview

Page 1: Retaining Collective Intelligence in Incident Response and ... · Effectiveness through Gamification Mark Jaster, Founder & CEO mark@418intelligence.com (610) 742-9366 . RADICAL TRANSPARENCY

Retaining Collective Intelligence

in Incident Response and Controls

Effectiveness through Gamification

Mark Jaster, Founder & CEO [email protected]

(610) 742-9366

www.418intelligence.com

Page 2: Retaining Collective Intelligence in Incident Response and ... · Effectiveness through Gamification Mark Jaster, Founder & CEO mark@418intelligence.com (610) 742-9366 . RADICAL TRANSPARENCY

RADICAL TRANSPARENCY

BELIEVABILITY WEIGHTED DECISION MAKING

BACKTESTED DECISIONS WITH OUTCOMES

Page 3: Retaining Collective Intelligence in Incident Response and ... · Effectiveness through Gamification Mark Jaster, Founder & CEO mark@418intelligence.com (610) 742-9366 . RADICAL TRANSPARENCY

• Incident Responders’ and inputs were

“Cyber Believability Weighted?”

• Detection & Mitigation Methods were

Back Tested against outcomes?

• Responders and stakeholders were

rewarded for the value of their inputs?

What if we tried this in IR?

Page 4: Retaining Collective Intelligence in Incident Response and ... · Effectiveness through Gamification Mark Jaster, Founder & CEO mark@418intelligence.com (610) 742-9366 . RADICAL TRANSPARENCY

Continuous Collective Intelligence Calibrated Up-to-Date Answers on Call

Page 5: Retaining Collective Intelligence in Incident Response and ... · Effectiveness through Gamification Mark Jaster, Founder & CEO mark@418intelligence.com (610) 742-9366 . RADICAL TRANSPARENCY

Can we turn IR into a game?

Page 6: Retaining Collective Intelligence in Incident Response and ... · Effectiveness through Gamification Mark Jaster, Founder & CEO mark@418intelligence.com (610) 742-9366 . RADICAL TRANSPARENCY

• IARPA developed and tested

• Gamifies, scores & retains collaborative

intelligence in a Bayes Net Model

• Merges human and machine intelligences

through the language of probabilities

FOURSight Technology

As covered by …

Page 7: Retaining Collective Intelligence in Incident Response and ... · Effectiveness through Gamification Mark Jaster, Founder & CEO mark@418intelligence.com (610) 742-9366 . RADICAL TRANSPARENCY

Get Points Analyze Incidents Bet Outcome Probabilities Gamified Rewards

How FOURSight works

Trends Predictive Analytics

Page 8: Retaining Collective Intelligence in Incident Response and ... · Effectiveness through Gamification Mark Jaster, Founder & CEO mark@418intelligence.com (610) 742-9366 . RADICAL TRANSPARENCY

Prototype User Experience & Design

8

Page 9: Retaining Collective Intelligence in Incident Response and ... · Effectiveness through Gamification Mark Jaster, Founder & CEO mark@418intelligence.com (610) 742-9366 . RADICAL TRANSPARENCY

FOURSight Game Board

Page 10: Retaining Collective Intelligence in Incident Response and ... · Effectiveness through Gamification Mark Jaster, Founder & CEO mark@418intelligence.com (610) 742-9366 . RADICAL TRANSPARENCY

FOURSight Game Board

• Timed Rounds

• Currency Updated Continuously

• Running EV Score (not shown)

Page 11: Retaining Collective Intelligence in Incident Response and ... · Effectiveness through Gamification Mark Jaster, Founder & CEO mark@418intelligence.com (610) 742-9366 . RADICAL TRANSPARENCY

FOURSight Game Board

• All primary navigation occurs here

• Assess risk factors

• Collaboratively analyze attack TTPs

• Estimate effectiveness of IR options

Page 12: Retaining Collective Intelligence in Incident Response and ... · Effectiveness through Gamification Mark Jaster, Founder & CEO mark@418intelligence.com (610) 742-9366 . RADICAL TRANSPARENCY

FOURSight Game Board

• Background

Information Window

Page 13: Retaining Collective Intelligence in Incident Response and ... · Effectiveness through Gamification Mark Jaster, Founder & CEO mark@418intelligence.com (610) 742-9366 . RADICAL TRANSPARENCY

FOURSight Game Board

• Probabilities

Assessments Window

Page 14: Retaining Collective Intelligence in Incident Response and ... · Effectiveness through Gamification Mark Jaster, Founder & CEO mark@418intelligence.com (610) 742-9366 . RADICAL TRANSPARENCY

FOURSight Game Board

• Top Ten

• Player’s 1 over, 1 under

Page 15: Retaining Collective Intelligence in Incident Response and ... · Effectiveness through Gamification Mark Jaster, Founder & CEO mark@418intelligence.com (610) 742-9366 . RADICAL TRANSPARENCY

FOURSight Game Board

• Achievements

(Badges)

Page 16: Retaining Collective Intelligence in Incident Response and ... · Effectiveness through Gamification Mark Jaster, Founder & CEO mark@418intelligence.com (610) 742-9366 . RADICAL TRANSPARENCY

FOURSight Game Board

• Player Submissions

• IOCs

• Playbooks

Page 17: Retaining Collective Intelligence in Incident Response and ... · Effectiveness through Gamification Mark Jaster, Founder & CEO mark@418intelligence.com (610) 742-9366 . RADICAL TRANSPARENCY

Let’s Begin!

17

Page 18: Retaining Collective Intelligence in Incident Response and ... · Effectiveness through Gamification Mark Jaster, Founder & CEO mark@418intelligence.com (610) 742-9366 . RADICAL TRANSPARENCY

Each Round has a new briefing FOURSight

Page 19: Retaining Collective Intelligence in Incident Response and ... · Effectiveness through Gamification Mark Jaster, Founder & CEO mark@418intelligence.com (610) 742-9366 . RADICAL TRANSPARENCY

Artifacts served up for context FOURSight

Page 20: Retaining Collective Intelligence in Incident Response and ... · Effectiveness through Gamification Mark Jaster, Founder & CEO mark@418intelligence.com (610) 742-9366 . RADICAL TRANSPARENCY

Sim artifacts revealed by Rounds FOURSight

Page 21: Retaining Collective Intelligence in Incident Response and ... · Effectiveness through Gamification Mark Jaster, Founder & CEO mark@418intelligence.com (610) 742-9366 . RADICAL TRANSPARENCY

Users capture IOCs FOURSight

• This is a test!

(Sorry no

partial credit!)

Find the Easter Eggs to unlock

bonus content!

Page 22: Retaining Collective Intelligence in Incident Response and ... · Effectiveness through Gamification Mark Jaster, Founder & CEO mark@418intelligence.com (610) 742-9366 . RADICAL TRANSPARENCY

Assess Macro Situation

Now that you’ve seen the scenario

and some initial artifacts…

• What is at risk?

• How severe?

• What do we know from priors?

• What forecasts can we make on

the outcomes?

FOURSight

Careful, things may change next round!

Page 23: Retaining Collective Intelligence in Incident Response and ... · Effectiveness through Gamification Mark Jaster, Founder & CEO mark@418intelligence.com (610) 742-9366 . RADICAL TRANSPARENCY

Show us what you know! FOURSight

• What is at risk?

• How severe?

• Who else knows

something?

(Hint – Check the

Info window)

• What will happen

next?

Take your long positions early

when the “price” is cheap.

Page 24: Retaining Collective Intelligence in Incident Response and ... · Effectiveness through Gamification Mark Jaster, Founder & CEO mark@418intelligence.com (610) 742-9366 . RADICAL TRANSPARENCY

Assess the Target FOURSight

• What is the Target’s Security

Baseline?

• What is their maturity?

Page 25: Retaining Collective Intelligence in Incident Response and ... · Effectiveness through Gamification Mark Jaster, Founder & CEO mark@418intelligence.com (610) 742-9366 . RADICAL TRANSPARENCY

Assess the Threat FOURSight

• STIX Threat Factors

• These can modulate Detection and

Mitigation Efficacies

(eg. NIDS should perform differently

in APTs than in SQL Injection attacks)

• And they can be inferred from

TTPs

Page 26: Retaining Collective Intelligence in Incident Response and ... · Effectiveness through Gamification Mark Jaster, Founder & CEO mark@418intelligence.com (610) 742-9366 . RADICAL TRANSPARENCY

Analyze Incident TTPs FOURSight

• ATT&CK Model

• All 11 Tactics

• Prototype has 20% of Techniques

Show you can spot a red herring,

and profit from it!

Page 27: Retaining Collective Intelligence in Incident Response and ... · Effectiveness through Gamification Mark Jaster, Founder & CEO mark@418intelligence.com (610) 742-9366 . RADICAL TRANSPARENCY

Which Techniques are present? FOURSight

Going long, and going short can be

just as profitable!

Page 28: Retaining Collective Intelligence in Incident Response and ... · Effectiveness through Gamification Mark Jaster, Founder & CEO mark@418intelligence.com (610) 742-9366 . RADICAL TRANSPARENCY

How confident are you, and when?

What is the community consensus?

FOURSight

The community says Automated

Collection was used to Collect Data.

Page 29: Retaining Collective Intelligence in Incident Response and ... · Effectiveness through Gamification Mark Jaster, Founder & CEO mark@418intelligence.com (610) 742-9366 . RADICAL TRANSPARENCY

What Detection methods are best? FOURSight

• Each Technique is mapped to

between 5 and 20 Methods

• Post Prototype, the Techniques

and Methods will be chosen

dynamically from Pick Lists

Page 30: Retaining Collective Intelligence in Incident Response and ... · Effectiveness through Gamification Mark Jaster, Founder & CEO mark@418intelligence.com (610) 742-9366 . RADICAL TRANSPARENCY

What Detection tools would you bet on? FOURSight

How to Detect Automated

Collection? That is the question!

Page 31: Retaining Collective Intelligence in Incident Response and ... · Effectiveness through Gamification Mark Jaster, Founder & CEO mark@418intelligence.com (610) 742-9366 . RADICAL TRANSPARENCY

Do threat factors change your bets? FOURSight

Well, maybe it depends… (This is a side-bet that

pays extra if APT is True, else costs nothing).

Page 32: Retaining Collective Intelligence in Incident Response and ... · Effectiveness through Gamification Mark Jaster, Founder & CEO mark@418intelligence.com (610) 742-9366 . RADICAL TRANSPARENCY

What do your peers think, and why? FOURSight

Page 33: Retaining Collective Intelligence in Incident Response and ... · Effectiveness through Gamification Mark Jaster, Founder & CEO mark@418intelligence.com (610) 742-9366 . RADICAL TRANSPARENCY

Deeper insights for better actions FOURSight

• Because this is likely an

APT type of attack…

• Centralized Logging

moves to the top

Detection method

• The insight is retained

for new cases –

Community Memory!

Page 34: Retaining Collective Intelligence in Incident Response and ... · Effectiveness through Gamification Mark Jaster, Founder & CEO mark@418intelligence.com (610) 742-9366 . RADICAL TRANSPARENCY

Which Mitigation methods are best? FOURSight

• Same mappings as Detection in

the prototype

Page 35: Retaining Collective Intelligence in Incident Response and ... · Effectiveness through Gamification Mark Jaster, Founder & CEO mark@418intelligence.com (610) 742-9366 . RADICAL TRANSPARENCY

How would you mitigate this TTP? FOURSight

Page 36: Retaining Collective Intelligence in Incident Response and ... · Effectiveness through Gamification Mark Jaster, Founder & CEO mark@418intelligence.com (610) 742-9366 . RADICAL TRANSPARENCY

The community knows something new FOURSight

• Share emerging best

practices

Page 37: Retaining Collective Intelligence in Incident Response and ... · Effectiveness through Gamification Mark Jaster, Founder & CEO mark@418intelligence.com (610) 742-9366 . RADICAL TRANSPARENCY

Use Cases FOURSight

• Skills assessment and development –

Individuals and Teamwork

• Community brain bank and leverage –

All that knowledge at your back!

• Tools investment decisions – Base

your reco’s on proven tool experts.

Page 38: Retaining Collective Intelligence in Incident Response and ... · Effectiveness through Gamification Mark Jaster, Founder & CEO mark@418intelligence.com (610) 742-9366 . RADICAL TRANSPARENCY

FOURSight Collective IR Analysis Platform

Gamified Information Market

Incident Analysis Playbooks & Countermeasures

Page 39: Retaining Collective Intelligence in Incident Response and ... · Effectiveness through Gamification Mark Jaster, Founder & CEO mark@418intelligence.com (610) 742-9366 . RADICAL TRANSPARENCY

The End Game