Threat Intelligence |
- - , , , APT-. - , . , . - , . .
Threat Intelligence. , , , , TI .
Threat Intelligence , , , . TI IDS SIEM. TI , , , ( ) . TI .
, 2014 threat intelligence . , , , , RSA Conference.
TI-! , , , 126 . . TI : ! . . (451 Research, MarketsandMarkets, IT-Harvest, IDC Gartner) 2018 .
2013 | 2014 | 2015 | 2016 | 2017 | 2018 | 2019 | 2020 | , % | |
---|---|---|---|---|---|---|---|---|---|
451 Research | 1,0 | 3,3 | 34,0 | ||||||
MarketsandMarkets | 3,0 | 5,86 | 14,3 | ||||||
IT-Harvest | 0,25 | 0,46 | 1,5 | 80,0 | |||||
IDC | 0,9 | 1,4 | 11,6 | ||||||
Gartner | 0,25 | 1,5 | 43,1 |
, (TTP) . , , ( ) , , .
, , CVSS- ( CVSS v.3 ). , .
2015 SANS Institute TI , 329 , , , . , TI TI.
.
10% .
TI ( ). , .
TI | TI | |
---|---|---|
, , | , | |
( ) | ( ) | |
, - | , | |
, | , , |
, . , .
TI . , , , , , .
|
|
|
---|---|---|
|
( )
|
, , (TTP)
|
|
|
, SOC ( ), , forensics-
|
, , . , . .
- open-source , , , IPS/IDS, UTM. , . TI, .
- . , , DDoS- . : , -10 ..
TI .
- TI: , , TI . :
. , . - beer intelligence. . , .
TI , . 2 (-), (), , , . (, CiSP), (Vulners) (AlienVault Open Threat Exchange).
threat intelligence? , : 1) TI; 2) TI ; 3) , , TI.