Chapter 76. Advanced Threat Intelligence Capabilities for Enhanced Application Security Defense
Michael Freeman
In the digitally transformed world, the security of applications is constantly threatened by many sophisticated cyberattacks in the ever-evolving cyber landscape. Among the most valuable defenses an organization can implement is a comprehensive threat intelligence program capable of providing actionable intelligence on new Tactics, Techniques, and Procedures (TTPs) and vulnerabilities being exploited in the wild. Developing these advanced capabilities is critical for an organization to proactively detect, prevent, and respond to these threats while protective and offensive security controls are also developed for those applications.
Advanced threat intelligence capabilities for AppSec start with the intelligence life cycle, which starts with the question, What application security flaws are being exploited right now? That will drive your collection and analysis of information from a multitude of sources. These include open source intelligence (OSINT), cyber threat intelligence feeds, industry-specific threat-sharing groups, and even the dark web.
Leveraging AI and ML technologies can help target the correct sources, automate the analysis process, and give you actionable and timely intelligence of what to prioritize.
The first facet of actionable intelligence is understanding new TTPs. Cyber adversaries constantly innovate their attack strategies to evade detection ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access