chg: [event:AusCERT24] Removing dots

pull/25/head
Christian Studer 2024-05-06 12:04:36 +02:00
parent 2e7a162b24
commit 6f54651b84
No known key found for this signature in database
GPG Key ID: 6BBED1B63A6D639F
1 changed files with 23 additions and 23 deletions

View File

@ -25,9 +25,9 @@
\begin{frame} \begin{frame}
\frametitle{CIRCL's involvement} \frametitle{CIRCL's involvement}
\begin{itemize} \begin{itemize}
\item CIRCL is mandated by the Ministry of Economy and acting as the Luxembourg National CERT for private sector. \item CIRCL is mandated by the Ministry of Economy and acting as the Luxembourg National CERT for private sector
\item \textbf{CIRCL leads the development} of the Open Source MISP threat intelligence platform which is used by many military or intelligence communities, private companies, financial sector, National CERTs and LEAs globally. \item \textbf{CIRCL leads the development} of the Open Source MISP threat intelligence platform which is used by many military or intelligence communities, private companies, financial sector, National CERTs and LEAs globally
\item \textbf{CIRCL runs multiple large MISP communities performing active daily threat-intelligence sharing}. \item \textbf{CIRCL runs multiple large MISP communities performing active daily threat-intelligence sharing}
\item [] \item []
\item We use MISP as an \textbf{internal tool} to cover various day-to-day activities \item We use MISP as an \textbf{internal tool} to cover various day-to-day activities
\item Whilst being the main driving force behind the development, we're also one of the largest consumers \item Whilst being the main driving force behind the development, we're also one of the largest consumers
@ -82,12 +82,12 @@
\begin{itemize} \begin{itemize}
\item There are many different types of users of an information sharing platform like MISP: \item There are many different types of users of an information sharing platform like MISP:
\begin{itemize} \begin{itemize}
\item \textbf{Malware reversers} willing to share indicators of analysis with respective colleagues. \item \textbf{Malware reversers} willing to share indicators of analysis with respective colleagues
\item \textbf{Security analysts} searching, validating and using indicators in operational security. \item \textbf{Security analysts} searching, validating and using indicators in operational security
\item \textbf{Intelligence analysts} gathering information about specific adversary groups. \item \textbf{Intelligence analysts} gathering information about specific adversary groups
\item \textbf{Law-enforcement} relying on indicators to support or bootstrap their DFIR cases. \item \textbf{Law-enforcement} relying on indicators to support or bootstrap their DFIR cases
\item \textbf{Risk analysis teams} willing to know about the new threats, likelyhood and occurences. \item \textbf{Risk analysis teams} willing to know about the new threats, likelyhood and occurences
\item \textbf{Fraud analysts} willing to share financial indicators to detect financial frauds. \item \textbf{Fraud analysts} willing to share financial indicators to detect financial frauds
\end{itemize} \end{itemize}
\end{itemize} \end{itemize}
\end{frame} \end{frame}
@ -141,7 +141,7 @@
\begin{frame} \begin{frame}
\frametitle{Bringing different sharing communities together} \frametitle{Bringing different sharing communities together}
\begin{itemize} \begin{itemize}
\item Getting your community to be active takes \textbf{time and effort}, but with persistence your chances are great. \item Getting your community to be active takes \textbf{time and effort}, but with persistence your chances are great
\item We generally all \textbf{end up sharing with peers that face similar threats} \item We generally all \textbf{end up sharing with peers that face similar threats}
\item Division is either \textbf{sectorial or geographical} \item Division is either \textbf{sectorial or geographical}
\item So why even bother with trying to bridge these communities? \item So why even bother with trying to bridge these communities?
@ -269,7 +269,7 @@
\begin{frame} \begin{frame}
\frametitle{Dispelling the myths around blockers when it comes to information sharing} \frametitle{Dispelling the myths around blockers when it comes to information sharing}
\begin{itemize} \begin{itemize}
\item Sharing difficulties are not really technical issues but often it's a matter of \textbf{social interactions} (e.g. \textbf{trust}). \item Sharing difficulties are not really technical issues but often it's a matter of \textbf{social interactions} (e.g. \textbf{trust})
\begin{itemize} \begin{itemize}
\item You can play a role here: organise regular workshops, conferences, have face to face meetings \item You can play a role here: organise regular workshops, conferences, have face to face meetings
\end{itemize} \end{itemize}
@ -293,10 +293,10 @@
\begin{itemize} \begin{itemize}
\item MISP project collaborated with legal advisory services \item MISP project collaborated with legal advisory services
\begin{itemize} \begin{itemize}
\item Information sharing and cooperation \textbf{enabled by GDPR}; \item Information sharing and cooperation \textbf{enabled by GDPR}
\item \textbf{ISO/IEC 27010:2015} - Information security management for inter-sector and inter-organizational communications; \item \textbf{ISO/IEC 27010:2015} - Information security management for inter-sector and inter-organizational communications
\item How MISP enables stakeholders identified by the \textbf{NISD} to perform key activities; \item How MISP enables stakeholders identified by the \textbf{NISD} to perform key activities
\item Guidelines to setting up an information sharing community such as an ISAC or ISAO; \item Guidelines to setting up an information sharing community such as an ISAC or ISAO
\end{itemize} \end{itemize}
\item For more information: https://www.misp-project.org/compliance/ \item For more information: https://www.misp-project.org/compliance/
\end{itemize} \end{itemize}
@ -307,8 +307,8 @@
\begin{frame} \begin{frame}
\frametitle{MISP feature - correlation} \frametitle{MISP feature - correlation}
\begin{itemize} \begin{itemize}
\item MISP includes a \textbf{powerful engine for correlation} which allows analysts to discover correlating values between attributes. \item MISP includes a \textbf{powerful engine for correlation} which allows analysts to discover correlating values between attributes
\item Getting a direct benefit from shared information by other ISAC members. \item Getting a direct benefit from shared information by other ISAC members
\end{itemize} \end{itemize}
\includegraphics[scale=0.20]{../images/correlation.png} \includegraphics[scale=0.20]{../images/correlation.png}
\end{frame} \end{frame}
@ -316,8 +316,8 @@
\begin{frame} \begin{frame}
\frametitle{MISP feature - event graph} \frametitle{MISP feature - event graph}
\begin{itemize} \begin{itemize}
\item \textbf{Analysts can create stories} based on graph relationships between objects, attributes. \item \textbf{Analysts can create stories} based on graph relationships between objects, attributes
\item ISACs users can directly understand the information shared. \item ISACs users can directly understand the information shared
\end{itemize} \end{itemize}
\includegraphics[scale=0.20]{../images/event-graph.png} \includegraphics[scale=0.20]{../images/event-graph.png}
\end{frame} \end{frame}
@ -390,15 +390,15 @@
\begin{frame} \begin{frame}
\frametitle{Many objectives from different user-groups} \frametitle{Many objectives from different user-groups}
\begin{itemize} \begin{itemize}
\item Sharing indicators for a \textbf{detection} matter. \item Sharing indicators for a \textbf{detection} matter
\begin{itemize} \begin{itemize}
\item 'Do I have infected systems in my infrastructure or the ones I operate?' \item 'Do I have infected systems in my infrastructure or the ones I operate?'
\end{itemize} \end{itemize}
\item Sharing indicators to \textbf{block}. \item Sharing indicators to \textbf{block}
\begin{itemize} \begin{itemize}
\item 'I use these attributes to block, sinkhole or divert traffic.' \item 'I use these attributes to block, sinkhole or divert traffic'
\end{itemize} \end{itemize}
\item Sharing indicators to \textbf{perform intelligence}. \item Sharing indicators to \textbf{perform intelligence}
\begin{itemize} \begin{itemize}
\item 'Gathering information about campaigns and attacks. Are they related? Who is targeting me? Who are the adversaries?' \item 'Gathering information about campaigns and attacks. Are they related? Who is targeting me? Who are the adversaries?'
\end{itemize} \end{itemize}