SEC595: Applied Data Science and AI/Machine Learning for Cybersecurity Professionals

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsThis paper examines the common but flawed practice of implicitly assigning trust to threat indicators (or intel) that are shared by external providers. These indicators are often deployed automatically to security controls without adequate vetting, resulting in false positives and a false sense of security. This paper proposes a solution for how to implement an intel analysis process that separates noise from useful indicators, can handle a large volume of information received regularly and is scalable despite limited analyst resources.